Patching a domain controller with all the FSMO roles in a large enterprise

Lance Candia 20 Reputation points
2023-06-29T07:32:24.7+00:00

Scenario: a large, multiple site, enterprise with over 10 domain controllers and a single domain controller holding all of the FSMO.

Question: Is there any benefit to moving the FSMO to another domain controller prior to patching a domain controller that holds all of the FSMO roles?

Is there any benefit or reduction in risk?

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,550 questions
{count} votes

Accepted answer
  1. Dave Patrick 426.4K Reputation points MVP
    2023-06-29T14:12:25.0766667+00:00

    Not really, active directory is now multi-master, in a worst case you can seize roles to another healthy one.

    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/transfer-or-seize-operation-master-roles-in-ad-ds

    --please don't forget to upvote and Accept as answer if the reply is helpful--


1 additional answer

Sort by: Most helpful
  1. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more