{"id":56,"date":"2009-02-03T03:39:47","date_gmt":"2009-02-03T03:39:47","guid":{"rendered":"http:\/\/web03.partners.extranet.chrisse.com\/wordpress\/?p=56"},"modified":"2009-02-03T03:39:47","modified_gmt":"2009-02-03T03:39:47","slug":"the-real-enterprise-read-only-domain-controllers-group-498","status":"publish","type":"post","link":"https:\/\/blog.chrisse.se\/?p=56","title":{"rendered":"The real Enterprise Read-Only Domain Controllers group [498]"},"content":{"rendered":"<p>It&#8217;s been yet another sleepless night working, actually I have a lot of stuff going on right now, I guess I don&#8217;t will feel too well when this week is over, anyway some interesting facts about the Enterprise Read-Only Domain Controllers group (Yes the _real_ one this time, with RID 498 that&#8217;s not an FSP), have you ever look thru the members of that group? Why would you ever do that, isn&#8217;t it obvious that it&#8217;s going to contain the RODC accounts in the enterprise? Nope, in fact it won&#8217;t, it will always be empty <span style=\"font-family: Wingdings;\">J<\/span><\/p>\n<p>So how does this really work? Adprep \/rodcprep stamps each NC head with an ACE (in order to allow RODCs replicate changes from the NC), NDNCs are stamped with an ACE for the Read-Only Enterprise Domain Controllers group (Note that the group doesn&#8217;t exist at this stage, but always has a well-known RID of 498, so that&#8217;s how adprep dose it)<\/p>\n<p><span style=\"font-size: 10pt;\"><span style=\"font-family: Tahoma;\">But won&#8217;t replication of NDNCs fail as Enterprise Read-Only Domain Controllers is granted extended-right Replicate Changes but the group is empty? Nope RODCs will always include the RID 498 in its token <\/span><span style=\"font-family: Wingdings;\">J<\/span><span style=\"font-family: Tahoma;\"><br \/>\n<\/span><\/span><\/p>\n<p><span style=\"font-family: Tahoma; font-size: 10pt;\">So what do we really need the group for? It&#8217;s there for display purposes, so you don&#8217;t have to see something like (Unknown Account) if you look at the ACL.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s been yet another sleepless night working, actually I have a lot of stuff going on right now, I guess I don&#8217;t will feel too well when this week is over, anyway some interesting facts about the Enterprise Read-Only Domain Controllers group (Yes the _real_ one this time, with RID 498 that&#8217;s not an FSP), &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blog.chrisse.se\/?p=56\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;The real Enterprise Read-Only Domain Controllers group [498]&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-56","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=\/wp\/v2\/posts\/56","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=56"}],"version-history":[{"count":0,"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=\/wp\/v2\/posts\/56\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=56"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=56"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.chrisse.se\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=56"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}