Which operations master roles exist per forest and per domain, what each does and the placement guidance for each.
From Ultra Transcenders AZ-802 by Tony Rough (coming November 2026)
AD DS is multi-master: any writable DC accepts changes. Some operations can’t safely be multi-master, so they are handled by a single DC holding an operations master role, still widely called a Flexible Single Master Operations (FSMO) role.
| Role | Scope | What it does | Must be available when |
|---|---|---|---|
| Schema master | One per forest | Only DC that can write schema changes (adprep /forestprep, application schema extensions) |
Schema is updated |
| Domain naming master | One per forest | Adds and removes domains and application partitions (including DNS application partitions) | Domains or partitions are added or removed |
| PDC emulator | One per domain | Receives password changes preferentially; final check for bad passwords; processes account lockout; default DC targeted for Group Policy updates; time source for the domain (forest root PDC is the forest time source) | Always: it should be online all the time |
| RID master | One per domain | Allocates pools of relative IDs to DCs so every SID is unique; moves objects between domains | New DCs promote; DCs need a new RID pool |
| Infrastructure master | One per domain (and per application partition) | Updates cross-domain references (SIDs and distinguished names) | Rarely critical |
The first DC in a new forest gets all five roles; the first DC of each additional domain gets the three domain roles. Roles move only when an administrator transfers or seizes them, or when a role holder is gracefully demoted (the wizard hands its roles to another DC). Figure 1.1 shows which roles exist once per forest and which exist in every domain.
The infrastructure master should not be on a global catalog server in a multi-domain forest unless every DC in its domain is a GC, because a GC already holds a partial replica of every object and so never notices stale cross-domain references. The role has no work to do when:
Microsoft still recommends defining a proper role owner to avoid warnings from monitoring tools.
To find the current holders, use netdom query fsmo, Get-ADDomain (PDC emulator, RID master, infrastructure master) and Get-ADForest (schema master, domain naming master), or the Operations Masters dialogs in Active Directory Users and Computers, Active Directory Domains and Trusts, and the Active Directory Schema snap-in.
Common trap: Placing the infrastructure master on a global catalog server in a multi-domain forest where some DCs are not GCs - it stops updating cross-domain references because the GC never sees them as stale; either host it on a non-GC DC or make every DC in the domain a GC.
This note is one section of Ultra Transcenders AZ-802: Administering Windows Server, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · AZ-802 terms in the glossary · All AZ-802 study notes
When to deploy an RODC, how staged installation works and how the allowed and denied groups decide which passwords are cached.
Which managed service account type fits a service, its requirements such as the KDS root key, and how Windows Server 2025 delegated MSAs migrate old accounts.
The LSDOU order, which GPO wins a conflict, and how Block Inheritance, Enforced and link order change the result.
How the two DHCP failover modes split or reserve addresses, what MCLT does and how relay agents fit in.
What SMB over QUIC needs on the server, the certificate rules, which editions support it and how client access control works.
The Storage Replica topologies, when to use synchronous or asynchronous mode, log volume requirements and the Standard edition limits.
How Windows LAPS rotates and stores local administrator passwords, its policy settings, encryption and the cmdlets to retrieve them.