Questions tagged [rodc]

40 questions
2
votes
1 answer

SYSVOL not replicating to some RODC

I'm stumped. I was trying to replicate a file (corporate wallpaper) to branch offices via SYSVOL (so that workstations in branch offices don't have to pull the file from HO). However, the replication only worked for some RODCs, but failed on other…
pepoluan
  • 5,038
  • 4
  • 47
  • 72
2
votes
1 answer

Windows 2008R2 RODC

Quick and easy one for the return after Easter;) I upgraded a clients domain a few months ago from a 2003DC to a 2008R2 Domain. All went OK, few issues we solved along the way but all good now. During the upgrade procedure I completed the necessary…
vlannoob
  • 153
  • 4
  • 16
2
votes
4 answers

RODC deployment

Is it useful to enhance security by implementing RODC in the same site, which RWDC exist also? Pointing the site user the RODC instead of the RWDC. Thanks.
calvin
  • 21
  • 1
2
votes
3 answers

Alternatives to the Cisco "Windows Server on WAAS appliance" for satellite office usage

We need to deploy RODCs to many small satellite offices where we may want additional lightweight infrastructure there too (file, print, dhcp) Are there any networking devices that include RODC functionality so users can log in with local…
makerofthings7
  • 8,911
  • 34
  • 121
  • 197
2
votes
1 answer

Can't deploy branch RODC

I am trying to deploy a branch office RODC and am getting an error about extending the domain and forest schema. I know I have already done this in the past but I went ahead and tried from the main office DC. I get an error saying its already been…
1
vote
0 answers

80090308: LdapErr: DSID-0C0903D9, comment: AcceptSecurityContext error, data 0, v2580

Trying to fastbind against an RODC and I'm getting the following error: 80090308: LdapErr: DSID-0C0903D9, comment: AcceptSecurityContext error, data 0, v2580 I have googled around and don't have any ideas why I'm getting this... I would really…
Stelly
  • 11
  • 1
  • 5
1
vote
1 answer

Windows RODC/DMZ connection to trusted AD issue

I have a really strange scenario...We have a server within a DMZ, which uses an RODC (Read-Only Domain Controller) for user authentication. The users are in a trusted 3rd domain, something like this: DMZserver -> RODC -> InternalDC -> TrustedDC…
Falcones
  • 73
  • 5
1
vote
1 answer

active directory rodc or sub site for New branch office

This may sound silly but I am no ad expert. We have setup a new branch office and 2 users will be moving to that office to man a point of sales system, the internet connectivity is poor so maintaining a constant vpn connection is not going to…
Robert Brown
  • 125
  • 1
  • 4
1
vote
1 answer

assign an OU to a certain RODC

I have a RWDC(A) and two RODC(B and C).i create an OU for each branch in RWDC however the OU and its content will be replicated to all DCs within the domain. So I want to know can we assign an OU to a certain RODC?
KF2
  • 145
  • 1
  • 1
  • 8
1
vote
0 answers

Wrong time on RODC after dcpromo

My team has been experiencing this strange problem: After doing dcpromo (followed by reboot), the time on the newly promoted RODC rolls back to the year 2011. Before dcpromo, the time is correct. The time on the head office's DCs are all correct…
pepoluan
  • 5,038
  • 4
  • 47
  • 72
1
vote
0 answers

Oracle Identity Manager and Microsoft Read-Only Domain Controllers

Is Oracle Identity Management 11g (OID) compatible with Microsoft Active Directory Read-Only Domain Controllers? (RODC) My setup has OID importing users from AD RODC. Is this configuration supported? I read some documentation here and here but I…
Fabio
  • 155
  • 1
  • 5
1
vote
2 answers

AD Replication to RODC; Failover to RODC when DC is Unavailable

I have successfully setup a Router on a Stick and have two subnets: 10.0/16 10.1/16 My Router's sub interfaces are set to 10.0.0.1 and 10.1.0.1, respectively. My primary domain controller, running Windows Server 2008, is located at 10.0.0.3. My…
David W
  • 3,453
  • 5
  • 36
  • 62
1
vote
1 answer

Windows Server 2008 R2 RODC shows no installed updates, won't install updates, won't run DCPROMO to allow demotion

I have a Windoer 2008 R2 RODC. It runs AD DS and DNS and that's it. The install is less than a day old. Windows update hangs at "downloading updates" indefinitely, Server Manager errors on refresh with "The Remote Procedure Call failed. (Exception…
MDMarra
  • 100,734
  • 32
  • 197
  • 329
1
vote
1 answer

Group Managed Service Accounts (GMSA) and Read-Only Domain Controllers (RODC)

We have RODC in a DMZ site and we would like to use GMSA, but the problem is that since domain controllers are read-only, it seems that I have to set a password at the creation of a new account such as: New-ADServiceAccount -name STEST01_gmsa…
user219241
0
votes
1 answer

Adding a rodc to an existing domain failed

I want to add a new RODC to an existing domain. The new RODC is a Server 2012R2 and the existing domain is a 2008R2 domain. The firewall on both sites is offline and both can reach each other per ping and DNS. When I want to promote the 2012R2…