In the Password Replication Policy, you can specify whose passwords are allowed to replicate to the read-only domain controller ...