Read Only Domain Controller , How to prevent add and modify users & GPO


New Member
Dear at Microsoft Answers ,,,
I have created RODC in my office connected to my PDC , the installation steps i took from Microsoft docs and Alternetive Websites ...
The issue is that the RODC can Add/Modify/Delete Users & Groups , how to prevent that ? i want the RODS be able to read only .
HINT: I tried the solution with ( Change Domain Controller ) and it works till the moment i restarted the RODC , but as soon as i restarted the RODC it can Add/Modify/Delete again ...



Cloud Security Engineer
Staff member
If you go into AD sites and services and open the properties on the DC does it actually say Read Only? Also are you actually connect to the RDOC when you open AD users and computers?