4.4. Read-Only Domain Controllers

The read-only domain controller (RODC) is a new domain controller that is being introduced with Windows Server 2008. The RODC is meant to solve the problem of domain services for branch offices or remote sites being hampered by a poor bandwidth connection, low security, and/or lack of IT staff. The RODC has the following features:

Read-Only AD Database

The RODC contains the entire AD DS database, but is missing account passwords. Read-only means that no changes can be written to the RODC, either from local clients or from applications.

Read-Only Domain Name System

When a DNS server is installed on an RODC, the data contained in the DNS partitions on your writable hub DNS servers can be replicated to the RODC. ...

Get Microsoft® Windows Server® 2008: Implementation and Administration now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.