AD-DC-06 - FSMO role holder details should be retrievable
Overviewโ
Understanding FSMO (Flexible Single Master Operations) role distribution is critical for:
- Operational awareness: Knowing which DCs perform critical directory operations
- Disaster recovery: Being able to quickly seize roles if a DC fails
- Maintenance planning: Understanding impact of DC downtime
- Security monitoring: Tracking changes to FSMO role holders
The 5 FSMO roles are:
- Schema Master (forest-wide): Controls Active Directory schema updates
- Domain Naming Master (forest-wide): Controls domain additions and removals
- PDC Emulator (domain-wide): Primary DC for backward compatibility and time sync
- RID Master (domain-wide): Allocates relative IDs for security identifiers
- Infrastructure Master (domain-wide): Handles cross-domain object references
Security Recommendationโ
- Document your FSMO role holders and keep the documentation updated
- Ensure FSMO role holders are highly available DCs
- Place at least one role holder in a different site for geographic redundancy
- Monitor for unexpected FSMO role transfers
- Test FSMO role seizure procedures periodically
How the Test Worksโ
This test retrieves the current FSMO role holders from the domain and forest objects, then displays:
- Which DC holds each FSMO role
- How many roles each DC holds
- Total number of unique FSMO role holders
Related Testsโ
Test-MtAdDcAllFsmoRolesCount- Identifies DCs holding all 5 rolesTest-MtAdDomainControllerCount- Total DC count
Test Metadataโ
| Field | Value |
|---|---|
| Test ID | AD-DC-06 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.DomainController |
| PowerShell test | Test-MtAdDcFsmoRoleHolderDetails |
| Tags | AD, AD-DC-06, AD.DomainController |
Sourceโ
- Pester test:
tests/ad/domaincontroller/Test-MtAdDcFsmoRoleHolderDetails.Tests.ps1 - PowerShell source:
powershell/public/ad/domaincontroller/Test-MtAdDcFsmoRoleHolderDetails.ps1

