You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
rodc
About this tag
A Read-Only Domain Controller (RODC) is a type of domain controller in Windows Server that hosts a read-only copy of the Active Directory database. Unlike a writable domain controller, an RODC is designed for branch office or remote locations where physical security cannot be guaranteed. However, users have reported issues where an RODC unexpectedly allows adding, modifying, or deleting users and groups, contrary to its intended read-only behavior. Troubleshooting steps include verifying the RODC's configuration and ensuring that the Password Replication Policy is correctly set. Additionally, known problems exist with the Active Directory Users and Computers MMC snap-in crashing when attempting to delete an RODC, and with certain Windows updates failing to install on RODCs. These issues often require specific hotfixes or workarounds from Microsoft.
Dear at Microsoft Answers ,,,
I have created RODC in my office connected to my PDC , the installation steps i took from Microsoft docs and Alternetive Websites ...
The issue is that the RODC can Add/Modify/Delete Users & Groups , how to prevent that ? i want the RODS be able to read only .
HINT...
Fixes an issue that occurs when you try to delete a RODC in the "Active Directory Users and Computers" MMC snap-in in Windows 7 or in Windows Server 2008 R2. When this issue occurs, you receive an error message and then the MMC snap-in crashes.
More...