Mcitp 70-640 ⇒ | ESSENTIAL |
  中国科学院大学学报 mcitp 70-640 2021, Vol. 38 mcitp 70-640Issue (5): 611-623 mcitp 70-640 mcitp 70-640  PDF    

Mcitp 70-640 ⇒ | ESSENTIAL |

Configure the Allowed RODC Password Replication Group – leave the user out of that group. Then use Denied RODC Password Replication Group to explicitly deny caching for that user. (But if user is not in Allowed, their password never caches – they can only authenticate when a writable DC is reachable, which defeats the "only during maintenance window". For time-based access, you would instead use Group Policy with logon hours and ensure the RODC has the password cached only during the window.)