Hi,
You can consider using Administrator Role Separation Configuration. This permits a local branch user to log on to an RODC and perform
maintenance work on the server, such as upgrading a driver. However, the branch user cannot log on to any other domain controller or perform any other administrative task in the domain.
For more information, please refer to:
Administrator Role Separation Configuration
http://technet.microsoft.com/en-us/library/cc732301(WS.10).aspx
AD DS: Read-Only Domain Controllers
http://technet.microsoft.com/en-us/library/cc732801(WS.10).aspx
Hope this helps.
Regards,
Bruce
Forum Support
Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback
for TechNet Subscriber Support, contact tnmff@microsoft.com.