Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

May 17, 2008 12:00 AM

Q. I read that I should never log on to a Read-Only Domain Controller (RODC) with a domain administrator account. Why?

Windows IT Pro
InstantDoc ID #99208
Rating: (6)
A. The fact that it's a RODC is not the crucial factor. It's more that because it's a RODC, it's probably not considered a secure machine because it's sitting out in a branch office somewhere relatively exposed to physical attack.

So why should we not log on as a domain administrator? Even if the RODC is caching passwords, the domain administrator accounts are expressly denied from being cached so there's no danger. Wrong. Your administrator credentials should be used only on secure terminals (servers or workstations). Someone who has control of a box can run a keylogger to capture plain text passwords, or someone could hijack the session with local control, or someone could have configured a policy to run at logon as the logging on user and then run something bad. There are many risks so only protected workstations should ever see administrator credentials. The best practice is to not log on to a RODC as a full domain admin or RDP into it. Instead, use WinRS/WinRM to run commands on a RODC or Microsoft Management Console (MMC) in remote mode. Otherwise, you could be giving away credentials if the box is compromised. This should not apply to just RODC boxes but to any potentially unsecure box.

You need to judge how practical this is for your environment as obviously it's far easier to just RDP into a box than run remote commands and MMC snap-ins.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.