# Transfer FSMO Roles with PowerShell and ntdsutil: Safe Steps

Source: https://srvscripts.com/guides/transfer-fsmo-roles-powershell/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

Active Directory has five operations master roles: Schema Master and Domain Naming Master at forest level, and RID Master, PDC Emulator and Infrastructure Master per domain. Most of the time nobody notices where they live, until you decommission the domain controller that holds them or it fails. A transfer is a cooperative handover between two live DCs; a seizure forces the role onto a new DC when the old one is unreachable and will never return. The commands below work on Windows Server 2019, 2022 and 2025.

In short: When both DCs are online, transfer the roles with Move-ADDirectoryServerOperationMasterRole -Identity DC02 -OperationMasterRole SchemaMaster,DomainNamingMaster,PDCEmulator,RIDMaster,InfrastructureMaster.

**Short answer:** When both DCs are online, transfer the roles with `Move-ADDirectoryServerOperationMasterRole -Identity DC02 -OperationMasterRole SchemaMaster,DomainNamingMaster,PDCEmulator,RIDMaster,InfrastructureMaster`. When the old holder is dead, add `-Force` to the same cmdlet, or use `ntdsutil` » `roles` » `seize <role>`, then remove the failed DC’s metadata with `ntdsutil` or by deleting its object in Active Directory Users and Computers. Never bring a seized-from DC back online without reinstalling it.

## Find the current role holders

Before changing anything, record where the roles are:

```
netdom query fsmo
Get-ADForest | Select-Object SchemaMaster, DomainNamingMaster
Get-ADDomain | Select-Object PDCEmulator, RIDMaster, InfrastructureMaster
```

Run a replication check as well, because transferring roles to a DC that is not replicating simply moves the problem. `repadmin /replsummary` should show zero failures; if it does not, fix that first using the steps in [check domain controller health with dcdiag and repadmin](/guides/dcdiag-repadmin-dc-health-check/).

## Transfer roles gracefully

Transfers require the account to be a member of Schema Admins (for the Schema Master), Enterprise Admins (for the Domain Naming Master) and Domain Admins (for the three domain roles). From PowerShell on any DC or management workstation with RSAT:

```
Move-ADDirectoryServerOperationMasterRole -Identity "DC02" `
  -OperationMasterRole PDCEmulator, RIDMaster, InfrastructureMaster, `
  SchemaMaster, DomainNamingMaster
```

You can also use the numeric aliases 0 to 4 in the same order (PDCEmulator=0, RIDMaster=1, InfrastructureMaster=2, SchemaMaster=3, DomainNamingMaster=4). The old and new holders talk to each other, the role ownership attribute is updated on both, and the change replicates normally. The same operation is available in the consoles: Active Directory Users and Computers » right-click domain » Operations Masters for the three domain roles, Active Directory Domains and Trusts for the Domain Naming Master, and the Active Directory Schema snap-in (after `regsvr32 schmmgmt.dll`) for the Schema Master.

Place the Infrastructure Master with care: in a domain where not every DC is a global catalog, it must not sit on a GC, or cross-domain group membership references stop being updated. If every DC is a GC, which is the norm today, the placement does not matter.

## Seize roles when the holder is gone

Seizing is only for a DC that has failed permanently or is being rebuilt. If it comes back after a seizure, two DCs will claim the same role, which is especially dangerous for the RID Master and Schema Master. With PowerShell:

```
Move-ADDirectoryServerOperationMasterRole -Identity "DC02" `
  -OperationMasterRole 0,1,2,3,4 -Force
```

The cmdlet attempts a normal transfer first and only seizes if the old holder does not respond, so it is safe to use even when you are not sure the old DC is completely dead. The classic method with ntdsutil does the same:

```
ntdsutil
roles
connections
connect to server DC02
quit
seize pdc
seize rid master
seize infrastructure master
seize schema master
seize naming master
quit
quit
```

Each seize prompts for confirmation. Expect a delay of a minute or so per role while it tries the transfer path.

## Clean up the failed DC’s metadata

A seized role leaves behind the dead DC’s NTDS Settings object, its server object, DNS records and possibly a DFS-R subscription. Since Windows Server 2008 R2, deleting the computer object under the Domain Controllers OU in Active Directory Users and Computers performs the metadata cleanup automatically, and deleting the server object in Active Directory Sites and Services removes the rest. The manual path still exists:

```
ntdsutil
metadata cleanup
remove selected server CN=DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=corp,DC=example,DC=com
quit
quit
```

Then remove stale A, NS and SRV records for the old DC in the DNS console under the forward zone and the `_msdcs` zone, and check `repadmin /showrepl` on every remaining DC for references to it.

## Verify

Run `netdom query fsmo` on two different DCs and confirm they agree. Then run `dcdiag /test:knowsofroleholders /v` and `dcdiag /test:fsmocheck`; both should pass on every DC once replication has converged. Finally, confirm the new PDC emulator is syncing time from an external source, as described in [configure NTP time sync for the PDC emulator](/guides/pdc-emulator-ntp-time-sync/).

## Transfer FSMO roles at a glance

**Official documentation:** [Active Directory Domain Services docs](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-domain-services), [Windows Server documentation](https://learn.microsoft.com/en-us/windows-server/).

**Related guides:** [Fix “The trust relationship between this workstation and the primary domain failed”](https://srvscripts.com/guides/trust-relationship-failed-fix/) · [Raise the AD forest and domain functional level safely](https://srvscripts.com/guides/raise-ad-functional-level/) · [How to find the source of Active Directory account lockouts (Event ID 4740)](https://srvscripts.com/guides/ad-account-lockout-source-event-4740/).

## Frequently asked questions

### Does transferring the PDC emulator role affect user logons?

No; the transfer completes in seconds and clients discover the new PDC through DNS, but you should reconfigure the time source afterwards because the new PDC emulator becomes the authoritative clock for the domain.

### How long does seizing FSMO roles take?

Each seize attempts a graceful transfer first and waits for a timeout, so allow roughly one to two minutes per role, plus replication time for other DCs to learn about the change.

### Can I undo a seizure by bringing the old domain controller back?

No; once a role has been seized, the old holder must be wiped and reinstalled, because reconnecting it produces two role owners and can corrupt the RID pool or schema.
