Re: fsmo auf 2000 oder 2003 dc

Tech-Archive recommends: Fix windows errors by optimizing your registry



Nico Brandt wrote:
Hi,

Gibt es Gründe, die FSMO-Rollen auf den 2003 zu verschieben ?

Gibt es Gründe das nicht zu tun? ;)
http://support.microsoft.com/kb/243330/en-us

The following groups will show as SIDs until a Windows Server 2003 domain controller is made the primary domain controller (PDC) operations master role holder. (The "operations master" is also known as flexible single master operations or FSMO.) Additional new built-in groups that are created when a Windows Server 2003 domain controller is added to the domain are:
. SID: S-1-5-32-554
Name: BUILTIN\Pre-Windows 2000 Compatible Access
Description: An alias added by Windows 2000. A backward compatibility group which allows read access on all users and groups in the domain.
. SID: S-1-5-32-555
Name: BUILTIN\Remote Desktop Users
Description: An alias. Members in this group are granted the right to logon remotely.
. SID: S-1-5-32-556
Name: BUILTIN\Network Configuration Operators
Description: An alias. Members in this group can have some administrative privileges to manage configuration of networking features.
. SID: S-1-5-32-557
Name: BUILTIN\Incoming Forest Trust Builders
Description: An alias. Members of this group can create incoming, one-way trusts to this forest.
. SID: S-1-5-32-557
Name: BUILTIN\Incoming Forest Trust Builders
Description: An alias. Members of this group can create incoming, one-way trusts to this forest.
. SID: S-1-5-32-558
Name: BUILTIN\Performance Monitor Users
Description: An alias. Members of this group have remote access to monitor this computer.
. SID: S-1-5-32-559
Name: BUILTIN\Performance Log Users
Description: An alias. Members of this group have remote access to schedule logging of performance counters on this computer.
. SID: S-1-5-32-560
Name: BUILTIN\Windows Authorization Access Group
Description: An alias. Members of this group have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects.
. SID: S-1-5-32-561
Name: BUILTIN\Terminal Server License Servers
Description: An alias. A group for Terminal Server License Servers.


Der 2000er ist auch Terminaldienstelizensierungsserver, sollen wir
das auch auf den 2003er ändern ?

Das lohnt wiederum lohnt sich nur, wenn euer TS auch W2k3 ist.

HTH
Norbert
--
Dilbert's words of wisdom #04: There are very few personal problems
that cannot be solved by a suitable application of high explosives.

.



Relevant Pages

  • Re: fsmo auf 2000 oder 2003 dc
    ... The following groups will show as SIDs until a Windows Server 2003 domain ... An alias added by Windows 2000. ... Members in this group are granted the right to ...
    (microsoft.public.de.german.windows.server.general)
  • Re: Exchange 2003 Move
    ... I would not run Dcpromo and demote the domain controller to a member server. ... Changing the role of a server after you install Exchange Server 2003 may ... Please do not send email directly to this alias. ...
    (microsoft.public.exchange.setup)
  • Re: Internet Time Server
    ... is it a Domain Controller? ... It the server a member of a Domain ... This particular setting will cause that machine to sync to time.nist.gov (a ... the other Domain members to auto-sync to the DC (for ...
    (microsoft.public.win2000.general)
  • Re: Domain Computers cant access each other
    ... The W2K domain controller also needs to be a wins client. ... checking the networking health of all W2K domain members. ... > I setup a Small Business Server 2000 and everything works ... except that users can't access domain computer ...
    (microsoft.public.win2000.security)
  • Re: Panther trying to connect to Win2003 server share
    ... If this is a domain controller it is configured by default to only allow ... Please do not send e-mail directly to this alias. ... > I'm trying to connect to a shared file on one of our Win2003 Server but ... > authentication credentials again, I click "ok" ...
    (microsoft.public.win2000.macintosh)