How to create a Windows Server 2019 RODC or Read Only Domain Controller

This is a quick post on how to promote your Windows 2019 Server to Read Only domain controller on an established domain

Firstly build your Windows 2019 Server, give it an IP and make sure it has connectivity back to the rest of the domain.  Run the usual health checks i.e. dcdiag, replmon etc.

Open Server Manager and click Manage> Add Role and Features

Select Active Directory Domain Services and click Next

Cick Add Features to include all the necessary tools

Select Group Policy Management and click Next

Click Next

Click Install

Allow the installation to finish

Once finished click Promote this server to a domain controller

Click Add a domain controller to an existing domain

Select all three options including Read only domain controller.  Enter a DSRM password.

Accept the default allowed password replication group

Click Next

Click Next

Click Next

Click Next

Click Install

Allow the install to finish

You will see the domain controller appear in ADUC

Configure DNS to respond on the correct IP

If this is your first Active Directory 2019 deployment and you are still using FRS you will see this error. I will be doing another post on how to fix this.

 

Leave a Reply

Your email address will not be published. Required fields are marked *