Reset the credentials that are cached on the RODC.
To reset the credentials that are cached on an RODC, perform the following steps:
1. | Log on to a domain controller or a member computer that has Windows Server 2008 RSAT installed.
|
2. | Click Start, click Administrative Tools, and then click Active Directory Users and Computers.
|
3. | Right-click Active Directory Users and Computers in the console tree, and click Change Domain Controller.
|
4. | On the Change Directory Server window, select a writable domain controller that has W2K8 in the DC Version column and click OK.
|
5. | In the console tree, expand the domain node and select the Domain Controllers node.
|
6. | In the details pane, right-click the RODC that was compromised; then select Delete.
|
7. | Click Yes to confirm the deletion, shown in Figure 1.
|
8. | On
the Deleting Domain Controller page, select Reset All Passwords for
User Accounts That Were Cached on This Read-only Domain Controller, type
a location and filename to export the list of accounts that were cached
on the RODC in the Location field, and click Delete.
|