Troubleshoot Active Directory replication errors
Domain controllers disagree about users, passwords or GPOs. Use repadmin and dcdiag to find failing replication links and their causes.
- Server 2016
- Server 2019
- Server 2022
- Server 2025
With more than one domain controller, every change must replicate. When it stops, users see different passwords, group memberships or policies depending on which DC they hit.
Symptoms
- A password change or new user works on one DC but not another.
- GPO changes reach some sites but not others.
repadminshows failures, or event 2042 says it’s been too long since replication.
Cause
Most replication failures come down to a few causes:
- DNS: DCs can’t resolve each other’s names or
_msdcsrecords (error 8524). - Network: firewall or routing blocks RPC (error 1722, RPC server unavailable).
- Time: clock skew breaks Kerberos. See Fix time sync in an Active Directory domain.
- A DC offline too long: past the tombstone lifetime (180 days by default in modern forests), it must not replicate back in.
- Hardware or disk problems on a DC.
Fix
1. Get the big picture
On a DC, in an elevated prompt:
repadmin /replsummary
This lists each DC with its largest delta and failure count. Focus on the DCs with failures.
2. Find the failing link and error
repadmin /showrepl * /csv > showrepl.csv
Open the CSV and filter on Number of Failures greater than zero. Note the Last Failure Status code.
3. Run the DC diagnostics
dcdiag /v /c /e > dcdiag.txt
Look for failed tests, especially Replications, Connectivity and DNS.
4. Fix the underlying cause
- 8524 or name errors: see Troubleshoot DNS for Active Directory.
- 1722: test RPC from one DC to the other with
Test-NetConnection <dc> -Port 135, and check firewalls between sites. - Access denied or Kerberos errors: check time on both DCs and the DC’s secure channel.
5. Force replication and re-check
repadmin /syncall /AdeP
repadmin /replsummary
If that didn’t work
- A DC that’s been offline past the tombstone lifetime should be demoted and rebuilt, not forced to replicate.
- Check SYSVOL separately: it replicates with DFSR. See DFSR events 4012 and 2213.
When to call us
- Replication has been failing for weeks, or a DC has been offline for months.
- You’re considering seizing FSMO roles or doing a metadata cleanup. Mistakes here can damage the whole domain.
Sources
Didn’t fix it? We can take a look.
Open a ticket