Error while Transferring FSMO Roles

Discussion in 'Active Directory' started by gonnabokay, Apr 7, 2008.

  1. gonnabokay

    gonnabokay Guest

    We currently have 2 DCs in our domain. We are planning to add a 3rd and then
    demote the oldest DC.

    The old DC that we want to demote has the Operations master roles for the
    domain. (multi-domain forest).

    Before the cutover and demotion of the old server we wanted to transfer the
    FSMO roles to the 2nd DC in our domain.

    While transferring the Infrastructure Role we receive this error:
    The Infrastructure operations master role should not be transferred to a gc

    The server we want to transfer the role to is indeed a GC. But...the server
    we want to transfer from is also a GC. In fact, all DCs in our forest are GCs.

    Since the old server that we want to transfer roles from and the new server
    that we want to transfer roles to are both it okay to go ahead and
    transfer the roles?


    gonnabokay, Apr 7, 2008
  2. Are all of the DCs in the forest GCs? If so (and you plan to keep it that
    way), it would be safe to transfer the Infrastructure Master role to a GC.
    The problem is introduced when you have a multidomain environment where all
    DCs are not GCs. Check out the following KB:
    Joseph T Corey, Apr 7, 2008
  4. Hello,
    I noticed that you are working in a multi-domain forest, as you said, in
    this case, placing the IS role on a GC will cause some conflicts, especially
    if you are giving cross domain permissions, i.e. granting users from other
    domains access to local resources, resulting in displaying the SID of the
    foreign security principals instead of the acutal name. Now since you have 2
    DCs, it is recommended to stop the GC service on the DC that will hold the IS
    role, afterall, you do not need all your DCs to be GCs.

    Hope it helps...
    Ziad K. Chafi, Apr 8, 2008
  5. that is a message from Windows that is not ablways correct, because it
    depends on the IF.....

    for a single domain forest make all DCs a GC (IM can be on any DC)

    for a multiple domain forest



    # Jorge de Almeida Pinto # MVP Identity & Access - Directory Services #

    Jorge de Almeida Pinto [MVP - DS], May 16, 2008
