الفريق العربي للبرمجةأرشيف المنتديات · 2000 – 2023
نسخة أرشيفية للقراءة فقط — التسجيل والمشاركة مغلقان، والمحتوى محفوظ كما كان.

Fsmo

بدأه ZIADALNASSER في 4 نوفمبر 2008 · 0 رد · 1,793 مشاهدة · في Active directory
مشاركة: واتساب X فيسبوك تيليجرام
#1

<H1 class=title align=justify>كيفية عرض أدوار FSMO ونقلها في Windows Server 2003‏http://support.microsoft.com/kb/324801#

تتناول هذه المقالة كيفية نقل أدوار العمليات الرئيسية المفردة المرنة (FSMO) (التي تُعرف أيضًا باسم أدوار العمليات الرئيسية) باستخدام الأداة الإضافية Active Directory الموجودة في وحدة التحكم بالإدارة لـ Microsoft ‏(MMC) بنظام التشغيل Windows Server 2003. </H1>uparrow.gifعودة إلى الأعلى

<H3 id=tocHeadRef>أدوار FSMO</H3>loadTOCNode(2, 'summary');يوجد في المجال الأم خمسة أدوار على الأقل من أدوار العمليات الرئيسية المفردة المرنة المخصصة لوحدة أو أكثر من وحدات التحكم بالمجال. وفيما يلي الأدوار الخمسة للعمليات الرئيسية المفردة المرنة: •المخطط الرئيسي: تتحكم وحدة التحكم بالمجال الخاصة بالمخطط الرئيسي في كافة التحديثات والتعديلات التي يتم إجراؤها على المخطط. لتحديث مخطط المجال الأم، يجب أن تكون لديك صلاحية وصول إلى المخطط الرئيسي. لا يمكن أن يكون هناك سوى مخطط رئيسي واحد فقط في المجال الأم بأكمله.•تسمية المجال الرئيسية: تتحكم وحدة التحكم بالمجال الخاصة بتسمية المجال الرئيسية في إضافة المجالات أو إزالتها من المجال الأم. لا يمكن أن يكون هناك سوى تسمية مجال رئيسية واحدة فقط في المجال الأم بأكمله.•البنية الأساسية: تتولى البنية الأساسية مسئولية تحديث المراجع من الكائنات الموجودة في مجالها إلى الكائنات الموجودة في مجالات أخرى. وفي كل مرة تكون هناك وحدة تحكم بالمجال واحدة فقط لتقوم بدور البنية الأساسية في كل مجال.•وحدة تحكم المجال الرئيسية للمعرفات النسبية: تتولى "وحدة تحكم المجال الرئيسية للمعرفات النسبية" مسئولية معالجة طلبات تجمع RID من كافة وحدات التحكم بالمجال في مجال معين. وفي كل مرة تكون هناك وحدة تحكم بالمجال واحدة فقط لتقوم بدور "وحدة تحكم المجال الرئيسية للمعرفات النسبية" في المجال.•محاكي PDC: يعتبر محاكي PDC إحدى وحدات التحكم بالمجال التي تقدم نفسها على أنها وحدة التحكم بالمجال الرئيسي (PDC) لمحطات العمل والملقمات الأعضاء ووحدات التحكم بالمجال التي تقوم بتشغيل الإصدارات السابقة من أنظمة تشغيل Windows. على سبيل المثال، إذا كان المجال يحتوي على أجهزة كمبيوتر لا تعمل بنظام التشغيل Microsoft Windows XP Professional أو البرنامج العميل Microsoft Windows 2000 أو إذا كان يحتوي على وحدات التحكم بالمجال الخاصة بالنسخة الاحتياطية من Microsoft Windows NT، يقوم المجال الرئيسي الخاص بمحاكي PDC بدور PDC الخاص بنظام التشغيل Windows NT. ويقوم أيضًا بدور المستعرض الرئيسي للمجال، حيث يعالج تباين كلمات المرور. وفي كل مرة تكون هناك وحدة تحكم بالمجال واحدة فقط لتقوم بدور المجال الرئيسي الخاص بمحاكي PDC في كل مجال داخل المجال الأم.يمكنك نقل أدوار FSMO باستخدام الأداة المساعدة Ntdsutil.exe بسطر الأوامر أو باستخدام الأداة الإضافية لوحدة التحكم بالإدارة لـ Microsoft. بناءً على دور FSMO المطلوب نقله، يمكنك استخدام إحدى الأدوات الإضافية لوحدة التحكم بالإدارة لـ Microsoft من الأدوات الإضافية الثلاث التالية: الأداة الإضافية مخطط Active Directory

الأداة الإضافية Active Directory Domains and Trusts

الأداة الإضافية Active Directory Users and Computersإذا لم يعد جهاز الكمبيوتر موجودًا، يجب الحصول على الدور. للحصول على دور، استخدم الأداة المساعدة Ntdsutil.exe. uparrow.gifعودة إلى الأعلى

<H3 id=tocHeadRef>نقل دور المخطط الرئيسي</H3>loadTOCNode(2, 'summary');استخدم الأداة الإضافية "المخطط الرئيسي لـ Active Directory" لنقل دور المخطط الرئيسي. قبل أن تتمكن من استخدام هذه الأداة الإضافية، يجب تسجيل الملف Schmmgmt.dll.

<H4 id=tocHeadRef>تسجيل Schmmgmt.dll</H4>loadTOCNode(3, 'summary');1.انقر فوق ابدأ، ثم انقر فوق تشغيل.2.اكتب regsvr32 schmmgmt.dll في مربع فتح، ثم انقر فوق موافق. 3.انقر فوق موافق عند ظهور رسالة إتمام العملية بنجاح. <H4 id=tocHeadRef>نقل دور المخطط الرئيسي</H4>loadTOCNode(3, 'summary');1.انقر فوق ابدأ، ثم انقر فوق تشغيل، ثم اكتب mmc في المربع فتح، ثم انقر فوق موافق.2.في القائمة ملف، انقر فوق إضافة/إزالة أداة إضافية.3.انقر فوق إضافة.4.انقر فوق مخطط Active Directory، ثم انقر فوق إضافة، ثم انقر فوق إغلاق، ثم انقر فوق موافق.5.في شجرة وحدة التحكم، انقر بزر الماوس الأيمن فوق مخطط Active Directory، ثم انقر فوق تغيير وحدة تحكم المجال. 6.انقر فوق تعيين اسم، ثم اكتب اسم وحدة التحكم بالمجال التي ستكون بمثابة صاحب الدور الجديد، ثم انقر فوق موافق.7.في شجرة وحدة التحكم، انقر بزر الماوس الأيمن فوق مخطط Active Directory، ثم انقر فوق العمليات الرئيسية.8.انقر فوق تغيير.9.انقر فوق موافق لتأكيد الرغبة في نقل الدور، ثم انقر فوق إغلاق.uparrow.gifعودة إلى الأعلى

<H3 id=tocHeadRef>نقل الدور الرئيسي لتسمية المجال</H3>loadTOCNode(2, 'summary');1.انقر فوق ابدأ، ثم أشر إلى أدوات إدارية، ثم انقر فوق Active Directory Domains and Trusts.2.انقر بزر الماوس الأيمن فوق Active Directory Domains and Trusts، ثم انقر فوق الاتصال بجهاز تحكم المجال.

ملاحظة: يجب القيام بهذه الخطوة إذا لم تكن موجودًا في وحدة التحكم بالمجال المطلوب نقل الدور لها. ليس من الضروري القيام بهذه الخطوة إذا كنت متصلاً بالفعل بوحدة التحكم بالمجال المطلوب نقل الدور الخاص بها.3.استخدم إحدى الطريقتين التاليتين: •في المربع Enter the name of another domain controller، اكتب اسم وحدة التحكم بالمجال التي ستكون بمثابة صاحب الدور الجديد، ثم انقر فوق موافق.

- أو - •في القائمة Or, select an available domain controller، انقر فوق وحدة التحكم بالمجال التي ستكون بمثابة صاحب الدور الجديد، ثم انقر فوق موافق.4.في شجرة وحدة التحكم، انقر بزر الماوس الأيمن فوق Active Directory Domains and Trusts، ثم انقر فوق العمليات الرئيسية.5.انقر فوق تغيير.6.انقر فوق موافق لتأكيد الرغبة في نقل الدور، ثم انقر فوق إغلاق.uparrow.gifعودة إلى الأعلى

<H3 id=tocHeadRef>نقل الأدوار الرئيسية لوحدة تحكم المجال الرئيسية للمعرفات النسبية ومحاكي PDC والبنية الأساسية</H3>loadTOCNode(2, 'summary');1.انقر فوق ابدأ، ثم أشر إلى أدوات إدارية، ثم انقر فوق Active Directory Users and Computers.2.انقر بزر الماوس الأيمن فوق Active Directory Users and Computers، ثم انقر فوق الاتصال بجهاز تحكم المجال.

ملاحظة: يجب إجراء هذه الخطوة إذا لم تكن موجودًا في وحدة التحكم بالمجال المطلوب نقل الدور لها. ليس من الضروري القيام بهذه الخطوة إذا كنت متصلاً بالفعل بوحدة التحكم بالمجال المطلوب نقل الدور الخاص بها.3.استخدم إحدى الطريقتين التاليتين: •في المربع Enter the name of another domain controller، اكتب اسم وحدة التحكم بالمجال التي ستكون بمثابة صاحب الدور الجديد، ثم انقر فوق موافق.

- أو - •في القائمة Or, select an available domain controller، انقر فوق وحدة التحكم بالمجال التي ستكون بمثابة صاحب الدور الجديد، ثم انقر فوق موافق.4.في شجرة وحدة التحكم، انقر بزر الماوس الأيمن فوق Active Directory Users and Computers، ثم أشر إلى كافة المهام، ثم انقر فوق العمليات الرئيسية.5.انقر فوق علامة التبويب المناسبة للدور المطلوب نقله (وحدة تحكم المجال الرئيسية للمعرفات النسبية أو محاكي PDC أو البنية الأساسية)، ثم انقر فوق تغيير.6.انقر فوق موافق لتأكيد الرغبة في نقل الدور، ثم انقر فوق إغلاق.منقول عن ميكروسوفت الشرق الاوسط

Flexible single master operation (FSMO, F is sometimes floating ; pronounced Fiz-mo), or just single master operation or operations master, is a feature of Microsoft's Active Directory (AD). As of 2005, the term FSMO has been deprecated in favor of operations masters.

FSMOs are specialized domain controller (DC) tasks, used where standard data transfer and update methods are inadequate. AD normally relies on multiple peer DCs, each with a copy of the AD database, being synchronized by multi-master replication. The tasks which are not suited to multi-master replication, and are viable only with a single-master database, are the FSMOs.

<H2 style="MARGIN: auto 0in">Contents</H2>

<H2 style="BACKGROUND: #f8fcff; MARGIN: auto 0in">Domain-wide FSMO Roles:</H2>Every domain in an Active Directory forest must contain one of each of the following FSMO roles:

  • The Relative ID Master allocates security RIDs to DCs to assign to new AD security principals (users, groups or computer objects). It also manages objects moving between domains.
  • The Infrastructure Master maintains security identifiers, GUIDs, and DNS for objects referenced across domains. Most commonly it updates user and group links.This is another domain-specific role and its purpose is to ensure that cross-domain object references are correctly handled. For example, if you add a user from one domain to a security group from a different domain, the Infrastructure Master makes sure this is done properly. As you can guess however, if your Active Directory deployment has only a single domain, then the Infrastructure Master role does no work at all, and even in a multi-domain environment it is rarely used except when complex user administration tasks are performed, so the machine holding this role doesn't need to have much horsepower at all.
  • The PDC Emulator operations master role processes all password changes in the domain. Failed authentication attempts due to a bad password at other domain controllers are forwarded to the PDC Emulator before rejection. This ensures that a user can immediately login following a password change from any domain controller, without having to wait several minutes for the change to be replicated. The PDC Emulator Operations Master role must be carefully sited in a location to best handle all password reset and failed-authentication forwarding traffic for the domain.

<H2 style="BACKGROUND: #f8fcff; MARGIN: auto 0in">Forest-wide FSMO Roles:</H2>Regardless of the number of domains in an Active Directory forest, the following FSMO roles exist only once:

  • The Schema Master maintains all modifications to the schema of the forest. The schema determines the types of objects permitted in the forest and the attributes of those objects for.
  • The Domain Naming Master tracks the names of all domains in the forest and is required to add new domains to the forest or delete existing domains from the forest.

<H2 style="BACKGROUND: #f8fcff; MARGIN: auto 0in">Transferring or Seizing FSMO Roles</H2>Transferring or Seizing an FSMO role can be done with the ntdsutil command on a Windows 2000 or Windows Server 2003 Server computer.

Full Details of the process can be found in Microsoft KB255504[1]

<H2 style="BACKGROUND: #f8fcff; MARGIN: auto 0in">Moving FSMO Roles Between Domain Controllers</H2>By default AD assigns all operations master roles to the first DC created in a forest. If new domains are created in the forest, the first DC in a new domain holds all of the domain-wide FSMO roles. This is not a satisfactory position. Microsoft recommends the careful division of FSMO roles, with standby DCs ready to take over each role. When an FSMO role is transferred to a different DC, the original FSMO holder and the new FSMO holder communicate to ensure no data is lost during the transfer. If the original FSMO holder experienced an unrecoverable failure, you can force another DC to seize the lost roles; however, there is a risk of data loss because of the lack of communications. If you seize an FSMO role instead of transferring the role, that domain controller can never be allowed to host that FSMO role again. Corruption can occur within Active Directory. FSMO roles can be easily moved between DCs using the AD snap-ins to the <A title="Microsoft Management Console" href="http://en.wikipedia.org/wiki/Microsoft_Management_Console">MMC or using ntdsutil which is a command line based tool.

Certain FSMO roles depend on the DC being a Global Catalog (GC) server as well. For example, the Infrastructure Master role must not be housed on a domain controller which also houses a copy of the global catalog in a multi-domain forest (unless all domain controllers in the domain are also global catalog servers), while the Domain Name Master role should be housed on a DC which is also a GC. When a Forest is initially created, the first Domain Controller is a Global Catalog server by default. The Global Catalog provides several functions. The GC stores object data information, manages queries of these data objects and their attributes as well as provides data to allow network logon.

The PDC emulator and the RID master should be on the same DC, if possible. The Schema Master and Domain Name Master should also be on the same DC. To provide fault tolerance, there should be at least 2 domain controllers available within each domain of the Forest. Furthermore, the Infrastructure Master role holder should not also be a Global Catalog Server, as the combination of these two roles on the same host will cause unexpected (and potentially damaging) behaviour in a multi-domain environment.(see "Phantoms, Tombstones and the Infrastructure Master", 248047)

<H2 style="BACKGROUND: #f8fcff; MARGIN: auto 0in">http://' target="_blank">Active Directory Support Tools</H2>There are support tools that can test Active Directory to make sure the components are functioning correctly within the Forest. These tools can tell you the health of your Active Directory as they verify the various system components. The tools can be downloaded from the Microsoft web site or obtained from the Windows Server CD.

مواضيع مشابهة