FSMO Roles
Also known as:Flexible Single Master Operations · FSMO
FSMO Roles: Assign special single-master tasks to selected domain controllers. Schema Master and Domain Naming Master exist once per forest, while RID Master, PDC Emulator, and Infrastructure Master exist once per domain. Failure, recovery, transfer, or seizure must be controlled because competing role owners can create inconsistent directory state.
How it works and where it fits
FSMO Roles denotes a technical component or operating environment with its own trust boundaries, identities, interfaces, and dependencies. Security is determined not only by the product, but by architecture, configuration, and the way data and privileges cross component boundaries. Management planes and production processing should be considered separately.
Practical security relevance
Secure operation depends on complete inventory, hardened baselines, least privilege, patchability, and centralized telemetry. Changes should be reproducible and reviewable. Exposed interfaces, default access, secrets, and supply-chain dependencies need particular attention; isolation, backup, and recovery must also be exercised in realistic conditions.
Related concepts
- Domain ControllerDomain ControllerServer running Active Directory Domain Services that replicates directory data and supports authentication and authorization for a domain.: Server running Active Directory Domain Services that replicates directory data and supports authentication and authorization for a domain.
- Active Directory DomainActive Directory DomainLogical Active Directory partition with a shared directory database, namespace, policies, and domain controllers.: Logical Active Directory partition with a shared directory database, namespace, policies, and domain controllers.
- Active Directory ForestActive Directory ForestTop-level Active Directory structure whose domains share a schema, configuration, global catalog, and mutual trust foundation.: Top-level Active Directory structure whose domains share a schema, configuration, global catalog, and mutual trust foundation.
- Active Directory SchemaActive Directory SchemaForest-wide definition of the object classes and attributes that may be stored in Active Directory.: Forest-wide definition of the object classes and attributes that may be stored in Active Directory.