How to check the replication frequency in a domain with multiple DCs?

Michael Hammond korann at
Thu Feb 28 12:30:45 MST 2013

My understanding is that this should be like password authentication
and try the "convenient" DC and then try the FSMO role holder for PDC
as a reference of last resort iff there is a failure on the leave.

On Thu, Feb 28, 2013 at 2:20 PM, Richard Sharpe
<realrichardsharpe at> wrote:
> On Thu, Feb 28, 2013 at 9:38 AM, Richard Sharpe
> <realrichardsharpe at> wrote:
>> Hi folks,
>> QA have found a problem where sometimes removing a Samba-based member
>> server with 'net ads leave' fails with ENOENT.
>> This is happening in a domain with two DCs and it looks like the
>> problem is related to the fact that sometimes it tries to do the
>> machine account delete on the DC that the join was not done on and the
>> info has not yet replicated.
>> Where can I check for the replication frequency etc in W2K08R2?
> OK, I have found out how to change this:
> However, this suggests that there is a bug in our net ads leave code.
> Consider the following:
> 1. Administrator adds a new DC to the site. However, replication has
> not yet occurred or has not yet completed to the new DC.
> 2. Someone tries to leave the domain from their Samba member server.
> They get a list of DCs with the new DC first in the list.
> 3. Leave fails because that DC does not yet know about the member server.
> Shouldn't we try the next DC in the case of a failure until we exhaust
> all DCs or we get a success?
> --
> Regards,
> Richard Sharpe
> (何以解憂?唯有杜康。--曹操)

More information about the samba-technical mailing list