RODC Administrator role separation feature(ARS)


Administrator Role Separation (ARS) in a Read-Only Domain Controller (RODC) is a feature that enhances security by allowing the delegation of administrative tasks to different users without giving them full administrative privileges over the domain controller or the entire Active Directory (AD) environment.

Open CMD as Administrator mode

dsmgmt.exe
Local Roles
List Roles
show role Administrators
add dell\rodc_admin Administrators
remove dell\rodc_admin Administrators

Step:1

dsmgmt.exe
Local Roles

Step:2

show role Administrators

Step:3

add dell\rodc_admin Administrators

Step:4

remove dell\rodc_admin Administrators

Refer :

https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-r2-and-2008/cc753223(v=ws.10)

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.