19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

D.1.3 Identifying Holders of FSMO Roles<br />

The following are methods to determine the names of the domain controllers that hold FSMO<br />

roles in the domain. Depending on the size of the AD implementation, it is typical for one<br />

domain controller to host multiple FSMO roles.<br />

- The RID Master, PDC Emulator, and Infrastructure Master roles must be present on a<br />

domain controller in each AD domain.<br />

- The Domain Naming Master and Schema Master roles must be present on a domain<br />

controller in each AD forest.<br />

Method 1: Microsoft Management Console<br />

e. Start the Active Directory Users and Computers console (“Start”, “Run…”, “dsa.msc”).<br />

f. Right-click the left pane item that matches the name of the domain being reviewed.<br />

g. Select the Operations Masters… menu item.<br />

h. The fully qualified host name(s) of the domain controller(s) holding the RID Master, PDC<br />

Emulator, and Infrastructure Master are displayed in the “Operations master” text boxes on<br />

the respective tabs of the Operations Masters dialog.<br />

i. Select the Close (2003) or Cancel (2000) button to terminate the Operations Masters dialog.<br />

j. Start the Active Directory Domains and Trusts console (“Start”, “Run…”, “domain.msc”).<br />

k. Right-click the “Active Directory Domains and Trusts” item in the left pane.<br />

l. Select the Operations Master… menu item.<br />

m. The fully qualified host name of the domain controller holding the Domain Naming Master<br />

FSMO role is displayed in the “Domain naming operations master” text box.<br />

n. Select the Close button to terminate the Operations Master dialog.<br />

o. Start a management console that is configured with the Active Directory Schema snap-in.<br />

(“Start”, “Run…”, console-name.msc).<br />

Note: This console must be manually configured and might only be configured on one server<br />

in the forest.<br />

p. Right-click the “Active Directory Schema” item in the left pane.<br />

q. Select the Operations Master… menu item.<br />

r. The fully qualified host name of the domain controller holding the Schema Master FSMO<br />

role is displayed in the “Current schema master” (2003) or “Current operations master”<br />

(2000) text box.<br />

s. Select the Close (2003) or Cancel (2000) button to terminate the Schema Master dialog.<br />

UNCLASSIFIED<br />

D-4

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!