Skip to main content
Version: 2.2.1-preview

AD-ROOTDSE-03 - Root DSE synchronized status should be retrievable

Overview​

The Root DSE (Directory Service Agent) synchronization status indicates whether a domain controller has completed its initial replication with replication partners:

  • Directory Consistency: Unsynchronized DCs may have stale data
  • Authentication Reliability: Users may experience authentication failures
  • Replication Health: Indicates overall replication topology health
  • Operational Readiness: New or recovered DCs need to complete sync before serving clients

A synchronized status (isSynchronized = TRUE) indicates the DC is ready to serve directory requests with current data.

Security Recommendation​

  • Monitor synchronization status after DC promotion or recovery
  • Investigate DCs that remain unsynchronized for extended periods
  • Ensure all DCs complete initial synchronization before production use
  • Include synchronization status in regular health checks
  • Alert on unexpected synchronization failures

How the Test Works​

This test checks the Root DSE isSynchronized attribute and reports:

  • Synchronization status (Yes/No)
  • Server DNS name
  • Domain, forest, and DC functionality levels
  • Test-MtAdDisabledReplicationConnectionCount - Checks for disabled replication connections
  • Test-MtAdNonAutoReplicationConnectionCount - Identifies manual replication connections

Test Metadata​

FieldValue
Test IDAD-ROOTDSE-03
SeverityUnknown
SuiteActive Directory
CategoryAD.Replication
PowerShell testTest-MtAdRootDseSynchronizedStatus
TagsAD, AD-ROOTDSE-03, AD.Replication

Source​

  • Pester test: tests/ad/replication/Test-MtAdRootDseSynchronizedStatus.Tests.ps1
  • PowerShell source: powershell/public/ad/replication/Test-MtAdRootDseSynchronizedStatus.ps1