# DFS Namespaces and Replication: Reliable File Server Setup

Source: https://srvscripts.com/guides/dfs-namespaces-and-replication/
Updated: 2026-10-07
Publisher: srvScripts (https://srvscripts.com/)

A DFS namespace gives users a single stable path such as `\\corp.example.com\files\Finance` regardless of which physical server holds the data, which makes server replacements invisible to drive mappings. DFS Replication keeps a copy of that data on a second server, for a branch office or a warm standby. The two features are independent but usually deployed together. This walkthrough uses two Windows Server 2025 file servers; the steps are the same on 2019 and 2022.

In short: Install FS-DFS-Namespace and FS-DFS-Replication on both servers, create a domain-based namespace in Windows Server 2008 mode with New-DfsnRoot -TargetPath \\fs01\files -Type DomainV2 -Path \\corp.example.com\files, add folders with…

**Short answer:** Install `FS-DFS-Namespace` and `FS-DFS-Replication` on both servers, create a domain-based namespace in Windows Server 2008 mode with `New-DfsnRoot -TargetPath \\fs01\files -Type DomainV2 -Path \\corp.example.com\files`, add folders with `New-DfsnFolder` pointing at the shares, then create a replication group with `New-DfsReplicationGroup`, `Add-DfsrMember`, `New-DfsReplicatedFolder`, `Add-DfsrConnection` and `Set-DfsrMembership` with a primary member and a staging quota sized to the largest files. Verify with `dfsrdiag backlog` and Event ID 4104 on the receiving server.

## Install the roles and prepare the shares

On both file servers:

```
Install-WindowsFeature FS-FileServer, FS-DFS-Namespace, FS-DFS-Replication -IncludeManagementTools
New-Item D:\Shares\Finance -ItemType Directory
New-SmbShare -Name Finance -Path D:\Shares\Finance -FullAccess "CORP\Domain Admins" -ChangeAccess "CORP\Finance"
```

Set NTFS permissions on the folder itself with the same groups; share permissions should stay simple and NTFS should carry the detail. Data volumes need at least 10 percent free, because DFS Replication keeps its staging area on the same volume by default.

## Create the domain-based namespace

Run this from either server or a management station with the DFS tools:

```
New-Item C:\DFSRoots\files -ItemType Directory
New-SmbShare -Name files -Path C:\DFSRoots\files -ReadAccess Everyone
New-DfsnRoot -TargetPath "\\fs01.corp.example.com\files" -Type DomainV2 -Path "\\corp.example.com\files" -EnableAccessBasedEnumeration $true
New-DfsnRootTarget -Path "\\corp.example.com\files" -TargetPath "\\fs02.corp.example.com\files"
New-DfsnFolder -Path "\\corp.example.com\files\Finance" -TargetPath "\\fs01.corp.example.com\Finance"
New-DfsnFolderTarget -Path "\\corp.example.com\files\Finance" -TargetPath "\\fs02.corp.example.com\Finance"
```

DomainV2 is the Windows Server 2008 mode, which supports access-based enumeration and more than 5,000 folders; every domain today qualifies. Two root targets make the namespace itself highly available. In the DFS Management console you can set referral ordering per folder: “Lowest cost” uses AD site costs so branch users hit their local server, and “Exclude targets outside of the client’s site” stops them failing over to the head office when the local copy is down, which is sometimes preferable to a slow WAN experience. Set the client cache duration to 300 seconds for folder referrals during a migration so changes take effect quickly.

## Configure DFS Replication

Pick the server that holds the authoritative data as the primary member; on the first sync, its content wins and conflicting files on the other member are moved to the `DfsrPrivate\PreExisting` folder.

```
New-DfsReplicationGroup -GroupName "Finance-RG" -DomainName corp.example.com
Add-DfsrMember -GroupName "Finance-RG" -ComputerName fs01, fs02
New-DfsReplicatedFolder -GroupName "Finance-RG" -FolderName "Finance" -DfsnPath "\\corp.example.com\files\Finance"
Add-DfsrConnection -GroupName "Finance-RG" -SourceComputerName fs01 -DestinationComputerName fs02
Set-DfsrMembership -GroupName "Finance-RG" -FolderName "Finance" -ComputerName fs01 -ContentPath D:\Shares\Finance -PrimaryMember $true -StagingPathQuotaInMB 16384 -Force
Set-DfsrMembership -GroupName "Finance-RG" -FolderName "Finance" -ComputerName fs02 -ContentPath D:\Shares\Finance -StagingPathQuotaInMB 16384 -Force
Update-DfsrConfigurationFromAD -ComputerName fs01, fs02
```

The staging quota is the setting that matters. The default 4 GB is too small for anything with large files; size it to at least the combined size of the 32 largest files in the folder, which you can calculate with `Get-ChildItem D:\Shares\Finance -Recurse -File | Sort-Object Length -Descending | Select-Object -First 32 | Measure-Object Length -Sum`. Too small a quota causes Event ID 4202 and 4204 warnings and throttles replication. For a very large initial seed over a slow link, pre-stage the data on the second server with `Export-DfsrClone` and `Import-DfsrClone`, or robocopy with `/copyall /mir` before creating the membership, so DFS-R only has to reconcile hashes.

## Understand what DFS-R does not do

DFS Replication is not a backup and not a lock manager. Deleting a file on one server deletes it everywhere within minutes, and two users editing the same file on different servers produce a conflict that is resolved by last-writer-wins, with the loser stored under `DfsrPrivate\ConflictAndDeleted`. Keep proper backups of at least one member and consider Volume Shadow Copies on both. For active-active use of the same folder, prefer a single target with failover or a clustered file server; for branch caching with one writer, DFS-R is ideal. Files with the temporary attribute and open files with exclusive locks are skipped until they close.

## Verify and monitor

```
dfsrdiag backlog /rgname:Finance-RG /rfname:Finance /smem:fs01 /rmem:fs02
Get-DfsrBacklog -GroupName Finance-RG -FolderName Finance -SourceComputerName fs01 -DestinationComputerName fs02
Get-DfsrState -ComputerName fs02
dfsdiag /testdfsintegrity /dfsroot:\\corp.example.com\files /full
```

Event ID 4104 in the DFS Replication log on the receiving server confirms the initial replication finished; 4102 means it started and 2212 means the database is being rebuilt after a dirty shutdown. A backlog that never reaches zero points at staging quota, an open file or a network issue. Test the namespace from a client with `dfsutil /pktinfo` and by opening `\\corp.example.com\files\Finance` after stopping the LanmanServer service on fs01; the client should fail over to fs02 within the referral cache time.

A common pitfall is a folder target created against a server’s IP address rather than its FQDN, which breaks Kerberos and produces access denied errors that look like permissions. Map the namespace path, not the server path, in drive maps, as described in [map network drives with Group Policy Preferences](/guides/map-network-drives-group-policy/).

## DFS Namespaces and Replication at a glance

**Official documentation:** [Active Directory Domain Services docs](https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/active-directory-domain-services), [Windows Server documentation](https://learn.microsoft.com/en-us/windows-server/).

**Related guides:** [Enable and use the Active Directory Recycle Bin to restore deleted objects](https://srvscripts.com/guides/enable-active-directory-recycle-bin/) · [What changed in DirectAdmin system backups after sysbk was replaced (1.709) — and what you must add](https://srvscripts.com/guides/directadmin-system-backup-sysbk-1-709/) · [Disable RDP drive, clipboard and USB redirection with Group Policy](https://srvscripts.com/guides/disable-rdp-drive-redirection-gpo/).

**See also:** [DFS Replication Backlog: Check It with PowerShell and Fix It](/guides/dfs-replication-backlog-powershell/) · [Event ID 4012 DFSR: Replicated Folder Offline Too Long (Fix)](/guides/event-id-4012-dfsr/)

## Frequently asked questions

### Does DFS Replication work over a slow WAN link between sites?

Yes; it uses remote differential compression to send only changed blocks and supports bandwidth throttling and schedules per connection, but seed the initial copy locally or with a cloned database to avoid days of transfer.

### How long does the initial DFS replication take?

For a pre-seeded folder, hash verification of 1 TB typically finishes within a few hours; without pre-seeding, the time is the data size divided by the effective link speed, which can mean days for large folders across a WAN.

### Can I undo DFS Replication without losing data?

Yes; remove the membership with `Remove-DfsrMember` or delete the replication group, and the data stays on both servers, though you should stop users writing to the secondary first to avoid unreplicated changes being stranded there.
