How to give the minimum required permission :c a user who wants to promote a RODC.

How to give the minimum required permission :c a user who wants to promote a RODC.

How to give the minimum required permission :c a user who wants to promote a RODC.

A.
member of the Domain Admins group

B.
allowed to attach the server to the RODC computer account

C.
Local admin

D.
organization admin

Explanation:
Local admin
administrator
Enterprise admins
domain admins



Leave a Reply 4

Your email address will not be published. Required fields are marked *


CsEd

CsEd

I think this is the wrong question, it was actually
Your network contains an Active Directory domain named contoso. All domain controllers run Windows Server 2012. In a remote site, a support technician installs a server named DC10 that runs Windows Server 2012. DC10 is currently a member of a workgroup. You plan to promote DC10 to a read-only domain controller (RODC). You need to ensure that a user named Contoso\User1 can promote DC10 to a RODC in the contoso domain. The solution must minimize the number of permissions assigned to User1.
What should you do?

A. From Ntdsutil, run the local roles command.
B. From Active Directory Users and Computers, pre-create an RODC computer account.
C. From Active Directory Users and Computers, run the Delegation of Control Wizard on the contoso domain object.
D. Join DC10 to the domain. Modify the properties of the DC10 computer account.
Correct Answer: B

karl

karl

AB: you must be a Domain Admin to create a delegation; user must be allowed to attach the server.

or just B: user must be allowed to attach the server.
To install an RODC, you must be a member of the Domain Admins group.

Optional: delegate RODC installation
You can perform a staged installation of an RODC in which the installation is completed in two stages by different individuals. The first stage of the installation, which requires domain administrative credentials, creates an account for the RODC in AD DS. The second stage of the installation attaches the actual server that will be the RODC in a remote location, such as a branch office, to the account that was previously created for it. You can delegate the ability to attach the server to the account to a nonadministrative group or user in the remote location.

During the first stage of the installation, the wizard records all the data about the RODC that will be stored in the distributed Active Directory database, including the read-only domain controller account name and the site in which it will be placed. This stage must be performed by a member of the Domain Admins group.

The administrator who creates the RODC account can also specify at that time which users or groups can complete the next stage of the installation. The next stage of the installation can be performed in the branch office by any user or group who was delegated the right to complete the installation when the account was created. This stage does not require any membership in built-in groups, such as the Domain Admins group. If the user who creates the RODC account does not specify any delegate to complete the installation (and administer the RODC), only a member of the Domain Admins group or the Enterprise Admins group can complete the installation.
During the second stage, the wizard installs AD DS on the server that will become the RODC, and it attaches the server to the domain account that was previously created for it. This stage typically occurs in the branch office or other remote location where the RODC is deployed. During this stage, all AD DS data that resides locally, such as the database, log files, and so on, is created on the RODC itself. You can replicate the installation source files to the RODC from another domain controller over the network, or you can use the install from media (IFM) feature. To use IFM, use Ntdsutil.exe to create the installation media.

The server that will become the RODC must not be joined to the domain before you try to attach it to the RODC account. As part of the installation, the wizard automatically detects whether the name of the server matches the names of any RODC accounts that have been created in advance for the domain. When the wizard finds a matching account name, it prompts the user to use that account to complete the RODC installation.
https://technet.microsoft.com/en-us/library/cc754629%28v=ws.10%29.aspx

ブランド激安 時計 レディース

ブランド激安 時計 レディース

シュプリームS品N品コピー 専門店
シュプリームS品N品コピー N級バッグ、 専門サイト問屋
弊社は販売シュプリームバッグ、キャップ、 小物 、Tシャツなどでご
ざいます。
弊社は「信用第一」をモットーにお客様にご満足頂けるよう、
発送前には厳しい検査を通じて製品の品質を保証してあげますとともに、
配送の費用も無料とし、品質による返送、交換、さらに返金までも実際 にさせていただ
きます。
また、従業員一同、親切、丁寧、迅速に対応 させて頂き、ご安心になってお買い物を楽
しんでくださるよう精一杯力 を尽くしていくつもりです。
送料は無料です(日本全国)! ご注文を期待しています!
下記の連絡先までお問い合わせください。
是非ご覧ください!

ブランド激安 着払い 違い

ブランド激安 着払い 違い

S品N品コピーブランド専門店
ぜひ一度のS品N品コピーブランド品をお試しください。
驚きと満足を保証できます。
ご利用を心からお待ちしております。
営業時間: ご注文はオンラインにて年中無休24時間受付けております。