How Do I Prevent Domain Controller Changing?

Murat Er 1 Reputation point
2021-09-23T06:22:29.687+00:00

Hi,
We have 3 domain controllers one of Master DC another one ADC and last one is Read Only DC.
Read Only DC is being used for remote office domain services.
If I login at RODC , I can click "change to domain controller" then changing domain.

Is there anyway to disable this attribute at schema or regedit? I don't want to change domain controller for any admin who can login RODC?

thanks. 134554-change-domain-controller-setting.png

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,898 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Dave Patrick 426.1K Reputation points MVP
    2021-09-23T12:46:31.187+00:00

    What problem does this cause? This only changes the active domain controller in that MMC instance.

    --please don't forget to upvote and Accept as answer if the reply is helpful--


  2. Thameur-BOURBITA 32,586 Reputation points
    2021-09-24T09:17:22.887+00:00

    Hi,

    As mentioned by Patrick , you can change domain controller on MMC instance, it can be done from any machine where active directory tools installed (RODC,member server, workstation, domain controller).
    If you want prevent any change launched from RODC servers, you should check the permission of each admin account allowed to login on RODC ,avoid put all admin account on domain admin group, and prevent all domain admin account to longon on RODC servers.

    Please don't forget to mark helpful reply as answer

    0 comments No comments

  3. Murat Er 1 Reputation point
    2021-09-25T15:44:03.12+00:00

    Hi Patrick and Bourbita,

    You are right but our organization has different admins who have some permisson at Active Directory Console. On the other hand by default Domain users have permission to read some AD objects.

    I think that, I can remove or change passive to change domain controller menu via schema setting or attribute setting.

    If I can prevent this action by delegation, do you have any delegation sceranios?

    Thanks.

    0 comments No comments

  4. Dave Patrick 426.1K Reputation points MVP
    2021-09-25T16:06:18.293+00:00

    Some ideas here.
    https://www.rebeladmin.com/2018/02/step-step-guide-manage-active-directory-permissions-using-object-acls/

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments