AD-ROOTDSE-03 - Root DSE synchronized status should be retrievable
Overviewβ
The Root DSE (Directory Service Agent) synchronization status indicates whether a domain controller has completed its initial replication with replication partners:
- Directory Consistency: Unsynchronized DCs may have stale data
- Authentication Reliability: Users may experience authentication failures
- Replication Health: Indicates overall replication topology health
- Operational Readiness: New or recovered DCs need to complete sync before serving clients
A synchronized status (isSynchronized = TRUE) indicates the DC is ready to serve directory requests with current data.
Security Recommendationβ
- Monitor synchronization status after DC promotion or recovery
- Investigate DCs that remain unsynchronized for extended periods
- Ensure all DCs complete initial synchronization before production use
- Include synchronization status in regular health checks
- Alert on unexpected synchronization failures
How the Test Worksβ
This test checks the Root DSE isSynchronized attribute and reports:
- Synchronization status (Yes/No)
- Server DNS name
- Domain, forest, and DC functionality levels
Related Testsβ
Test-MtAdDisabledReplicationConnectionCount- Checks for disabled replication connectionsTest-MtAdNonAutoReplicationConnectionCount- Identifies manual replication connections
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-ROOTDSE-03 |
| Severity | Unknown |
| Suite | Active Directory |
| Category | AD.Replication |
| PowerShell test | Test-MtAdRootDseSynchronizedStatus |
| Tags | AD, AD-ROOTDSE-03, AD.Replication |
Sourceβ
- Pester test:
tests/ad/replication/Test-MtAdRootDseSynchronizedStatus.Tests.ps1 - PowerShell source:
powershell/public/ad/replication/Test-MtAdRootDseSynchronizedStatus.ps1

