Synology SA3400 Synology Directory Server Administrator s Guide for DSM 7.1 - Page 14

Get FSMO Roles, Add Password Replication Policies, Domain, Domain Controller, Role-getting mode

Page 14 highlights

Chapter 3: Manage the Domain Get FSMO Roles The PDC is the holder of the following FSMO roles by default: PDC Emulator, RID Master, Infrastructure Master, Domain Naming Master, and Schema Master. However, the SDC that acts as a RWDC can get the FSMO roles from the PDC. The PDC can also get the roles back from the SDC. 1. On a RWDC, go to Domain > Domain Controller. 2. Click on the RWDC that is going to get a FSMO role, and select Get FSMO Role. 3. Select one of the following modes from the Role-getting mode drop-down menu. • Transfer role: Transfer a role from the other RWDC to the current one. • Seize role: Take the role of the other RWDC by force. Seizing roles may cause synchronization problems between RWDCs. We suggest using this mode only when the original FSMO role owner is unexpectedly and permanently offline. 4. Select the role to take from the Role drop-down menu. 5. Enter the administrator account and password of your domain. 6. Click Submit to get the role from the other RWDC. Add Password Replication Policies Password replication policy allows you to determine which user account passwords can be replicated to a RODC. Once a password replication policy is added and a user account is in the allowed list of the password replication policy, the user account password is replicated to the RODC. A RODC that is permitted to replicate a user account password authenticates the user's logins, without forwarding authentication requests to a RWDC (i.e., a PDC or SDC). However, a RODC that is denied from replicating a user account will forward the authentication request to a RWDC. 11

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56

11
Chapter 3: Manage the Domain
Get FSMO Roles
The PDC is the holder of the following FSMO roles by default: PDC Emulator, RID Master,
Infrastructure Master, Domain Naming Master, and Schema Master. However, the SDC that
acts as a RWDC can get the FSMO roles from the PDC. The PDC can also get the roles back from
the SDC.
1. On a RWDC, go to
Domain
>
Domain Controller
.
2. Click
on the RWDC that is going to get a FSMO role, and select
Get FSMO Role
.
3. Select one of the following modes from the
Role-getting mode
drop-down menu.
Transfer role
: Transfer a role from the other RWDC to the current one.
Seize role
: Take the role of the other RWDC by force. Seizing roles may cause
synchronization problems between RWDCs. We suggest using this mode only when the
original FSMO role owner is unexpectedly and permanently offline.
4. Select the role to take from the
Role
drop-down menu.
5. Enter the administrator account and password of your domain.
6. Click
Submit
to get the role from the other RWDC.
Add Password Replication Policies
Password replication policy allows you to determine which user account passwords can be
replicated to a RODC. Once a password replication policy is added and a user account is in the
allowed list of the password replication policy, the user account password is replicated to the
RODC.
A RODC that is permitted to replicate a user account password authenticates the user’s logins,
without forwarding authentication requests to a RWDC (i.e., a PDC or SDC). However, a RODC
that is denied from replicating a user account will forward the authentication request to a
RWDC.