How to redirect clients of Active Directory site with RODC to another site when all RODC in site fail?

Yuriy Medvedev 1 Reputation point
2020-07-30T10:31:43.963+00:00

Hello!
We have 3 sites: two central sites A and B with RWDC and remote site C with 1 RODC.
What must we do to redirect clients of site C with RODC to another site A (not to B) with RWDC when RODC in this remote site fail? The access to site B is forbidden for security reasons.

Thank you very much!

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,149 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Hannah Xiong 6,256 Reputation points
    2020-07-31T02:29:49.527+00:00

    Hello,

    Thank you so much for posting here.

    When a user try to authenticate to an RODC, a check is performed to see if the password is cached on the RODC of the site. If the password is cached, the RODC will authenticate the user account locally. If the user’s password is not cached or RODC is not accessible, then the authentication request is forwarded to a writable Domain Controller which in turn authenticates the account and passes the authenticated request back.

    And if the RODC fails, the clients will find other DCs in other site. As mentioned, if site B is forbidden, it will find the DC in site A. Or if we would like to redirect the clients in site C to DC in site A, we could try to enable clients to locate the Next Closest Domain Controller. For more information about this, we could refer to:

    https://video2.skills-academy.com/en-us/windows-server/identity/ad-ds/plan/enabling-clients-to-locate-the-next-closest-domain-controller

    For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong