Hello 2AI,
Thank you for posting in Microsoft Community forum.
1. which operation masters roles must be put in the first domain controllers which operation masters must not put into other domain controllers?
A1: If all the DCs are read-writable domain controllers (RWDC), and they are running and online, Schema master and domain naming master had better be put in the first domain controller of the forest root domain.
Usually, we put all the five FSMO roles on the first Domain Controller in the forest root domain.
2. Is below assignment of operation masters roles the best practice and most secured design of assignment of roles among domain controllers?
A2: You can view the detailed information in the following link.
I hope the information above is helpful.
If you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou