
Is there way to lock down a FreeIPA replica so that it can only receive updates but not make changes to other FreeIPA systems.

Some of our environments are considered less secure than others, our security team are concerned that a FreeIPA in a less secure environment might become compromised at which point unwarranted changes could be applied that affect our secure production environments.

Thanks a lot