📎 AI Summary:
The thread discusses a user’s issue with an RODC (Read-Only Domain Controller) that can still modify users and groups, despite aiming for it to be read-only. The user reports that adjustments made through a certain solution work temporarily until a restart, after which the RODC regains write capabilities. A respondent suggests verifying the RODC’s configuration in Active Directory Sites and Services and ensuring the user is connecting to the RODC when managing AD objects.

Nalazzabi

New Member
Member details
Joined
Feb 28, 2019
Messages
1
Thread Author #1
Dear at Microsoft Answers ,,,
I have created RODC in my office connected to my PDC , the installation steps i took from Microsoft docs and Alternetive Websites ...
The issue is that the RODC can Add/Modify/Delete Users & Groups , how to prevent that ? i want the RODS be able to read only .
HINT: I tried the solution with ( Change Domain Controller ) and it works till the moment i restarted the RODC , but as soon as i restarted the RODC it can Add/Modify/Delete again ...


THANK YOU IN FURTHER
 

Solution
If you go into AD sites and services and open the properties on the DC does it actually say Read Only? Also are you actually connect to the RDOC when you open AD users and computers?

Neemobeer

Windows Forum Team
Staff member
Member details
Joined
Jul 4, 2015
Messages
8,995
If you go into AD sites and services and open the properties on the DC does it actually say Read Only? Also are you actually connect to the RDOC when you open AD users and computers?
 

Solution