Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

To control which passwords a Windows Server 2016 Read-Only Domain Controller (RODC) may cache, configure its Password Replication Policy (PRP). Allow only the branch users and computers that need offline authentication, keep privileged accounts denied, and verify the account appears in the RODC’s cached-password list before relying on it during a WAN outage.

An account on the allowed list is eligible for caching; it is not necessarily cached yet. A password is cached after the account authenticates through the RODC or an administrator prepopulates it. The policy is not a separate Windows Credential Manager setting. Microsoft’s RODC deployment guidance describes the policy and the distinction between eligibility and an existing cached password.

Before you begin

This procedure assumes the server is already promoted as an RODC in the target Active Directory domain. You also need rights to modify the RODC account and relevant security groups, and access to Active Directory Users and Computers (ADUC) from a domain-joined management computer or domain controller.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Make policy changes and prepopulation while the RODC can communicate with a writable domain controller. Confirm that AD DS replication, DNS, and the RODC’s site and subnet configuration are functioning. If you are deploying an RODC rather than changing an existing one, the AD DS Configuration Wizard exposes PRP controls on its RODC Options page and can export the deployment configuration as a PowerShell script.

How RODC credential caching works

An RODC is a read-only domain controller intended, in part, for locations with less physical security or less reliable connectivity to a hub. Its PRP determines whether it may cache an account’s password-related authentication material. When the RODC cannot reach a writable domain controller, it can authenticate an account locally only if the necessary credential is already cached. If it is not cached, authentication normally depends on reaching a writable DC.

The PRP is expressed through allowed and denied principals. The RODC’s msDS-RevealOnDemandGroup attribute holds allowed principals; msDS-NeverRevealGroup holds denied principals. An account that is neither allowed nor denied is implicitly denied. Explicit deny takes precedence over allow, including when group membership is involved. Review nested as well as direct memberships when checking an account’s effective policy.

The default policy is restrictive: the Allowed RODC Password Replication Group is allowed but initially empty, while the Denied RODC Password Replication Group and privileged principals are denied. Defaults may have been changed in your domain, so inspect the actual policy instead of assuming it is intact. Retain protections for groups and accounts such as Administrators, Server Operators, Backup Operators, Account Operators, Domain Admins, Enterprise Admins, Schema Admins, Group Policy Creator Owners, Cert Publishers, domain controllers, and the domain’s krbtgt account. See Microsoft’s guidance on default denied RODC password-replication members.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure the PRP in Active Directory Users and Computers

1. Create a narrowly scoped group

Create a security group for the branch or RODC, for example Branch1-RODC-Offline-Logon. Add only users and computer accounts that genuinely need to authenticate locally during a WAN outage. Include service accounts only when there is a documented operational need and the credential exposure is accepted.

A dedicated group configured on one RODC is usually easier to scope and audit than a broad organizational group. The built-in Allowed RODC Password Replication Group is domain-local and its membership can permit caching on RODCs across the domain, so use it only when that wider scope is intentional.

2. Open the RODC’s Password Replication Policy

  1. Open Active Directory Users and Computers.
  2. Expand the domain and open the Domain Controllers organizational unit.
  3. Right-click the target RODC and choose Properties.
  4. Open the Password Replication Policy tab.

3. Add the allowed group

  1. Under the list of accounts whose passwords are allowed to replicate, choose Add.
  2. Select Allow passwords for the account to replicate to this RODC.
  3. Select the group you created, such as Branch1-RODC-Offline-Logon, and confirm.
  4. Review the denied list on the same tab. Preserve the default privileged-account protections and your organization’s security baseline.
  5. Click Apply, then OK.

Allow time for the change to replicate. A policy update does not itself populate the password cache. Exact displayed entries can vary with domain configuration and Windows Server generation; do not replace the deny list wholesale to solve an authentication problem.

Verify policy and cache with repadmin

Run repadmin /prp from a management computer or domain controller and target the RODC by name. Microsoft documents these commands as querying a writable domain controller, not the RODC itself. Replace BRANCH1-RODC01 below with the RODC’s hostname.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
repadmin /prp view BRANCH1-RODC01 allow
repadmin /prp view BRANCH1-RODC01 deny
repadmin /prp view BRANCH1-RODC01 reveal
repadmin /prp view BRANCH1-RODC01 auth2
  • allow lists principals permitted by policy.
  • deny lists denied principals.
  • reveal lists accounts whose credentials are actually cached. This is the key check before depending on offline authentication.
  • auth2 records accounts authenticated by the RODC; it is not the same as the cached-password list.

To check an account’s effective policy, use its account name; use a distinguished name if the name is ambiguous:

repadmin /prp view BRANCH1-RODC01 username
repadmin /prp view BRANCH1-RODC01 "CN=Alex Smith,OU=Users,DC=contoso,DC=com"

You can also add or remove an allowed principal from the command line:

repadmin /prp add BRANCH1-RODC01 allow "Branch1-RODC-Offline-Logon"
repadmin /prp delete BRANCH1-RODC01 allow "Branch1-RODC-Offline-Logon"

For a group outside the default search context, use its distinguished name, for example "CN=Branch1-RODC-Offline-Logon,OU=Groups,DC=contoso,DC=com". repadmin /prp supports view, add, delete, and move operations, but it cannot directly add or remove deny-list entries; manage those through ADUC or scripting. Refer to the repadmin PRP command reference.

Prepopulate credentials and test

Prepopulation is useful before a planned outage, branch deployment, or maintenance window. First ensure the account is permitted and not denied, then use the RODC’s Password Replication Policy management interface to search for the account and request prepopulation. Tool labels can vary slightly by management tool and build. Confirm afterward with:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
repadmin /prp view BRANCH1-RODC01 reveal

Do not treat an entry in the allow list as proof of a cached password. If not prepopulating, have the account successfully authenticate through the RODC while a writable DC is reachable, then check reveal.

Before a real WAN outage, run a controlled test. Confirm the intended user or computer is allowed, not denied, and listed by reveal. In an approved maintenance window, make the writable DC unreachable while keeping the RODC and local DNS available. Test a known cached account and, if useful, an allowed-but-not-cached account. A cached, permitted account may authenticate locally; an allowed account without a cached password generally cannot authenticate offline. Do not test denied privileged accounts unless explicitly authorized.

Successful interactive logon does not guarantee that every domain-dependent function will work. DNS, authorization, Group Policy, file servers, applications, and other services can have their own connectivity requirements.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting

Allowed, but offline logon fails

  • Check whether the account ever authenticated through this RODC or was prepopulated.
  • Confirm it appears in reveal, not merely allow.
  • Inspect direct and nested membership for an explicit deny, including privileged groups.
  • Check that the PRP change replicated and that the account is using the intended RODC.
  • Consider whether the password changed after the credential was cached; verify the cache state again.
  • Check local DNS and site configuration, and determine whether the logon or subsequent operation still requires a writable DC.

Useful checks:

repadmin /prp view BRANCH1-RODC01 username
repadmin /prp view BRANCH1-RODC01 allow
repadmin /prp view BRANCH1-RODC01 deny
repadmin /prp view BRANCH1-RODC01 reveal

ADUC and repadmin show different results

The MMC interface can obtain PRP information from a domain controller, including the RODC, while repadmin /prp queries a writable DC. Replication inconsistency can therefore produce different views. Check AD replication and compare the policy as seen from the writable DC with the RODC. Microsoft documents this behavior in its article on RODC password replication and incorrect permissions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Unexpected passwords are being cached

Check effective group membership and the RODC’s allowed and denied attributes, including nested memberships and replication delays. Also investigate whether the RODC has incorrectly been granted Replicating Directory Changes All on the domain partition. Microsoft identifies that permission as a possible cause of an RODC replicating user passwords as if it were writable. Do not respond by weakening deny protections; correct the unexpected permission or policy membership.

Best Value
Sale
BrosTrend 5Gb PCIe Network Card for PC Windows 11/10, Windows Server 2022
  • Unparalleled 5 Gbps Speed: Future-proof your desktop PC's wired connection with the 5 Gbps PCIe network card. It takes your connectivity to the next level with speeds 5 times faster than a typical Gigabit PCIe Ethernet card
  • Hyper-Fast Internet Access: Experience boosted speed, reduced latency, and enhanced responsiveness with the PCIe network card, making your computer ideal for intense gaming and flawless streaming. Harness your ISP's speeds with added 5GBASE-T technology
  • Instant Local Network Transfer: Whether integrated into your client PC or host server, the PCI Express network card establishes lightning-fast connections with other devices in your local network, elevating the efficiency of data transmission
  • Crafted for Maximum Reliability: Enhanced with dense fins and high-quality aluminum construction, the PCIe nic optimizes heat dissipation, ensuring consistent performance and reliability
  • Supports Windows 11 / 10 / Windows Server 2022: Simply install the driver from the included disc or download it from our website to achieve the full 5Gbps speed. Supports Wake on LAN and QoS

Logon still fails when the WAN is down

Credential caching is only one part of branch availability. If the site has no Global Catalog and universal group membership caching is not enabled for that site, users may have difficulty logging on. Universal Group Membership Caching concerns membership information; it is not a substitute for caching the account password. Review Microsoft’s AD DS deployment guidance, and separately validate local DNS, resource availability, and application dependencies.

Remove a cached credential when access changes

Removing an account from an allow group changes eligibility; do not assume it immediately removes a credential already cached on the RODC. When an employee leaves the branch, a device is retired, a role changes, a site closes, or compromise is suspected:

  1. Remove the account from the branch’s allowed group or otherwise update its effective PRP.
  2. Verify the resulting policy and allow for replication.
  3. Use the RODC management interface or supported credential-removal operation in your tools to delete the existing cached credential.
  4. Run repadmin /prp view BRANCH1-RODC01 reveal and confirm the account is no longer listed.

Follow your incident-response process if the RODC may have been physically compromised; policy cleanup alone does not establish that exposed credentials are safe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose accounts by need, not convenience

Allow an account only when it must authenticate at the branch, must continue to do so while the WAN is unavailable, and the organization accepts storing its credential on that RODC. Branch users and workstation accounts are common candidates. Privileged accounts, domain controllers, and unnecessary service accounts are not. Because a compromised RODC can expose authentication material it holds, narrowly scoped groups and periodic reviews are important safeguards.

If the branch can tolerate dependence on the WAN, leaving accounts uncached minimizes credential exposure. Universal Group Membership Caching may help a site without a local Global Catalog, but addresses group-membership information rather than password availability. A writable DC offers broader local AD functionality but carries a substantially greater security impact if the branch is compromised. Cloud identity or application-specific offline access may be architectural alternatives, not drop-in replacements for RODC PRP.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.