How to Transfer FSMO Roles from One DC to Another Using PowerShell

Опубликовано: 29 Сентябрь 2026
на канале: Tech Channel
29
1

In this video, I’m going to show you how to transfer all five FSMO roles from one Domain Controller to another using PowerShell. The PowerShell command we’ll use is Move-ADDirectoryServerOperationMasterRole -Identity "DC2" -OperationMasterRole 0,1,2,3,4. Here, DC2 is the name of the destination Domain Controller where we want to transfer all five FSMO roles. The numbers 0, 1, 2, 3, and 4 represent the five different FSMO roles. Let’s take a quick look at each role and understand what it does.

Number 0 – PDC Emulator: The PDC Emulator is one of the most important FSMO roles in Active Directory. It is responsible for several critical functions, including handling password changes, helping with user authentication, and maintaining time synchronization across the domain. The PDC Emulator also plays an important role in Kerberos authentication because accurate time synchronization is required. There is one PDC Emulator for each domain.

Number 1 – RID Master: The RID Master is responsible for allocating pools of Relative IDs, or RIDs, to Domain Controllers. RIDs are used as part of the Security Identifier, or SID, when new security principals such as users and groups are created. There is one RID Master for each domain.

Number 2 – Infrastructure Master: The Infrastructure Master is responsible for maintaining references to objects from other domains. It helps keep these cross-domain references up to date, particularly in environments that contain multiple domains. There is one Infrastructure Master for each domain.

Number 3 – Schema Master: The Schema Master is responsible for managing changes to the Active Directory schema. The schema defines the different types of objects and attributes that can exist in Active Directory. For example, applications may need to extend the schema by adding new object types or attributes. There is only one Schema Master in an Active Directory forest, so this is a forest-wide FSMO role.

Number 4 – Domain Naming Master: The Domain Naming Master is responsible for managing changes to the domain namespace within the Active Directory forest. For example, when adding or removing a domain from the forest, the Domain Naming Master is involved. There is only one Domain Naming Master per forest, so this is also a forest-wide FSMO role.

So, the PDC Emulator, RID Master, and Infrastructure Master are domain-wide FSMO roles, while the Schema Master and Domain Naming Master are forest-wide FSMO roles. Now, to transfer all five FSMO roles to DC2, we simply run the following command:

Move-ADDirectoryServerOperationMasterRole -Identity "DC2" -OperationMasterRole 0,1,2,3,4

The -Identity "DC2" parameter specifies the destination Domain Controller, and -OperationMasterRole 0,1,2,3,4 tells PowerShell to transfer all five FSMO roles. Once the command completes successfully, all five FSMO roles will be held by DC2.