2008 RODC


here scenario
i have 2008 rodc has no internet connection, , users can't login.
is there way configure rodc allow still?

 

hi,

 

yes, mentioned before, in order allow rodc authenticate user logon itself, need configure password replication policy cache logon password. password replication policy lists accounts permitted cached, , accounts explicitly denied being cached.

 

you need ensure connectivity between rodc , windows server 2008 writable dc:

====================

 

when rodc makes request replicate user's password, writable windows server 2008 domain controller rodc contacts allows or denies request. allow or deny request, writable domain controller examines values of allowed list , denied list rodc presents request. if account password being requested rodc in allowed list rather denied list set rodc, request allowed.

so, let rodc cache users' password, should ensure connectivity between rodc , windows server 2008 writable dc @ first. after user authenticated writable dc , lists in password replication policy, rodc cache password further authentication.

 

for more information how configure password replication policy, please visit:

password replication policy

http://technet.microsoft.com/en-us/library/cc730883.aspx



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Event ID 64,77,1008 Certificates Events Windows Server 2008, 2008R2