Domain controllers rarely fail loudly. Replication stops on one partition, SYSVOL falls behind, a DC quietly stops advertising as a global catalog, and users only notice weeks later when Group Policy or logon behaves oddly at one site. Two built-in tools cover most of the diagnosis: dcdiag runs a battery of tests against a DC, and repadmin reports on replication topology and state. Both ship with the AD DS role and RSAT on Windows Server 2019, 2022 and 2025, and can be run remotely from a management workstation.
Table of Contents
Short answer: Run dcdiag /v /c /d /e /s:DC01 > dcdiag.txt for a full test of every DC in the forest and repadmin /replsummary for a one-page replication status; a healthy environment shows “passed test” for every test and zero in the “fails” columns. The tests that matter most day to day are Connectivity, Advertising, Replications, SysVolCheck, NetLogons, Services, FsmoCheck and DNS. Anything that fails should be investigated with repadmin /showrepl and the event log of the DC named in the output.
Run the standard health pass
A quick pass on one DC:
dcdiag /s:DC01
dcdiag /test:dns /s:DC01 /v
repadmin /replsummary
repadmin /showrepl DC01
For a full forest sweep that is worth keeping as a baseline, use /e (every DC), /c (comprehensive, includes optional tests), /v (verbose) and /d (debug), and redirect to a file. The DNS test is not included by default and is worth running separately because DNS is behind most replication failures. repadmin /replsummary shows each source and destination DC with the largest replication delta, the number of failed attempts and the last error code; a delta over an hour on a site link that should replicate every 15 minutes is a warning sign even without a hard failure.
What the key dcdiag tests mean
- Connectivity: resolves the DC’s GUID-based CNAME in
_msdcsand checks LDAP and RPC binding. A failure here stops all other tests and almost always means a DNS problem or a firewall in the way. - Advertising: confirms the DC is announcing itself as a DC, global catalog and time server through the Netlogon service. A DC that has just been promoted, or whose SYSVOL has not initialised, will fail this and clients will not use it.
- Replications: reports partitions with failed inbound replication and the error code. Cross-reference with
repadmin /showrepl. - SysVolCheck and NetLogons: check the SYSVOL and NETLOGON shares exist and are readable. Failure means Group Policy will not apply from that DC.
- Services: confirms DFSR, DNS, KDC, Netlogon, NTDS, W32Time and others are running.
- KccEvent and KnowsOfRoleHolders: check the Knowledge Consistency Checker is not logging errors and that the DC agrees with the rest of the forest on who holds each FSMO role. See transfer and seize FSMO roles if they disagree.
- FrsEvent and DfsrEvent: look for recent SYSVOL replication errors in the event logs. FrsEvent warnings on a domain migrated to DFSR are normal noise.
- SystemLog: reports any errors in the System event log over the past hour, which catches unrelated problems such as disk warnings.
- DNS: subtests Auth, Basc, Forw, Del, Dyn, RReg and Ext check authority, basic config, forwarders, delegations, dynamic update and record registration. Forwarder warnings for an unreachable upstream are common and usually benign; Del and RReg failures are not.
Read repadmin output correctly
repadmin /showrepl lists each naming context and its inbound neighbours with the last attempt and result. The states you will meet most often:
- “The last attempt was successful”: healthy.
- Error 8453 “Replication access was denied”: a permissions or secure-channel problem.
- Error 1722 “The RPC server is unavailable”: network, DNS or firewall between the DCs.
- Error 8614 “It has been too long since this machine last replicated”: the DC is past the tombstone lifetime and must be demoted and rebuilt.
- Error 1256 or 1908: usually transient after a DC restart; re-check after a few minutes.
For the two most common errors see fix AD replication errors 8453 and 1722. To force replication after a fix, run repadmin /syncall /AdeP on the DC, and repadmin /kcc to have the KCC rebuild the topology. repadmin /showbackup shows when each partition was last backed up, which should be within the last day if system state backups are running.
Watch for the quieter problems
Two things dcdiag does not shout about. First, the SYSVOL migration state: dfsrmig /getglobalstate must report “Eliminated” on any domain that still shows FRS event tests, or Windows Server 2025 DCs will refuse to promote. Second, time skew: w32tm /monitor lists each DC’s offset from the PDC emulator; anything over a few seconds breaks Kerberos and should be corrected using configure NTP time sync for the PDC emulator.
Keep it running
Schedule the full pass weekly with a task that writes the output to a share and mail it, or feed repadmin /replsummary into your monitoring platform and alert on any non-zero fail count. A DC that fails the same test on two consecutive runs is worth a ticket even if nobody has complained yet.
Dcdiag repadmin at a glance

Official documentation: Active Directory Domain Services docs, Windows Server documentation.
Related guides: A basic RMM monitoring policy for small-business endpoints: disk, patching and antivirus · Fix “Invalid Signature Detected: Check Secure Boot Policy” · Deploy Win32 apps with Intune: IntuneWinAppUtil packaging and detection rules.
Frequently asked questions
Does dcdiag need to be run on the domain controller itself?
No; it can target any DC with /s: from a Windows 10/11 workstation with RSAT installed, but running it locally on the DC avoids firewall and RPC issues masking the result.
How long does a full dcdiag /e /c /v run take?
On a forest with a handful of DCs it completes in one to three minutes; large forests with many sites can take 15 minutes or more, mostly waiting on the DNS and cross-site connectivity tests.
Can I run repadmin without domain admin rights?
Read-only commands such as /showrepl and /replsummary work for any authenticated user with LDAP read access, but /syncall and /kcc require rights on the DC and are normally run as a Domain Admin.