SCVMM 2008, R2: Using Read Only Domain Controller (RODC) as a Host

A Read Only Domain Controller (RODC) can only be used as a Host if it was already a Host prior to being promoted. If a RODC needs to be used as a Host and was not previously managed by SCVMM, it will have to be demoted to a member server and made a managed Host […]

A Read Only Domain Controller (RODC) can only be used as a Host if it was already a Host prior to being promoted. If a RODC needs to be used as a Host and was not previously managed by SCVMM, it will have to be demoted to a member server and made a managed Host prior to promotion back to RODC. Important: Although a Read Only Domain Controller can be used as Host in SCVMM, this’s not the recommended usage of a Read Only Domain Controller.

Resolution

  1. If server is a RODC, it must be demoted to member server via DCPROMO.
  2. Add member server to SCVMM via Admin Console. You must not install VMMAgent manually or necessary groups’ll not be created.
  3. Once member server can be managed by SCVMM, proceed with next steps.
  4. Log onto a Domain Controller and go to Active Directory Users and Computers
  5. Add VMM Server Computer Account to Built-In Administrators Group in Active Directory
  6. (VMM Server=AP2118514 in this example)
  7. On member server, START>RUN>DCPROMO
  8. Follow wizard, and select Read Only Domain Controller as an option, leaving DNS and Global Catalog checked.
  9. After DCPROMO wizard completes , allow reboot to complete
  10. On RODC, under CONTROL PANEL>WINDOWS FIREWALL, clicked on “Allow a Program through Windows Firewall”
    • Make sure these are checked:
      • Hyper-V
      • Hyper-V Management Clients
      • Windows Management Instrumentation (WMI)
      • Windows Remote Management
  11. On SCVMM Admin Console, selected the host (now an RODC) and selected REFRESH from the ACTION panel.
    • Action should complete successfully.
  12. Created new VM on the host as a test
    • Action should complete successfully.

NOTE: If above steps don’t work, demote server to a member server and start over. This time, after Step 7, on the “Delegation of RODC Installation and Administrators” section of the wizard, set BUILTIN\Administrators as the group.