Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Windows Server 2008: install a RODC (read only domain controller)

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
11,931
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Feb 10, 2010

This is a video about how to install a Read Only Domain Controller (RODC). A RODC stores a copy of Active Directory in a branch office. It will cache authentication credentials in an effort to reduce WAN (wide area network) traffic or bandwidth. You may control who may approve or deny who may or may not cache their credentials (passwords) on the RODC. It is a feature available on Microsoft Windows Server 2008 only and requires a server 2003 functional domain. Any machine running Server 2003 must have a command (adprep /rodcPrep) run on them to prepare them for a domain or forest that contains a read only domain controller.

Commands used:
dcpromo
d:\support\adprep\adprep /forestPrep
d:\support\adprep\adprep /rodcPrep

Providing training videos since last Tuesday.
http://technoblogical.com
Thanks for watching.

  • likes, 1 dislikes

Link to this comment:

Share to:

Uploader Comments (technoblogical)

  • when I try to install a RODC there is no option to do so. dcpromo.exe tells me the following: This computer is already an Active Directory domain controller. You can use this wizard to uninstall Active Directory Domain Services on this server.

    Im dont know why it says that as I had to reinstall due to some odd problem and now when trying to install RODC now.. i get this.. Very frustrating. Probably something dumb on my part. PLEASE advise. :)

  • @Dankkable You should run dcpromo twice. First to remove ADUC and secondly to retry the RODC. During the install, watch for the screen with three check boxes. the third will be for a RODC. Sounds like that server has already been made a regular domain controller somehow.

    Probably not stupid. Did you restore from a backup, because that might explain why this is already a DC.

  • @technoblogical

    In addition, I went ahead and reformatted since this is a test/practice server I am working on. I installed AD:DS then ran dcpromo.exe. This installed the DC. When I run dcpromo again, I get the same thing, the uninstall option only. Why is it doing this? It says this and nothing else: "This computer is already an Active Directory domain controller. You can use this wizard to uninstall AD:DS on this server." It wont let me install a RODC. ughhh.

  • @Dankkable You need two servers. The first is the DC. The second is the RODC. The purpose of the RODC is to put it in a remote office. It'll authenticate users there, but it only reads AD and doesn't add to it. If a user in that branch office signs in, it will cache their credentials locally.

  • how do you know your clients are authenticating from the RODC and not the other DC on the domain?

  • @ChestrCopperpot The next video "Manage a RODC" will show how to tell who has authenticated to that server, but from the client you can enter the command "set logonserver". It'll say "LOGONSERVER=\\" and the server name.

    Video is youtube ID number "pNExPwNsJTo"

see all

All Comments (13)

Sign In or Sign Up now to post a comment!
  • @MD82TheMaddog MSDN subscription.

  • I was able to have a RODC before. all on one server. I dont know why I cant do it now. Thanks, but it appears as if this is a futile effort. The OS (server 2008 R2) tells me it is advisable to have a backup DC, but for the life of me, I cant install one in addition to the DC that is on there now.  I do not know how to uninstall just the ADUC. I end up uninstalling the whole AD:DS . Thank you for putting up with me.

  • thanks for the reply, every time I run dcpromo now, I get the delete AD:DS option only. If I uninstall the ADDS, as I have tried before, then all settings on the server are gone and I am missing a lot of stuff including some quickstart icons. This is why I restored in the first place; uninstalling AD:DS. I ran dcpromo one time to install the first DC. After that the only thing I have gotten is the uninstall option only. :(

    please dont tell me I have to reinstall server from scratch :(

  • i was asked to explain the modifications necessary to dns for accommodating rodc,and how it differs from the way dns handles ordinary domain controllers. any thoughts?

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more