mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-27 08:13:39 +00:00
as per internal discussion and tests, we confirmed with engineering team there is a known issue between cloud trust and real RODC: 1. WHfB Cloud trust would only work with RODC if the user’s password can’t be cached by that RODC (as per the password replicdation policy). that is, RODC will to return TGT_Revoked to the client after successfully verifying the partial tgt from WHfB cloud trust client if the user is supposed to have a password cached locally on local RODC. 2. Auth can be successful if the same RODC has KDC certs and then it can failover to Key trust.