October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk4 min

How Password Changes Are Communicated Between Active Directory Sites

Active Directory sends user password changes quickly to the PDC Emulator, then relies on configured replication topology and schedules to distribute them across sites.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A writable Active Directory domain controller (DC) commits a user’s password change locally, then normally sends an accelerated notification to the domain’s PDC Emulator over Netlogon and RPC. The originating DC and the PDC then distribute the change through ordinary Active Directory replication. That fast notification helps update the PDC; it does not mean every DC at every site already has the new password.

How a password change travels through Active Directory

  1. The change is committed locally. When a user changes or resets a password through a writable DC, that DC writes the change to its directory.
  2. The writable DC notifies the PDC Emulator. By default, it sends a password-update notification to the domain’s PDC Emulator role owner using the Netlogon service over RPC. The PDC is a domain-wide role and may be located at another site. Microsoft describes this fast path in its password-change processing and conflict-resolution guidance.
  3. Ordinary replication distributes the update. The originating DC and the PDC each replicate the password change onward through Active Directory replication. When both copies reach a destination DC, normal conflict resolution applies; the updates carry the same new password value.
  4. Other sites receive it through the configured topology. The Knowledge Consistency Checker (KCC) builds replication connections using the site and site-link configuration. Connections, schedules, intervals, costs, and network availability influence the route and timing. Microsoft explains the underlying Active Directory replication topology and site topology design.

Sites do not independently push passwords based only on geographic distance. A site link is a configured replication path, and its schedule and interval affect when intersite replication can occur; its cost helps determine route selection. A missing or disconnected site link can prevent changes from reaching parts of the environment.

How long does a password change take to reach every site?

There is no universal cross-site convergence time. The PDC notification is an accelerated step for that DC, not a timer or guarantee for every remote DC. The time for other sites to receive the change depends on replication connections, site-link schedules and intervals, connectivity, and replication health. Check the configured topology and observed replication state rather than assuming a fixed number of minutes.

Microsoft documents default notification delays of 15 seconds before notifying the first replication partner and 3 seconds between notifications to subsequent partners when the relevant intra-site notification attributes are unset. Those figures apply to intra-site replication notifications; they are not an estimate or service-level promise for cross-site password propagation. See Microsoft’s intra-site replication notification guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022
  • Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
  • ABIS BOOK
  • Packt Publishing

What changes for an RODC or when the PDC is across a WAN?

Read-only domain controllers

An RODC forwards a password-change request it receives to its hub writable DC. The hub handles the request as the first DC to receive it, and the RODC receives the changed password later through normal replication. Until then, authentication may need to be handled by the hub or PDC.

The AvoidPdcOnWan setting

AvoidPdcOnWan is a REG_DWORD under HKEY_LOCAL_MACHINESystemCurrentControlSetServicesNetlogonParameters. It is absent and disabled by default. If set to 1 and the PDC is in a different site, the originating DC skips the immediate password notification to the PDC; ordinary replication updates the PDC later. The setting does not apply when the PDC is local to the site.

Even with the setting disabled, a network outage or RPC problem can prevent the notification. In that case, normal replication is the fallback. The setting also affects PDC contact during some incorrect-password logons, a separate authentication behavior rather than the replication process itself.

Computer account passwords

The PDC notification behavior described here concerns user password changes, not computer account password changes. Microsoft notes that computers retry authentication with the most recent previous password.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why a new password can work at one site but fail at another

A user may reach a DC that has the new password and then reach another DC whose copy has not yet replicated. Microsoft’s protocol specification explains why fast propagation matters: “if the password is not made available rapidly, a user can experience unpredictable authentication failures when the new password is tried against domain controllers that have not yet replicated it.” The notification to the PDC reduces one part of that delay, but other DCs still depend on replication.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to diagnose delayed or failed propagation

Check the PDC notification events

On Windows Server 2022, Microsoft documents these Directory Service events for the PDC notification path:

  • Event 3037: the originating DC successfully sent the notification to the PDC.
  • Event 3035: the PDC successfully processed the notification.
  • Event 3038: the originating DC encountered an error sending it; Microsoft gives RPC blocked by a firewall as an example.
  • Event 3036: the PDC encountered an error processing it.

A failed notification can mean temporary authentication problems until ordinary replication completes. These event IDs are documented for Windows Server 2022; do not assume the same event coverage on every older server version.

Check the topology, schedule, and connectivity

  • Confirm that the sites are connected by the intended site links and that the KCC has viable replication connections.
  • Review the site-link schedule and replication interval to see when intersite traffic is permitted.
  • Verify the selected route and network/RPC reachability between the originating writable DC and the PDC.
  • Check replication health and the actual state on the DC that is failing authentication; a successful PDC notification alone does not prove that DC has received the update.

Interpret event 3036 error 8440 narrowly

Microsoft documents a specific interoperability case: a Windows Server 2022-or-later PDC can log event 3036 with error 8440 when a Windows Server 2019-or-earlier BDC sends a notification for a newly created user whose account has not yet replicated to the PDC. Microsoft’s stated mitigation for that scenario is to upgrade the BDC to Windows Server 2022 or later. This does not establish that every 8440 event has the same cause.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.