We hit a false-positive. <img width="1291" height="885" alt="Image" src="https://github.com/user-attachments/assets/e0795f9f-c9e7-44cd-8419-1cf2e4d1e532" /> AzureADKerberos is a member of the Read-Only Domain Controllers group, but isn't a real RODC. The msDS-isRODC is missing on that computer account.
We hit a false-positive.
AzureADKerberos is a member of the Read-Only Domain Controllers group, but isn't a real RODC.
The msDS-isRODC is missing on that computer account.