How to create a Windows Server 2019 RODC or Read Only Domain Controller

This is a quick post on how to promote your Windows 2019 Server to Read Only domain controller on an established domain

Firstly build your Windows 2019 Server, give it an IP and make sure it has connectivity back to the rest of the domain.  Run the usual health checks i.e. dcdiag, replmon etc.

Open Server Manager and click Manage> Add Role and Features

How to create a Windows Server 2019 RODC or Read Only Domain Controller-15

Select Active Directory Domain Services and click Next

How to create a Windows Server 2019 RODC or Read Only Domain Controller-16

Cick Add Features to include all the necessary tools

How to create a Windows Server 2019 RODC or Read Only Domain Controller-17

Select Group Policy Management and click Next

How to create a Windows Server 2019 RODC or Read Only Domain Controller-18

Click Next

How to create a Windows Server 2019 RODC or Read Only Domain Controller-19

Click Install

How to create a Windows Server 2019 RODC or Read Only Domain Controller-20

Allow the installation to finish

How to create a Windows Server 2019 RODC or Read Only Domain Controller-21

Once finished click Promote this server to a domain controller

How to create a Windows Server 2019 RODC or Read Only Domain Controller-22

Click Add a domain controller to an existing domain

How to create a Windows Server 2019 RODC or Read Only Domain Controller-23

Select all three options including Read only domain controller.  Enter a DSRM password.

How to create a Windows Server 2019 RODC or Read Only Domain Controller-24

Accept the default allowed password replication group

How to create a Windows Server 2019 RODC or Read Only Domain Controller-25

Click Next

How to create a Windows Server 2019 RODC or Read Only Domain Controller-26

Click Next

How to create a Windows Server 2019 RODC or Read Only Domain Controller-27

Click Next

How to create a Windows Server 2019 RODC or Read Only Domain Controller-28

Click Next

How to create a Windows Server 2019 RODC or Read Only Domain Controller-29

Click Install

How to create a Windows Server 2019 RODC or Read Only Domain Controller-30

Allow the install to finish

How to create a Windows Server 2019 RODC or Read Only Domain Controller-31

You will see the domain controller appear in ADUC

How to create a Windows Server 2019 RODC or Read Only Domain Controller-32

Configure DNS to respond on the correct IP

How to create a Windows Server 2019 RODC or Read Only Domain Controller-33

If this is your first Active Directory 2019 deployment and you are still using FRS you will see this error. I will be doing another post on how to fix this.

How to create a Windows Server 2019 RODC or Read Only Domain Controller-34

 

Leave a Reply

Your email address will not be published. Required fields are marked *