<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Understanding “Read Only Domain Controller” authentication</title><link>http://blogs.technet.com/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx</link><description>Hello there. Bob Drake here to discuss how Windows Server 2008 &amp;#8220;Read Only Domain Controllers&amp;#8221; (RODC&amp;#8217;s) authenticate users differently from the way Windows Server 2003 and Windows Server 2008 standard domain controllers do. The &amp;#8220;</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>W2K8 - Doku ??ber Read Only DCs &amp;laquo; Susanns Weblog</title><link>http://blogs.technet.com/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx#2757404</link><pubDate>Sat, 19 Jan 2008 00:07:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2757404</guid><dc:creator>W2K8 - Doku ??ber Read Only DCs « Susanns Weblog</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://susanneurich.wordpress.com/2008/01/18/w2k8-doku-uber-read-only-dcs/"&gt;http://susanneurich.wordpress.com/2008/01/18/w2k8-doku-uber-read-only-dcs/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Understanding “Read Only Domain Controller” authentication</title><link>http://blogs.technet.com/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx#2757425</link><pubDate>Sat, 19 Jan 2008 00:17:33 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2757425</guid><dc:creator>Corpuscule</dc:creator><description>&lt;p&gt;Great post ! You sum up all existing information and show the PROOF of what was said on the RODC.&lt;/p&gt;
&lt;p&gt;[ sorry but i'm now used to reading incorrect or erroneous statements on the technet or KB articles. I've been in a technical support team for several years. ]&lt;/p&gt;
&lt;p&gt;My current client was only pondering this question to decide on their RODC implementation in the year to come : &amp;quot;What will be the effect of bringing an RODC in my branch sites with dial-up-like bandwidth ?&amp;quot;&lt;/p&gt;
&lt;p&gt;You finally bring the answer MS ought to give us in the &amp;quot;corp&amp;quot; documentation... Thanks :)&lt;/p&gt;
</description></item><item><title>Understanding “Read Only Domain Controller” authentication</title><link>http://blogs.technet.com/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx#2765138</link><pubDate>Mon, 21 Jan 2008 12:28:39 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2765138</guid><dc:creator>Microsoft Product's</dc:creator><description>&lt;p&gt;Hello there. Bob Drake here to discuss how Windows Server 2008 “Read Only Domain Controllers” (RODC’s&lt;/p&gt;
</description></item><item><title>re: Understanding “Read Only Domain Controller” authentication</title><link>http://blogs.technet.com/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx#2898807</link><pubDate>Sat, 16 Feb 2008 16:50:56 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2898807</guid><dc:creator>cnschindler</dc:creator><description>&lt;p&gt;Excellent Post! I have one question rearding auhtentication: After the RODC has authenticated a user over the WAN, does it &amp;quot;cache&amp;quot; the authenticated credentials in volatile RAM? So that further requests for the same account can be serviced without contacting a writable DC over the WAN? Thanks Christian&lt;/p&gt;
</description></item><item><title>re: Understanding “Read Only Domain Controller” authentication</title><link>http://blogs.technet.com/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx#2906768</link><pubDate>Mon, 18 Feb 2008 17:37:20 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2906768</guid><dc:creator>bobdrake</dc:creator><description>&lt;p&gt;Hey there,&lt;/p&gt;
&lt;p&gt;Once the users account is cached (local AD Database on the RODC and in RAM if recent enough) the local RODC will and does authenticate the user during subsequent logins and secondary logons (accessing network resources and such).&lt;/p&gt;
&lt;p&gt;Remember the key here is the user acount is allowed to be cached, and that way the WAN bandwidth is saved. &amp;nbsp;Once it is cached, the local RODC does it all.&lt;/p&gt;
&lt;p&gt;~Bob&lt;/p&gt;
</description></item><item><title>Windows 2008 RODC Tick List for Deployment</title><link>http://blogs.technet.com/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx#3029072</link><pubDate>Fri, 04 Apr 2008 23:51:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3029072</guid><dc:creator>Jane Lewis's  Weblog</dc:creator><description>&lt;p&gt;Well I am sat in the departure lounge of Aberdeen Scotland Airport after a really interesting and enjoyable&lt;/p&gt;
</description></item><item><title>4 methods to add Server Core RODCs to your environment</title><link>http://blogs.technet.com/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx#3088177</link><pubDate>Sun, 13 Jul 2008 10:55:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3088177</guid><dc:creator>The things that are better left unspoken</dc:creator><description>&lt;p&gt;The Read-only Domain Controller is one of the new and most existing features of Windows Server 2008.&lt;/p&gt;
</description></item><item><title>re: Understanding “Read Only Domain Controller” authentication</title><link>http://blogs.technet.com/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx#3182833</link><pubDate>Thu, 15 Jan 2009 17:27:25 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3182833</guid><dc:creator>Nazarevych</dc:creator><description>&lt;p&gt;My RODC is behind WAN, and still authenticate some amount of users from my domaint but, even if is not in Allowed RODC Password replication Group, just authenticate not save this credentials.&lt;/p&gt;
&lt;p&gt;How i must tune up my Active Directory to preven users authentication for my locally office in nearest AD controller, not throug WAN to RODC.&lt;/p&gt;
&lt;p&gt;Thanks for the reply.&lt;/p&gt;
</description></item><item><title>re: Understanding “Read Only Domain Controller” authentication</title><link>http://blogs.technet.com/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx#3182940</link><pubDate>Thu, 15 Jan 2009 20:47:25 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3182940</guid><dc:creator>bobdrake</dc:creator><description>&lt;p&gt;Hey Nazarevych,&lt;/p&gt;
&lt;p&gt;If you are seeing users authenticate to the RODC that are not supposed to be, then most likely the client computers are discovering the RODC through a possible misconfiguration of the site coverage in AD Sites and Services. &amp;nbsp;If you have the RODC configured to cover those computers' subnet then that could be the reason your users are authenticating to it (RODC) instead of thier local DC.&lt;/p&gt;
&lt;p&gt;See &amp;nbsp;&amp;quot;Procedures for Adding a Subnet&amp;quot;:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://technet.microsoft.com/en-us/library/bb727051.aspx"&gt;http://technet.microsoft.com/en-us/library/bb727051.aspx&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Check them subnets :)&lt;/p&gt;
</description></item><item><title>re: Understanding “Read Only Domain Controller” authentication</title><link>http://blogs.technet.com/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx#3182947</link><pubDate>Thu, 15 Jan 2009 21:04:58 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3182947</guid><dc:creator>bobdrake</dc:creator><description>&lt;p&gt;You may also want to check and see if you need:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/kb/944043"&gt;http://support.microsoft.com/kb/944043&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Description of the Windows Server 2008 read-only domain controller compatibility pack for Windows Server 2003 clients and for Windows XP clients&lt;/p&gt;
</description></item><item><title>re: Understanding “Read Only Domain Controller” authentication</title><link>http://blogs.technet.com/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx#3183530</link><pubDate>Fri, 16 Jan 2009 10:53:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3183530</guid><dc:creator>Nazarevych</dc:creator><description>&lt;p&gt;I think i understand, why it do so.&lt;/p&gt;
&lt;p&gt;In DNS is records type &lt;/p&gt;
&lt;p&gt;_kerberos._tcp.dc._msdcs.X &lt;/p&gt;
&lt;p&gt;And each AD server have it in DNS, even RODC.&lt;/p&gt;
&lt;p&gt;But each server have attribute &amp;quot;Priority&amp;quot; by default 100, deruce this value i think fix my issue.&lt;/p&gt;
&lt;p&gt;Txh. ALL for fast reply :)&lt;/p&gt;
</description></item><item><title>re: Understanding “Read Only Domain Controller” authentication</title><link>http://blogs.technet.com/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx#3247291</link><pubDate>Fri, 29 May 2009 01:23:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3247291</guid><dc:creator>isyed1</dc:creator><description>&lt;p&gt;I realize the post is quite old but I do have one question. &lt;/p&gt;
&lt;p&gt;Do you have to change your current replication topology in Sites &amp;amp; Services for RODC? (we have hub and spoke topology)&lt;/p&gt;
</description></item><item><title>re: Understanding “Read Only Domain Controller” authentication</title><link>http://blogs.technet.com/askds/archive/2008/01/18/understanding-read-only-domain-controller-authentication.aspx#3247365</link><pubDate>Fri, 29 May 2009 06:27:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3247365</guid><dc:creator>NedPyle</dc:creator><description>&lt;p&gt;No, but you cannot have RODC's replicating with other RODC's, so that will need to be a consideration.&lt;/p&gt;
</description></item></channel></rss>