Site to site replication


  • Hi, 

    we have 4 domain controllers - all are in different locations and in separate ad sites. How can I speed replication times between the domains because once the user is locked out we are having to look for the domain controller they are locked out on and then unlock them on that domain controller because the other DC's aren't aware of the lock out yet. 

    Thank you

    Monday, November 28, 2016 1:52 PM

All replies

  • From the Active Directory Sites and Services console you can reduce the connection object to 15mins of replication.

    Another way to achieve that would be to run a script at a minute or two with

    repadmin /syncall /force

    from each domain controller, but that doesn't scale well.

    Monday, November 28, 2016 2:21 PM
  • You could also enable Active Directory Replication: Change Notification.  This will replicate changes between sites without having to wait 15 min.

    But Account locked out is an "Urgent Replication" and should be replicated within few seconds (±15 to 30 sec).

    This posting is provided AS IS without warranty of any kind

    Monday, November 28, 2016 2:45 PM
  • Hi, it is already 15 minutes but shouldn't account lockout's be sync'd almost instantly?
    Monday, November 28, 2016 9:21 PM
  • Thank you, I will look into this and let you know how it went.
    Monday, November 28, 2016 9:22 PM
  • Hi,

    I am checking how the issue going, if you still have any questions, please feel free to contact us.

    And if the replies as above are helpful, we would appreciate you to mark them as answers, and if you resolve it using your own solution, please share your experience and solution here. It will be greatly helpful to others who have the same question.

    Appreciate for your feedback.

    Best regards,


    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact

    Wednesday, November 30, 2016 2:44 AM