Small Business Server Support, Server Support Services, Online Server Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, 7 May 2009

How to Install Read-Only Domain Controller on Windows Server 2008

Posted on 06:57 by Unknown
Installing a Read-Only Domain Controller (RODC) isn’t much different than installing a regular domain controller.

However, there is one important factor to keep in mind. A RODC can only be installed into an existing Active Directory Domain with at least one full (non-read-only) Windows 2008 Server Domain Controller.

The reason is that the RODC is a new feature to Windows 2008 and it needs at least one DC to understand what it is doing in order to function properly.

Once the decision has been made to install a RODC the next decision is whether to install on a full-install or core-install of Windows 2008 Server.

The RODC is primarily aimed at providing additional security on an Active Directory Database for a server that is not physically secured. Installing a RODC on a Core Install of Windows 2008 provides no additional physical security.

Installing RODC on a Core Server Install

There is only one way to install RODC role on a Core Server installation. The dcpromo.exe command runs on the GUI-less version of Windows Server 2008.

Using an answer file for the command makes the process much easier than trying to get all the switches just right in the command line.

Installing the Read-Only Domain Controller on Windows Server 2008 - 1

Although there are many settings available depending upon your particular infrastructure, just basic information is required to complete the command:

  • an account with permissions to do what you are trying to do
  • the name of the Site
  • the database and log paths
  • and whether or not to install DNS.

Installing the Read-Only Domain Controller on Windows Server 2008 - 2

Many people will put a “yes” for RebootOnCompletion. If you are doing an actual unattended promotion then that would make sense.

Regular Installation

On a full install of Windows Servers 2008, there is of course a GUI tool to help with the process. The Active Directory Domain Services Installation Wizard handles the installation of RODC.

Type “dcpromo” at a command prompt to start the wizard. The first screen will ask you whether you want to use an existing forest, or create a new domain in a new forest. Since you must join an existing domain with a RODC, the choice is obvious.

Next you’ll be asked for a username and password. The account must be a member of Domain Admins in order to create a Read-Only Domain Controller.

Next, you’ll choose the site you wish to join.

So far, this is all the same as a regular Domain Controller install. Under “Additional Options” is where you actually choose to make this a Read-Only Domain Controller installation.

Using an answer file for the command makes the process much easier than trying to get all the switches just right in the command line.

Installing the Read-Only Domain Controller on Windows Server 2008 - 1

Although there are many settings available depending upon your particular infrastructure, just basic information is required to complete the command:

* an account with permissions to do what you are trying to do
* the name of the Site
* the database and log paths
* and whether or not to install DNS.

Installing the Read-Only Domain Controller on Windows Server 2008 - 2

Many people will put a “yes” for RebootOnCompletion. If you are doing an actual unattended promotion then that would make sense.

If you are sitting at the console, I prefer to manually reboot the server so that I can take as much time as I want to study what is on the screen if there is an issue.

Next, choose the paths for installing the components, or just click Next to use the defaults. Once the confirmation screen appears, you are all set.

Source: http://windowsserver.trainsignal.com/server-2008-install-rodc-read-only-domain-controlle
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Read-Only Domain Controller, windows server 2008 | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Windows Server 2008: Active Directory Domain Services Auditing Capabilities Explained
    Active Directory Domain Services Auditing has remained fairly consistent since the first release of Active Directory in Windows 2000 Server...
  • How to Implement Outlook Web Access for Exchange Server 2007
    Implementing Outlook Web Access Once the Client Access role is installed on your Exchange Server , the OWA is available to your remote users...
  • Latest Gmail Outage Raises Concerns for Small Business
    Sometimes, your greatest assets can become costly liabilities. Google's remarkable success and rapid growth over the past few years may ...
  • Four Windows Server 2008 Storage Improvements
    With the release of Windows Server 2008 , Microsoft is making a number of improvements to the server's underlying storage mechanisms. He...
  • Data Recovery Options in Windows 2000 Server
    If your Windows 2000 Server crashes, you may not have to take the long way back to data recovery. Jim Boyce explores several options that m...
  • How to install the Windows 2000 Support Tools to a Windows 2000 Server-based computer
    Support personnel and network administrators can use the Windows 2000 Support Tools to help manage their networks and troubleshoot problems...
  • How do I install or remove Windows on Windows 64 (WoW64) on my Windows Server 2008 R2 server core installation?
    The WoW64 component is named ServerCore-WOW64. To install it, use the standard ocsetup method: Start /w ocsetup ServerCore-WOW64 To uninstal...

Categories

  • Active directory
  • Azaleos SharePoint Services
  • business tech support
  • Dell
  • dell server
  • DHCP server
  • exchange server
  • exchange server 2007
  • file server
  • IBM
  • Internet Information Server
  • IT support services
  • Microosft windows server
  • Microosft windows server 2000
  • Microosft windows server 2003
  • Microsoft Exchange
  • Microsoft Exchange environments
  • Microsoft Home Server
  • Microsoft SQL Server
  • Microsoft Windows
  • Microsoft Windows 2003
  • Microsoft windows server
  • Microsoft Windows Server 2003
  • Policy Patrol 5
  • private network
  • Read-Only Domain Controller
  • Red Hat Linux
  • remote server
  • RFID-Ready Server
  • SBS 2008
  • Security Configuration Wizard
  • server performance
  • server services
  • server support
  • server...
  • Servers
  • SharePoint Services
  • Shutdown Event Tracker
  • slave server
  • small business
  • small business computer support
  • small business server
  • small business server 2003
  • small business server 2008
  • small business VOIP
  • Snow Leopard Server
  • Terminal server
  • Types of Servers
  • virtual server support
  • windows 2000 server
  • Windows 2000 Support Tools
  • windows 2003 server
  • Windows Embedded Server
  • windows home server
  • windows server
  • windows server 2003
  • Windows Server 2003 R2
  • Windows Server 2003 Tips
  • windows server 2008
  • windows server 2008 installation
  • Windows Server 2008 R2
  • Windows Server 2008 R2 Beta
  • windows server 2008 setup
  • Windows Server 2008 Terminal Services
  • Windows server 2008.
  • windows server group
  • Windows Server OS
  • windows server support
  • windows server support services
  • windows small business server
  • windows small business server 2008

Blog Archive

  • ▼  2009 (28)
    • ►  June (5)
    • ▼  May (5)
      • How do I install or remove Windows on Windows 64 (...
      • Microsoft will support server virtualization for O...
      • Functions of IT Support Services
      • How to Install Read-Only Domain Controller on Wind...
      • How To Disable The Shutdown Event Tracker On Micro...
    • ►  April (6)
    • ►  March (4)
    • ►  February (3)
    • ►  January (5)
  • ►  2008 (17)
    • ►  December (4)
    • ►  November (4)
    • ►  October (4)
    • ►  September (1)
    • ►  July (3)
    • ►  June (1)
Powered by Blogger.

About Me

Unknown
View my complete profile