Skip to content

Real-World Scenarios

Problem

Cross-site replication delays occur when replication between domain controllers (DCs) in different sites is significantly slower than expected, often due to network latency, suboptimal site link configurations, or bandwidth limitations.

Symptoms

  • Replication latency exceeding 15 minutes.
  • repadmin /replsum showing "replicated" status but delayed timestamps.
  • Users in remote sites experiencing stale password caches or permission issues.

Resolution Steps

  1. Verify Site Link Costs:
    Use the Active Directory Sites and Services console to ensure site links have appropriate costs. Lower costs prioritize faster replication.
    Get-ADReplicationSiteLink -Filter * | Select-Object Name, Cost  
    
  2. Optimize Site Link Bandwidth:
    Adjust the "Maximum Number of Replications per Site Link" setting to avoid congestion.
    repadmin /setmaxreplications <SiteLinkName> <MaxValue>
    
  3. Force Replication:
    Use repadmin /replicate to manually trigger replication between specific DCs.
    repadmin /replicate <SourceDC> <DestinationDC> <NCName>
    
  4. Monitor Network Health:
    Use ping and tracert to identify network bottlenecks between sites.

Partial Replication Failures: DNS Resolution and Schema Issues

Problem

Partial replication occurs when some directory data fails to replicate, often due to DNS misconfigurations, schema inconsistencies, or inaccessible replication partners.

Symptoms

  • repadmin /showrepl showing "partial" status for specific NCs.
  • Users unable to authenticate or access resources due to missing attribute updates.
  • Event ID 13516 in Event Viewer (replication failure).

Resolution Steps

  1. Check DNS Resolution:
    Ensure DCs can resolve each other via SRV records. Use nslookup to verify:
    nslookup -type=srv _ldap._tcp.dc._dc
    
    If records are missing, configure them using DNS management tools like dnscmd or DNS Manager.
  2. Validate Schema Consistency:
    Run dcdiag /test:schema to check for schema conflicts.
    dcdiag /test:schema /v
    
  3. Force Schema Replication:
    Use repadmin /syncall to force replication of the schema partition.
    repadmin /syncall /AtoD /e
    
  4. Check Replication Partners:
    Ensure replication partners are listed in repadmin /showrepl and are reachable.

Replication Conflicts: Attribute Overwrites and Manual Resolution

Problem

Replication conflicts arise when two DCs update the same attribute simultaneously, leading to data inconsistencies.

Symptoms

  • Event ID 13517 (replication conflict detected).
  • Users with conflicting attribute values (e.g., password hashes, group memberships).
  • repadmin /showrepl showing "conflict" in replication metadata.

Resolution Steps

  1. Identify Conflicting Attributes:
    Use repadmin /showrepl to locate conflicting NCs and attributes.
    repadmin /showrepl <DCName> <NCName>
    
  2. Resolve Conflicts Manually:
  3. Use repadmin /repl to force a re-replication of the affected NC.
  4. Avoid using ntdsutil for conflict resolution, as it is designed for database maintenance tasks.
  5. Prevent Future Conflicts:
    Enforce stricter replication intervals using repadmin /set to reduce overlap.

Key takeaways

  • Use repadmin /replsum and dcdiag for quick replication health checks.
  • DNS resolution is critical for cross-site replication; validate SRV records regularly.
  • Force replication with repadmin /replicate or repadmin /syncall for partial failures.
  • Resolve conflicts by re-replicating affected NCs using repadmin /repl.
  • Monitor network latency and site link costs to prevent cross-site delays.