The RID has a responsibility of creating a team of identifiers used when new accounts, groups, and computers are created. This is a part of security identifiers (SID) which is used to identify an object throughout the domain. The Infrastructure Master is accountable for replicated changes to an object’s SID or distinguished name (DN). Infrastructure Master and global catalog work closely together but are not serviced on the same domain controller due to the fact that if they were on the same domain controller it would be difficult to know the other information has changed. Last one on the list the Primary Domain Controller Emulator (PDC) is held accountable for managing time synchronization within a domain edits to Group Policy Objects (GPO), and replication of security-sensitive account events, such as password changes and account lockouts.
The forest-wide FSMO roles provide a function which is unique in all domains; they keep track of adding and removing domain names and manage changes to the AD schema. In the AD the forest-wide authorities are Domain Naming Master (DMN) and Schema Master (SM). When creating a new domain the DM assures the name has never been used. Lastly, the SM role takes