Posted By: extreme | Feb 19th @ 6:39 PM
page 1 of 1
Comments: 2 | Views: 166

Ok, I know this is short notice, but what would you like to ask the AD program managers? 

I have some of my own thoughts, but I figure I'd just throw this post out there to see if anyone has any Qs they'd like to ask or have them talk about/clarify.

I'm doing interviews tomorrow.

I would like to know if the Directory Services Restore Mode password is cached anywhere on a Read Only Domain Controller? The question was asked today at TechEd and the answer from the Senior Program Manager was "I don't know."
Hey IT Pro,

I forwarded your question to one of our DS guys and here is his reply (thanks Gregoire!)

"There is a DSRM account per domain controller (RODC included), which is a local account (in the registry, not in AD).

Note that the DSRM account, and therefore the DSRM password, is different on every domain controller, so if a hacker manages to get the DSRM password of an RODC, only this RODC is compromised."

Hope this helps.

Joey

page 1 of 1
Comments: 2 | Views: 166