When to deploy an RODC, how staged installation works and how the allowed and denied groups decide which passwords are cached.
From Ultra Transcenders AZ-802 by Tony Rough (coming November 2026)
A read-only domain controller (RODC) holds a read-only copy of the AD DS database and, by default, no account passwords. It’s designed for branch offices with poor physical security, few users, slow links to the hub and little local IT expertise.
krbtgt_<number> account for cryptographic isolation of the tickets it issues, managed automatically at promotion and demotion.A staged installation splits deployment in two:
Add-ADDSReadOnlyDomainControllerAccount. This sets the name, site, PRP and the delegated administrator, a single user or (recommended) a group.Install-ADDSDomainController -UseExistingAccount).The first RODC in a forest requires adprep /rodcprep, which needs Enterprise Admins credentials.
The Password Replication Policy (PRP) controls which accounts’ credentials an RODC may cache. Accounts that are denied, or simply not listed, are never cached; if such a user can’t reach a writable DC, they can’t use AD DS resources. Default PRP:
| Account or group | Default setting |
|---|---|
| Administrators | Deny |
| Server Operators | Deny |
| Backup Operators | Deny |
| Account Operators | Deny |
| Denied RODC Password Replication Group | Deny |
| Allowed RODC Password Replication Group | Allow |
msDS-RevealOnDemandGroup).-AllowPasswordReplicationAccountName and -DenyPasswordReplicationAccountName.Get-ADDomainControllerPasswordReplicationPolicy lists the allowed or denied list of an RODC (it errors against a writable DC); repadmin /prp reports from a writable DC and can show which accounts have been revealed to (cached on) an RODC.
Common trap: Adding branch users to the Allowed RODC Password Replication Group while one of their groups is in the Denied group - deny takes precedence, so their passwords are still never cached and they can’t sign in when the WAN fails.
Common trap: Joining the branch server to the domain before attaching it to a pre-created RODC account - the server used for the second stage of a staged installation must not be domain-joined.
This note is one section of Ultra Transcenders AZ-802: Administering Windows Server, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · AZ-802 terms in the glossary · All AZ-802 study notes
Which operations master roles exist per forest and per domain, what each does and the placement guidance for each.
Which managed service account type fits a service, its requirements such as the KDS root key, and how Windows Server 2025 delegated MSAs migrate old accounts.
The LSDOU order, which GPO wins a conflict, and how Block Inheritance, Enforced and link order change the result.
How the two DHCP failover modes split or reserve addresses, what MCLT does and how relay agents fit in.
What SMB over QUIC needs on the server, the certificate rules, which editions support it and how client access control works.
The Storage Replica topologies, when to use synchronous or asynchronous mode, log volume requirements and the Standard edition limits.
How Windows LAPS rotates and stores local administrator passwords, its policy settings, encryption and the cmdlets to retrieve them.