While methods such as the ADUC console, NTDSUtil tool, and other approaches require administrators to perform multiple steps to view or transfer FSMO roles, PowerShell streamlines the process. With consistent cmdlets, PowerShell enables administrators to view and transfer all the five FSMO roles more quickly and efficiently.
Use the following cmdlet to identify all domain controllers that currently hold FSMO roles within your Active Directory environment.
$domain = Get-ADDomain ; $forest = Get-ADForest
[PSCustomObject]@{
PDCEmulator = $domain.PDCEmulator
RIDMaster = $domain.RIDMaster
InfrastructureMaster = $domain.InfrastructureMaster
SchemaMaster = $forest.SchemaMaster
DomainNamingMaster = $forest.DomainNamingMaster
}
You can also run the following command in the command prompt to view the FSMO role holders in your Active Directory environment.
When a domain controller is upgraded, decommissioned, or under maintenance, transfer the FSMO roles to ensure Active Directory continues to run smoothly.
Use the following cmdlet to transfer roles to another domain controller.
Move-ADDirectoryServerOperationMasterRole -Identity "<TargetDC>" -OperationMasterRole "<Role>"
Replace <TargetDC> with the target DC’s host name and <Role> with one or more of the following roles: SchemaMaster, DomainNamingMaster, PDCEmulator, RIDMaster, or InfrastructureMaster.