Promote Domain Controller to PDC and Seize FSMO roles


Table Of Contents

Eventually that day comes when a domain controller dies an sudden or ignominious death and a secondary controller needs to take it’s place. Well in the last month I’ve had two such occurrences. One on a 2003 domain and another on a 2008 domain. The problem I encountered is that the exact commands that are used by Ntdsutil.exe to seize FSMO roles isn’t easily found. Even Microsoft’s own website didn’t have the commands listed in their article about FSMO seizure. It does have a great deal of very good detail and outlines some important steps to take and some alternative options. Like how to transfer FSMO roles if your PDC is still online.

How to Seize FSMO roles

To seize the FSMO roles by using the Ntdsutil utility, follow these modified steps:

  1. Log on to a Windows 2000 Server-based or Windows Server 2003-based member computer or domain controller that is located in the forest where FSMO roles are being seized. We recommend that you log on to the domain controller that you are assigning FSMO roles to. The logged-on user should be a member of the Enterprise Administrators group to transfer schema or domain naming master roles, or a member of the Domain Administrators group of the domain where the PDC emulator, RID master and the Infrastructure master roles are being transferred.
  2. Click Start, click Run, type ntdsutil in the Open box, and then click OK.
  3. Type roles, and then press ENTER.
  4. Type connections, and then press ENTER.
  5. Type connect to server servername, and then press ENTER, where servername is the name of the domain controller that you want to assign the FSMO role to.
  6. At the server connections prompt, type q, and then press ENTER.
  7. Type seize role, where role is the role that you want to seize. For a list of roles that you can seize, type ? at the fsmo maintenance prompt, and then press ENTER. For example, to seize the RID master role, type seize rid master. The one exception is for the PDC emulator role, whose syntax is seize pdc, not seize pdc emulator.
    The actual commands to seize roles are:
    • Seize Schema Master
    • Seize Naming Master
    • Seize PDC
    • Seize RID
    • Seize Infrastructure Master
  8. At the fsmo maintenance prompt, type q, and then press ENTER to gain access to the ntdsutil prompt. Type q, and then press ENTER to quit the Ntdsutil utility.

One of the Microsoft notes states, (Do not put the Infrastructure master role on the same domain controller as the global catalog server. If the Infrastructure master runs on a global catalog server it stops updating object information because it does not contain any references to objects that it does not hold. This is because a global catalog server holds a partial replica of every object in the forest.)

If you only have one domain controller at this point you must turn on the “Global Catalog” option after seizing the Infrastructure Master role.

For More Info : FSMO placement and optimization on Active Directory domain controllers

Next you’ll need to remove the old PDC data from Active Directory. It’s a somewhat lengthy procedure.
The link : How to remove data in Active Directory after an unsuccessful domain controller demotion

Originally posted by:
– Cory L. Curtis
– (2010-01-08)

(Visited 1,687 times, 1 visits today)

Leave a Review

Disclaimer

Technoogies.com has made every effort to ensure that the information provided is correct but is not advice. Technoogies will not accept any responsibility or liability for any errors or omissions. Technoogies Authors do not vouch for third party sites. Visit third party sites at your own risk. Technoogies is not directly partnered with any vendor or third party. This website uses cookies only for analytics and basic website functions. Technoogies does not accept any liability that might arise from accessing the data presented on this site. Links to internal pages promotes the content of Technoogies. This article does not constitute legal advice.

Disclosure of Affiliations

Technoogies.com is affiliated with Google, Amazon, and other advertisers. Running this site costs money and if it can’t sustain itself through ad's, it’ll go bye-bye. Please help me to keep that from happening with your patronage of ads that are of interest to you.

Technical Nuggets of Knowledge
Scroll to Top