70-648 · Question #15
Your network contains an Active Directory domain. The domain contains two sites named Site1 Microsoft 70-648 Exam and Site2. Site1 contains four domain controllers. Site2 contains a read-only domain…
The correct answer is D. Add the computer account of User1's computer to the Allowed RODC Password Replication Group. When a network connection to a writeable domain controller is not available, a user is able to log on through an RODC only if the passwords of both the user account and the computer account (of the workstation that the user is accessing) are cached on the RODC. (MY NOTE: This…
Question
Your network contains an Active Directory domain. The domain contains two sites named Site1 Microsoft 70-648 Exam and Site2. Site1 contains four domain controllers. Site2 contains a read-only domain controller (RODC). You add a user named User1 to the Allowed RODC Password Replication Group. The WAN link between Site1 and Site2 fails. User1 restarts his computer and reports that he is unable to log on to the domain. The WAN link is restored and User1 reports that he is able to log on to the domain. You need to prevent the problem from reoccurring if the WAN link fails. What should you do?
Options
- ACreate a Password Settings object (PSO) and link the PSO to User1's user account.
- BCreate a Password Settings object (PSO) and link the PSO to the Domain Users group.
- CAdd the computer account of the RODC to the Allowed RODC Password Replication Group.
- DAdd the computer account of User1's computer to the Allowed RODC Password Replication Group.
How the community answered
(38 responses)- A5% (2)
- B8% (3)
- C3% (1)
- D84% (32)
Explanation
When a network connection to a writeable domain controller is not available, a user is able to log on through an RODC only if the passwords of both the user account and the computer account (of the workstation that the user is accessing) are cached on the RODC. (MY NOTE: This means BOTH accounts must be in the Allowed RODC Password Replication group, and we are not given theoption of adding User1's user account to the group)(...) Prepopulating the password cache helps ensure that a user can log on to the network using the RODC, even when a link to a writeable domain controller is not available. For example, suppose that a user who used to work in a data center transfers to a branch office with his computer. The RODC contacts the writable domain controller in the data center. If the PRP allows it, the RODC caches the password. However, if the wide area network (WAN) link is offline when the user attempts to log on, the logon attempt fails because the RODC has not cached the password for the account. To avoid this problem, you can prepopulate the password cache of the RODC in the branch office with the password of the user and his computer. This makes it unnecessary for the RODC to replicate the password from the writeable Windows Server 2008 domain controller over the WAN password- replication-policy%28v=ws.10%29.aspx
Topics
Community Discussion
No community discussion yet for this question.