{"id":1142,"date":"2013-03-20T14:16:15","date_gmt":"2013-03-20T14:16:15","guid":{"rendered":"https:\/\/pipe2text.com\/?page_id=1142"},"modified":"2013-05-10T03:14:07","modified_gmt":"2013-05-10T03:14:07","slug":"installing-a-read-only-domain-controller","status":"publish","type":"page","link":"https:\/\/pipe2text.com\/?page_id=1142","title":{"rendered":"Installing a Read Only Domain Controller"},"content":{"rendered":"<p>As part of a recent project to test out Microsoft Azure we placed a Read Only Domain Controller on an Azure VM. The steps and screenshots needed to put the RODC in place are documented below. The process is very similar to putting an RODC on your internal network once the network configurations and the VPN tunnel allowing connectivity back to an Azure vnet have been completed.<\/p>\n<p>After installing Active Directory Domain Services on your system\/vm kick off the domain controller install by running dcpromo. Running dcpromo will present the following:<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/1-Checking3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1179\" alt=\"1-Checking\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/1-Checking3-300x171.png\" width=\"300\" height=\"171\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/1-Checking3-300x171.png 300w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/1-Checking3.png 332w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Once verified you will see the AD Install Wizard. For this install we chose to use advanced mode.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/2-welcome2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1178\" title=\"2-welcome\" alt=\"\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/2-welcome2-300x284.png\" width=\"300\" height=\"284\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/2-welcome2-300x284.png 300w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/2-welcome2.png 505w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>The Operating System Compatibility warning will display. If your DC&#8217;s are all Windows 2008 and above you can generally ignore this.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/3-Wizard2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1187\" title=\"3-Wizard\" alt=\"\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/3-Wizard2-300x281.png\" width=\"300\" height=\"281\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/3-Wizard2-300x281.png 300w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/3-Wizard2.png 511w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>The next screen will give you options for the type of deployment. For this article we are adding a domain controller to an existing domain.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/4-Forest2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1188\" title=\"4-Forest\" alt=\"\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/4-Forest2-300x283.png\" width=\"300\" height=\"283\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/4-Forest2-300x283.png 300w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/4-Forest2.png 504w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Enter the name of the domain that you will be adding the domain controller to. If logged in with the necessary rights to add a DC you will not need to specify alternate credentials.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/5-Domain2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1180\" title=\"5-Domain\" alt=\"\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/5-Domain2-300x283.png\" width=\"300\" height=\"283\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/5-Domain2-300x283.png 300w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/5-Domain2.png 501w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Highlight the domain you are choosing to add the DC to. In this case it is the forest root domain.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/6-Additional-Domain3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1198\" title=\"6-Additional Domain\" alt=\"\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/6-Additional-Domain3-300x283.png\" width=\"300\" height=\"283\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/6-Additional-Domain3-300x283.png 300w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/6-Additional-Domain3.png 500w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Pick the AD site the DC will reside in. If the subnet and site were pre-configured properly it will automatically select the proper site.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/7-Site3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1199\" title=\"7-Site\" alt=\"\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/7-Site3-300x282.png\" width=\"300\" height=\"282\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/7-Site3-300x282.png 300w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/7-Site3.png 506w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>The wizard will run a check against your current DNS setup.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/8-ExaminingDNS2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1183\" title=\"8-ExaminingDNS\" alt=\"\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/8-ExaminingDNS2.png\" width=\"290\" height=\"163\" \/><\/a><\/p>\n<p>You will now receive the options for what you want to be installed on the DC. For our setup we chose to make it a GC and DNS server. This is where you will also select the RODC option.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/9-options1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1184\" title=\"9-options\" alt=\"\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/9-options1-300x284.png\" width=\"300\" height=\"284\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/9-options1-300x284.png 300w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/9-options1.png 498w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Depending upon how your network is setup you generally wouldn&#8217;t see the option below. For all internal Domain Controller installs we&#8217;ve built a static IP address was assigned.<\/p>\n<p><em>As this is an Azure system,<\/em> the IP&#8217;s are set to DHCP and they don&#8217;t change as a DHCP address normally would so you&#8217;d want to choose Yes, the computer will use an IP address automatically assigned by a DHCP server.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/10-ip.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1172\" alt=\"10-ip\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/10-ip-300x157.png\" width=\"300\" height=\"157\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/10-ip-300x157.png 300w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/10-ip.png 556w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>In this screen you will be able to specify which user accounts get their passwords replicated to the RODC and which users do not. This will allow the specified users to authenticate to this DC when a network \u00a0issue prevents connection back to a writable Windows 2008 DC.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/11-replicated1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1191\" title=\"11-replicated\" alt=\"\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/11-replicated1-300x284.png\" width=\"300\" height=\"284\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/11-replicated1-300x284.png 300w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/11-replicated1.png 501w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>As an RODC can be used for other purposes than strictly a domain controller there may be a need to allow a user in the local office to log onto it (to check backups etc). Adding a group or user in this screen will allow local users to gain administrative privileges to this server without specifically adding them to the domain admins group.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/12-delegation1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1192\" title=\"12-delegation\" alt=\"\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/12-delegation1-300x282.png\" width=\"300\" height=\"282\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/12-delegation1-300x282.png 300w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/12-delegation1.png 503w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>The next screen will provide the option to replicate AD data over from an existing DC or to copy a file over to the DC and replicate the AD information locally. For this article we will replicate from another DC<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/dc21.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1816\" alt=\"dc2\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/dc21.png\" width=\"501\" height=\"474\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/dc21.png 501w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/dc21-300x283.png 300w\" sizes=\"auto, (max-width: 501px) 100vw, 501px\" \/><\/a><\/p>\n<p>The Source Domain controller screen will allow you to pick a specific DC to replicate from. If the AD sites are all setup correctly it should be able to locate the closest DC and replicate from it. If not highlight the DC of your choice.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/dc31.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1837\" alt=\"dc3\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/dc31.png\" width=\"503\" height=\"476\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/dc31.png 503w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/dc31-300x283.png 300w\" sizes=\"auto, (max-width: 503px) 100vw, 503px\" \/><\/a><\/p>\n<p>Choose the location for the Database, Log, and Sysvol directories.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/dc4.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1819\" alt=\"dc4\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/dc4.png\" width=\"502\" height=\"474\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/dc4.png 502w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/dc4-300x283.png 300w\" sizes=\"auto, (max-width: 502px) 100vw, 502px\" \/><\/a><\/p>\n<p>The next screen will provide a summary of all options you&#8217;ve chosen in prior screens. You can also export the settings you&#8217;ve chosen from this screen if you plan to build multiple DC&#8217;s with the same configurations.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/13-Review1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1189\" title=\"13-Review\" alt=\"\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/13-Review1-300x284.png\" width=\"300\" height=\"284\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/13-Review1-300x284.png 300w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/13-Review1.png 502w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Clicking next will kick off the final step in the configuration. This may take some time depending on how many object exist in your Active Directory.<\/p>\n<p><a href=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/14-activity1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-1190\" title=\"14-activity\" alt=\"\" src=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/14-activity1-300x212.png\" width=\"300\" height=\"212\" srcset=\"https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/14-activity1-300x212.png 300w, https:\/\/pipe2text.com\/wp-content\/uploads\/2013\/03\/14-activity1.png 441w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>Select the &#8220;reboot on completion&#8221; option or reboot manually and the RODC will be complete.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As part of a recent project to test out Microsoft Azure we placed a Read Only Domain Controller on an Azure VM. The steps and screenshots needed to put the RODC in place are documented below. The process is very &hellip; <a href=\"https:\/\/pipe2text.com\/?page_id=1142\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"open","ping_status":"open","template":"","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","footnotes":""},"class_list":["post-1142","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/pipe2text.com\/index.php?rest_route=\/wp\/v2\/pages\/1142","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pipe2text.com\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/pipe2text.com\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/pipe2text.com\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/pipe2text.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1142"}],"version-history":[{"count":24,"href":"https:\/\/pipe2text.com\/index.php?rest_route=\/wp\/v2\/pages\/1142\/revisions"}],"predecessor-version":[{"id":1193,"href":"https:\/\/pipe2text.com\/index.php?rest_route=\/wp\/v2\/pages\/1142\/revisions\/1193"}],"wp:attachment":[{"href":"https:\/\/pipe2text.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1142"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}