Recommended Free Tools
A writable Active Directory domain controller (DC) commits a user’s password change locally, then normally sends an accelerated notification to the domain’s PDC Emulator over Netlogon and RPC. The originating DC and the PDC then distribute the change through ordinary Active Directory replication. That fast notification helps update the PDC; it does not mean every DC at every site already has the new password.
How a password change travels through Active Directory
- The change is committed locally. When a user changes or resets a password through a writable DC, that DC writes the change to its directory.
- The writable DC notifies the PDC Emulator. By default, it sends a password-update notification to the domain’s PDC Emulator role owner using the Netlogon service over RPC. The PDC is a domain-wide role and may be located at another site. Microsoft describes this fast path in its password-change processing and conflict-resolution guidance.
- Ordinary replication distributes the update. The originating DC and the PDC each replicate the password change onward through Active Directory replication. When both copies reach a destination DC, normal conflict resolution applies; the updates carry the same new password value.
- Other sites receive it through the configured topology. The Knowledge Consistency Checker (KCC) builds replication connections using the site and site-link configuration. Connections, schedules, intervals, costs, and network availability influence the route and timing. Microsoft explains the underlying Active Directory replication topology and site topology design.
Sites do not independently push passwords based only on geographic distance. A site link is a configured replication path, and its schedule and interval affect when intersite replication can occur; its cost helps determine route selection. A missing or disconnected site link can prevent changes from reaching parts of the environment.
How long does a password change take to reach every site?
There is no universal cross-site convergence time. The PDC notification is an accelerated step for that DC, not a timer or guarantee for every remote DC. The time for other sites to receive the change depends on replication connections, site-link schedules and intervals, connectivity, and replication health. Check the configured topology and observed replication state rather than assuming a fixed number of minutes.
Microsoft documents default notification delays of 15 seconds before notifying the first replication partner and 3 seconds between notifications to subsequent partners when the relevant intra-site notification attributes are unset. Those figures apply to intra-site replication notifications; they are not an estimate or service-level promise for cross-site password propagation. See Microsoft’s intra-site replication notification guidance.
#1 Best Overall
- Mastering Active Directory: Design, deploy, and protect Active Directory Domain Services for Windows Server 2022, 3rd Edition
- ABIS BOOK
- Packt Publishing
What changes for an RODC or when the PDC is across a WAN?
Read-only domain controllers
An RODC forwards a password-change request it receives to its hub writable DC. The hub handles the request as the first DC to receive it, and the RODC receives the changed password later through normal replication. Until then, authentication may need to be handled by the hub or PDC.
The AvoidPdcOnWan setting
AvoidPdcOnWan is a REG_DWORD under HKEY_LOCAL_MACHINESystemCurrentControlSetServicesNetlogonParameters. It is absent and disabled by default. If set to 1 and the PDC is in a different site, the originating DC skips the immediate password notification to the PDC; ordinary replication updates the PDC later. The setting does not apply when the PDC is local to the site.
Rank #2
Even with the setting disabled, a network outage or RPC problem can prevent the notification. In that case, normal replication is the fallback. The setting also affects PDC contact during some incorrect-password logons, a separate authentication behavior rather than the replication process itself.
Computer account passwords
The PDC notification behavior described here concerns user password changes, not computer account password changes. Microsoft notes that computers retry authentication with the most recent previous password.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsRank #3
Why a new password can work at one site but fail at another
A user may reach a DC that has the new password and then reach another DC whose copy has not yet replicated. Microsoft’s protocol specification explains why fast propagation matters: “if the password is not made available rapidly, a user can experience unpredictable authentication failures when the new password is tried against domain controllers that have not yet replicated it.” The notification to the PDC reduces one part of that delay, but other DCs still depend on replication.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to diagnose delayed or failed propagation
Check the PDC notification events
On Windows Server 2022, Microsoft documents these Directory Service events for the PDC notification path:
Rank #4
- Event 3037: the originating DC successfully sent the notification to the PDC.
- Event 3035: the PDC successfully processed the notification.
- Event 3038: the originating DC encountered an error sending it; Microsoft gives RPC blocked by a firewall as an example.
- Event 3036: the PDC encountered an error processing it.
A failed notification can mean temporary authentication problems until ordinary replication completes. These event IDs are documented for Windows Server 2022; do not assume the same event coverage on every older server version.
Check the topology, schedule, and connectivity
- Confirm that the sites are connected by the intended site links and that the KCC has viable replication connections.
- Review the site-link schedule and replication interval to see when intersite traffic is permitted.
- Verify the selected route and network/RPC reachability between the originating writable DC and the PDC.
- Check replication health and the actual state on the DC that is failing authentication; a successful PDC notification alone does not prove that DC has received the update.
Interpret event 3036 error 8440 narrowly
Microsoft documents a specific interoperability case: a Windows Server 2022-or-later PDC can log event 3036 with error 8440 when a Windows Server 2019-or-earlier BDC sends a notification for a newly created user whose account has not yet replicated to the PDC. Microsoft’s stated mitigation for that scenario is to upgrade the BDC to Windows Server 2022 or later. This does not establish that every 8440 event has the same cause.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




