Synology SA3400 Synology Directory Server Administrator s Guide for DSM 7.1 - Page 13

View Domain Privileges, Domain Naming Master

Page 13 highlights

Roles RID Master • The Relative ID (RID) Master role holder answers RID pool requests from all DCs within a domain so that DCs can add domain objects. • There is only one holder of this role for each domain, and the holder must be a RWDC. Infrastructure Master • The role holder is responsible for updating cross-domain object references. • There is only one holder of this role for each domain, and the holder must be a RWDC. Domain Naming Master • The role holder is assigned to deal with changes in the domain namespace. • There is only one holder of this role for each forest, and the holder must be a RWDC. Schema Master • The role holder is responsible for updating the directory schema. • There is only one holder of this role for each forest, and the holder must be a RWDC. Chapter 3: Manage the Domain View Domain Privileges The table below shows the actions that can be performed by a DC. DC type / Action PDC SDC RWDC RODC Get FSMO roles Yes Yes No Add password replication policies Yes Yes View only Preview password replication policies Yes Yes Yes Prepopulate passwords Yes Yes View only Change IP addresses Yes Yes View only Demote DCs Yes (can demote Yes (cannot Can only demote all DCs) demote the PDC) itself 10

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56

10
Chapter 3: Manage the Domain
Roles
RID Master
• The Relative ID (RID) Master role holder answers RID pool requests
from all DCs within a domain so that DCs can add domain objects.
• There is only one holder of this role for each domain, and the holder
must be a RWDC.
Infrastructure Master
• The role holder is responsible for updating cross-domain object
references.
• There is only one holder of this role for each domain, and the holder
must be a RWDC.
Domain Naming Master
• The role holder is assigned to deal with changes in the domain
namespace.
• There is only one holder of this role for each forest, and the holder
must be a RWDC.
Schema Master
• The role holder is responsible for updating the directory schema.
• There is only one holder of this role for each forest, and the holder
must be a RWDC.
View Domain Privileges
The table below shows the actions that can be performed by a DC.
DC type / Action
PDC
SDC
RWDC
RODC
Get FSMO roles
Yes
Yes
No
Add password
replication policies
Yes
Yes
View only
Preview password
replication policies
Yes
Yes
Yes
Prepopulate
passwords
Yes
Yes
View only
Change IP addresses
Yes
Yes
View only
Demote DCs
Yes (can demote
all DCs)
Yes (cannot
demote the PDC)
Can only demote
itself