QuestionQ44

Deploy and manage AD DS

Your network has an Active Directory Domain Services (AD DS) forest. The forest includes a root domain called contoso.com and a child domain called branch.contoso.com. The domain has a domain controller named DC1 that holds every domain-wide FSMO role.

DC1 fails and cannot be recovered, which causes these problems:

  • Recent password changes are not immediately recognized when signing in to contoso.com.
  • Domains cannot be added to or removed from the forest.

You must seize the minimum required domain-wide FSMO roles on a domain controller named DC2 to fix these problems. Select the role to seize for each issue. An item may be used once, more than once, or not at all.

Drag & Drop
Password changes:
Adding or removing domains:
Explanation

The PDC emulator FSMO role handles authoritative time synchronization for the domain and is the priority target for password-change replication: a changed password is sent to the PDC emulator immediately rather than waiting on the normal replication schedule, and when another domain controller receives what looks like a bad password during sign-in it checks with the PDC emulator to see whether a more recent password change exists before rejecting the logon. When the PDC emulator role holder is unavailable, recently changed passwords stop being recognized promptly elsewhere in the domain, which seizing the PDC emulator role onto a functioning domain controller resolves. The domain naming master is the single forest-wide role holder responsible for adding or removing domains (and application directory partitions) from the forest; while its role holder is offline, no domain can be added to or removed from the forest, so seizing the domain naming master role restores that capability.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!