FREE STUDY NOTES · AZ-802

Read-only domain controllers and the Password Replication Policy

When to deploy an RODC, how staged installation works and how the allowed and denied groups decide which passwords are cached.

From Ultra Transcenders AZ-802 by Tony Rough (coming November 2026)

A read-only domain controller (RODC) holds a read-only copy of the AD DS database and, by default, no account passwords. It’s designed for branch offices with poor physical security, few users, slow links to the hub and little local IT expertise.

What an RODC does and doesn’t do

Staged (delegated) installation

A staged installation splits deployment in two:

  1. A Domain Admin pre-creates the RODC account in ADAC or Active Directory Users and Computers (Pre-create a read-only domain controller account on the Domain Controllers OU), or with Add-ADDSReadOnlyDomainControllerAccount. This sets the name, site, PRP and the delegated administrator, a single user or (recommended) a group.
  2. At the branch, the delegated administrator attaches a server that is not joined to the domain by promoting it with Use existing RODC account (Install-ADDSDomainController -UseExistingAccount).

The first RODC in a forest requires adprep /rodcprep, which needs Enterprise Admins credentials.

Password Replication Policy

The Password Replication Policy (PRP) controls which accounts’ credentials an RODC may cache. Accounts that are denied, or simply not listed, are never cached; if such a user can’t reach a writable DC, they can’t use AD DS resources. Default PRP:

Account or group Default setting
Administrators Deny
Server Operators Deny
Backup Operators Deny
Account Operators Deny
Denied RODC Password Replication Group Deny
Allowed RODC Password Replication Group Allow
A flow for a branch account: if the account or one of its groups is denied, its password is never cached; if not denied but allowed, it can be cached on the RODC; if not listed, it is never cached. A panel lists the default denied and allowed groups.
Figure 1.2: How the Password Replication Policy decides whether an RODC caches a password

Common trap: Adding branch users to the Allowed RODC Password Replication Group while one of their groups is in the Denied group - deny takes precedence, so their passwords are still never cached and they can’t sign in when the WAN fails.

Common trap: Joining the branch server to the domain before attaching it to a pre-created RODC account - the server used for the second stage of a staged installation must not be domain-joined.

Get the whole book

This note is one section of Ultra Transcenders AZ-802: Administering Windows Server, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in November 2026, in Kindle and paperback editions.

About the book · AZ-802 terms in the glossary · All AZ-802 study notes

More AZ-802 study notes