Re: Denay replication in AD



if the person is an ADMIN on ANY DC, you CANNOT prevent that person from
changing anything in AD.

It is that simple.... Longhorn server will provide a read-only DC which will
help you in what you want --> admin on a DC and to manage all kinds of
things, BUT not change ANYTHING in AD

if you want to prevent that person from changing anything in AD, either
remove his permissions or remove his domain admin membership....

can you explain what that person needs to do within the branch office?

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"mostarx" <jurislav@xxxxxxxxx> wrote in message
news:1167257091.512585.254040@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Because I do not want that admin on branch office can any change on AD.
Is thare way that i make AD on specific DC unwritable, so that nobady
can make any user or any changes.

Thank you

Harj je napisao/la:
Hi,

Well this can be done but like Jorge asks, is why?

To disable outbound replication for a particuar DC, use the following
command:
repadmin /options <dc name> +DISABLE_OUTBOUND_REPL

To re-enable outbound replication, run:
repadmin /options <dc name> -DISABLE_OUTBOUND_REPL

To disable inbound replication for a particular DC, use the following
command:
repadmin /options <dc name> +DISABLE_INBOUND_REPL

To enable inbound replication, run:
repadmin /options <dc name> -DISABLE_INBOUND_REPL

Good luck

Harj Singh
Power your Active Directory
www.specopssoft.com



Jorge de Almeida Pinto [MVP - DS] wrote:
nope...

why do you want this?

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG (WEB-BASED)--> http://blogs.dirteam.com/blogs/jorge/default.aspx
BLOG (RSS-FEEDS)--> http://blogs.dirteam.com/blogs/jorge/rss.aspx
------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no
rights!
* Always test before implementing!
------------------------------------------------------------------------------------------
#################################################
#################################################
------------------------------------------------------------------------------------------
"mostarx" <jurislav@xxxxxxxxx> wrote in message
news:1167251821.274246.219400@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hello

I need advice. I have Active directory with four domain controller on
win 2003 in diferent sites. Problem is that I want that new user and
other settings can be changed only on first DC which is create when I
was create domain. Is there some way that I denay any changes on
other
DC or that I denay replicaion in two way so replication can go only
from first DC to other DC-s, not from others DC to first DC.

Thank you




.



Relevant Pages

  • Re: Cross reference for the specified naming context could not be
    ... replication errors CAN turn into the future gates of hell and headaches. ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... I already did the extension of my Forest. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Forcing Intersite Group Policy Replication AD 2003
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... intra site replication is unscheduled and quick ...
    (microsoft.public.windows.server.active_directory)
  • Re: Multiple Accounts Error with only one Computer Account in Domain
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... There are multiple accounts with name cifs/computer3 of type ... container replication with replmon and it says there are no replication ...
    (microsoft.public.windows.server.active_directory)
  • Re: upgrading ad schema windows 2003 R2
    ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... replication seems to work fine wher most ... but make sure to test the schema change in a test environment! ...
    (microsoft.public.win2000.active_directory)
  • Re: Local SID v. Domain SID.
    ... meaning being admin on PC1 also means being admin on PC2 ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... Dean Wells [MVP / Directory Services] ...
    (microsoft.public.windows.server.active_directory)

Loading