RODC Prerequisites:
The prerequisites for deploying an RODC (Read Only Domain Controller) are as follows:
• The domain controller that holds the primary domain controller (PDC) emulator operations master role for the domain must be running Windows Server 2008. This is necessary for creating the new krbtgt account for the RODC and for ongoing RODC operations.
• The RODC needs to forward authentication requests to a global catalog server running Windows Server 2008 in the site that is closest to the site with the RODC. The Password Replication Policy is set on this domain controller to determine if credentials are replicated to the branch location for a forwarded request from the RODC.
• The domain functional level must be Windows Server 2003 so that Kerberos constrained delegation is available. Constrained delegation is used for security calls that need to be impersonated under the context of the caller.
• The forest functional level must be Windows Server 2003, so that linked-value replication is available. This provides a higher level of replication consistency.
• You must run adprep /rodcprep one time in the forest. This will update the permissions on all of the DNS application directory partitions in the forest to facilitate replication between RODCs that are also DNS servers.
• Multiple RODCs for the same domain in the same site are not supported because RODCs in the same site do not share information with each other. Therefore, deploying multiple RODCs for the same domain in the same site can lead to inconsistent logon experiences for users, if the writable domain controllers cannot be reached on the network.
Sunday, 9 September 2007
What is prerequisites for deploying an RODC in your domain?
Posted on 09:54 by Unknown
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment