سلام من می خواهم اکتیو را از کامپیوتر قدیمی به کامپیوتر جدید انتقال بدم یک داکیونت دارم دوستان نظر بدن ایا کامل هست برای انتقال اکتیو تنظیم دیگری لازم هست
Transferring roles
There are two basic reasons for moving an FSMO role from one DC to another. One reason is because you want to. That is, the movement is planned for some reason, such as decommissioning a server that holds one or more of the FSMO roles. When you are carrying out a planned move, it is called transferring the role.
The other reason to move a role is because you have to. For instance, you might be forced to move a role when a server that holds one or more FSMO roles has suffered catastrophic hardware failure. When you carry out an unplanned move, it is called seizing the role. You should never seize a role unless you absolutely have to.
Transferring a role can be done either through the graphic user interface (GUI) or through the command line interface (CLI), while seizing a role can only be carried out via the command line.
Whether done through the GUI or the CLI, moving a role is done in two steps:
- Connect to a domain controller
- Transfer or seize the role
Let's first look at transferring a role through the GUI. After that, I'll show you how it's done using the CLI.
Using the GUI
To change a domain-level role, click on Start | Administrative Tools | Active Directory Users And Computers. Next, as shown in Figure B, right-click on the domain and then select Connect To Domain Controller…
Figure B
Next, you will see a dialog box in which you can specify to which DC you want to connect (see Figure C).
Figure C
Once you have connected to the domain controller to which you will transfer a role, right-click once again on the domain and select "Operations Masters…" This will bring up the dialog box you see in Figure D.
Figure D
This dialog box will allow you to transfer a domain-level role from one DC to another, provided that you have already connected to that DC. If you have not connected to the DC, the same name will appear in both boxes. To change a forest-level role, click on Start | Administrative Tools | Active Directory Domains and Trusts.
Next, as shown in Figure E, right-click on Domains and Trusts, and then select Connect To Domain Controller…
Figure E
Once you have connected to the other DC, right-click once again on Active Directory Domains And Trusts, and select Operations Master… This will bring up a dialog box (see Figure F) similar to the one you used to transfer a domain-level role.
Figure F
Using the command line interface
You can perform all of these same operations from the command line, using the Active Directory Diagnostic Tool, ntdsutil.exe. This tool is interactive, in that, when you invoke it, you have several submenus at your disposal. In this case, since I am talking about transferring and seizing roles, I will use the "Roles" submenu.
To do that, type "ntdsutil" at the command line. The prompt will then change to reflect the current level of the menu. In this case, at the "ntdsutil" prompt, you would type "roles." The command prompt will then change to FSMO Maintenance (as you'll see below in Figure G).
The commands available from the Roles submenu are:
- Connections
- Seize domain naming master
- Seize infrastructure master
- Seize PDC
- Seize RID master
- Seize schema master
- Select operation target
- Transfer domain naming master
- Transfer infrastructure master
- Transfer PDC
- Transfer RID master
- Transfer schema master
Figure G illustrates using the tool to make a connection to another domain controller.
Figure G
Figure H illustrates using ntdsutil to transfer a role.
Figure H
Seizing a role
Transferring can only be done if the original DC is alive on the network. If a domain controller hosting a single operations master role is no longer available (possibly due to catastrophic failure), you will not be able to transfer that role to another domain controller. If that is the case, then you can move that role to another DC by seizing the role.
Seizing a role can only be done through the command line interface using ntdsutil.exe. It is extremely important to remember two things about seizing FSMO roles:
- Never seize a role unless it is your last resort. If a DC hosting a role is only going to be down temporarily, don't worry about it. Your network will survive a short time without it.
- If either the schema master, domain naming master, or RID master role is seized from a domain controller, that domain controller must never be allowed to come back online.
Take FSMO roles seriously
Networks using Active Directory still tend to be relatively young, so in all likelihood there has been very little need for administrators to concern themselves much with FSMO roles up until now. But as the network ages and it comes time for servers to be replaced, great care will need to be taken to preserve the integrity of those roles. At some point, domain controllers hosting FSMO roles will need to be replaced. Admins will need to understand where the roles are located and how to transfer the roles if an outage is planned, or how to seize a role if the outage is unplanned.
موضوعات مشابه:
- سوال در مورد اکتیو دایرکتوری restore
- سوال در مورد کنترل یوزر در اکتیو دایرکتوری
- سوال: طریقه ایزوله کردن یوزرها در داخل اکتیو دایرکتوری با استفاده از ابزار ADSI به چه نحو می باشد ؟
- سوال راجع به اکتیو دایرکتوری
- یه سوال مهم در مورد اکتیو دایرکتوری