question

JanAdolfsson-5178 avatar image
0 Votes"
JanAdolfsson-5178 asked LimitlessTechnology-2700 commented

LAPS on servers that are only connected to a RODC

How can I get LAPS working on servers that only can access a RODC?
Ho can they populate the LAPS attributes when they cannot contact an RWDC?

windows-server
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LeonLaude avatar image
0 Votes"
LeonLaude answered LeonLaude edited

Hi @JanAdolfsson-5178,

I believe if the servers have no access to the RWDC whatsoever and only to the RODC, the LAPS solution will not work.
This has also been discussed in other thread over here:

If the reply was helpful please don't forget to upvote and/or accept as answer, thank you!


Best regards,
Leon

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LimitlessTechnology-2700 avatar image
0 Votes"
LimitlessTechnology-2700 answered LimitlessTechnology-2700 commented

Hello Jan A,

You can perform these procedures to exclude specific data from replicating to RODCs in the forest. Because the data is not replicated to any RODCs, you can be assured that the data will not be revealed to an attacker who manages to successfully compromise an RODC. In most cases, adding an attribute to the RODC FAS is completed by the developer of the application that added the attribute to the schema.

Determine and then modify the current searchFlags value of an attribute

Verify that an attribute is added to the RODC FAS

To get to know further about the LAPS working and attributes do follow up the below link,

https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc754794(v=ws.10)?redirectedfrom=MSDN

Hope this answers all your queries, if not please do repost back.
If an Answer is helpful, please click "Accept Answer" and upvote it : )

· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

But the computer never has access to a RWDC, how can it update the ms-Mcs-AdmPwd attribute then?

0 Votes 0 ·

Hello Jan,

Since the computer has no access to RWDC, you can't execute the steps mentioned above.

0 Votes 0 ·