Active Directory · Troubleshooting

Troubleshooting Replication Topology Errors: Resolving Events 1645, 1925, and KCC Failures

Diagnose and resolve Active Directory Knowledge Consistency Checker failures, Event ID 1925 replication link errors, and Event ID 1645 Kerberos SPN mismatches across enterprise site topologies.

By K Shankar R Karanth Active Directory Troubleshooting Homelab-tested — Windows Server 2025, DFL 2025
Quick idea: Event 1925 indicates that the Knowledge Consistency Checker cannot establish or validate an inbound replication link from a partner domain controller, typically triggered by DNS CNAME lookup failures, blocked RPC ports, or Kerberos SPN registration mismatches recorded in Event 1645.
KCC & ISTG

The built-in engine that evaluates forest topology every fifteen minutes to build a loop-free replication spanning tree.

Event ID 1925

Logged in Directory Service when a destination DC fails to construct a replication link for a directory partition.

Event ID 1645

Fires when authenticated RPC to a replication partner fails because the partner’s SPN is missing or unresolvable.

Understanding the KCC and Event 1925

Active Directory replication does not rely on static point-to-point configurations hard-coded by administrators. Instead, a background process called the Knowledge Consistency Checker (KCC) runs on every domain controller every fifteen minutes. Within a site, the local KCC constructs a bidirectional ring topology ensuring that any domain controller is no more than three replication hops away from any other partner. Across sites, an elected domain controller designated as the Intersite Topology Generator (ISTG) evaluates site links and costs to generate intersite connection objects between bridgehead servers.

Think of the KCC as an automated route-planning service continuously surveying motorways, bridges, and local roads between regional hubs. Under healthy conditions, it opens new paths when a server appears and reroutes around temporary roadblocks. Event ID 1925 fires when the planner attempts to validate an inbound link to a partner, but discovers that the road is impassable—the partner cannot be reached, cannot resolve, or rejects the mutual authentication handshake.

When this failure occurs, the directory partition named in the event—whether the Schema, Configuration, Domain, or an application DNS partition—halts inbound synchronisation from that specific partner. If alternate replication routes exist, replication may temporarily route around the dead link, but redundancy degrades. If the failure affects an isolated bridgehead or a single hub-and-spoke link, directory partitions across entire branch sites fall out of sync.

What the Errors Look Like

When topology generation stalls, the Windows Event Log records distinct warning and error entries in the Directory Service log. Understanding the exact text and the embedded numeric error code is the fastest way to pinpoint the root failure.

Event ID 1925 payload: Logged by source ActiveDirectory_DomainService or NTDS KCC with task category Knowledge Consistency Checker.
Log Name:      Directory Service
Source:        Microsoft-Windows-ActiveDirectory_DomainService
Date:          2026-09-21 01:15:32
Event ID:      1925
Task Category: Knowledge Consistency Checker
Level:         Warning
Computer:      DC02.corp.example.com
Description:
The attempt to establish a replication link for the following writable directory partition failed.

Directory partition:
DC=corp,DC=example,DC=com
Source directory service:
CN=NTDS Settings,CN=DC01,CN=Servers,CN=London-HQ,CN=Sites,CN=Configuration,DC=corp,DC=example,DC=com
Source domain controller address:
d4a8e48b-302a-4638-a5ec-974d758bc69b._msdcs.corp.example.com
Intersite transport (if any):
CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=corp,DC=example,DC=com

This domain controller will be unable to replicate with the source domain controller until this problem is corrected.

User Action
Verify if the source domain controller is accessible or network connectivity is available.

Additional Data
Error value:
8524 The DSA operation is unable to proceed because of a DNS lookup failure.

In many environments, Event 1925 does not appear alone. If the failure stems from Kerberos authentication or an unregistered Service Principal Name (SPN), it is accompanied by Event ID 1645:

Log Name:      Directory Service
Source:        Microsoft-Windows-ActiveDirectory_DomainService
Date:          2026-09-21 01:15:34
Event ID:      1645
Task Category: Replication
Level:         Error
Computer:      DC02.corp.example.com
Description:
Active Directory Domain Services did not perform an authenticated remote procedure call (RPC)
to another domain controller because the desired service principal name (SPN) for the target
domain controller is not registered on the Key Distribution Center (KDC) domain controller
that resolves the SPN.

Target DC:
CN=NTDS Settings,CN=DC01,CN=Servers,CN=London-HQ,CN=Sites,CN=Configuration,DC=corp,DC=example,DC=com
SPN:
E3514235-4B06-11D1-AB04-00C04FC2DCD2/d4a8e48b-302a-4638-a5ec-974d758bc69b/corp.example.com

Additional Data
Error value:
1396 Logon Failure: The target account name is incorrect.

When the failure is intersite and prevents the Intersite Topology Generator from computing a complete spanning tree across all sites, the ISTG logs Event ID 1311:

Log Name:      Directory Service
Source:        Microsoft-Windows-ActiveDirectory_DomainService
Event ID:      1311
Task Category: Knowledge Consistency Checker
Level:         Error
Description:
The Knowledge Consistency Checker (KCC) has detected that problems exist with the following
directory service partition.
Directory partition:
CN=Configuration,DC=corp,DC=example,DC=com
The KCC cannot construct a spanning tree network topology to complete the replication.

Step-by-Step Diagnostic Workflow

Troubleshooting replication topology requires isolating whether the failure is caused by transport-layer network drops, DNS lookup breakdowns, authentication rejections, or corrupted connection objects.

Follow these diagnostic checks in order from local event collection to remote network verification.

# 1. Query the Directory Service log for recent KCC and replication warning events
Get-WinEvent -FilterHashtable @{
    LogName   = 'Directory Service'
    Id        = @(1645, 1925, 1311, 1865)
    StartTime = (Get-Date).AddDays(-1)
} | Format-Table TimeCreated, Id, LevelDisplayName, Message -AutoSize

# 2. Inspect the local failure cache to review all recorded replication errors
repadmin /failcache

# 3. Retrieve structured replication partner failure metadata using PowerShell
Get-ADReplicationFailure -Target (Get-ADDomainController).HostName -Scope Server |
    Select-Object Partner, FailureCount, FirstFailureTime, LastError, LastResult

# 4. Trigger an immediate KCC recalculation on the local domain controller
repadmin /kcc

# 5. Run targeted KCC health tests via dcdiag across the directory service
dcdiag /test:kcc /v
dcdiag /test:KccEvent /v

# 6. Verify which domain controller is the designated Intersite Topology Generator (ISTG)
repadmin /istg *

# 7. Test DNS resolution for the source domain controller GUID-based CNAME record
Resolve-DnsName -Name "d4a8e48b-302a-4638-a5ec-974d758bc69b._msdcs.corp.example.com" -Type CNAME

# 8. Verify the registered Service Principal Names (SPNs) on the source domain controller
setspn -L "DC01"

# 9. Verify RPC endpoint mapper connectivity to the target domain controller over port 135
Test-NetConnection -ComputerName "DC01.corp.example.com" -Port 135
Healthy output check: In a healthy environment, repadmin /failcache returns “KCC has no recorded failures”, and repadmin /kcc completes with “The KCC updated the replication topology successfully.”

Common Causes and Solutions

The table below correlates the specific error codes observed in Event 1925 and Event 1645 with their verification procedures and exact remediation commands.

Cause How to Confirm Fix
DNS CNAME Lookup Failure (Error 8524) Resolve-DnsName fails for <guid>._msdcs.<domain>, or dcdiag /test:dns flags missing CNAME. Reregister DNS records on the source DC and restart Netlogon: ipconfig /registerdns followed by Restart-Service Netlogon.
Missing or Duplicate SPN (Event 1645 / Error 1396) setspn -X reports duplicates, or setspn -L <DCName> lacks the E3514235-4B06-11D1-AB04-00C04FC2DCD2 DSA GUID. Register the missing replication SPN against the target DC computer account: setspn -S "E3514235-4B06-11D1-AB04-00C04FC2DCD2/d4a8e48b-302a-4638-a5ec-974d758bc69b/corp.example.com" DC01.
RPC Endpoint Mapper or High Ports Blocked (Error 1722) Test-NetConnection -Port 135 fails, or high ephemeral RPC ports (49152–65535) are filtered by an intervening firewall. Enable the built-in Windows Defender firewall group across both servers: Enable-NetFirewallRule -DisplayGroup "Active Directory Domain Services".
Site Link Disjointedness or Spanning Tree Failure (Event 1311) Event 1311 appears on ISTG servers; “Bridge all site links” (BASL) is disabled without explicit Site Link Bridges. Re-enable transitive bridging across IP site links in Active Directory Sites and Services: Set-ADReplicationSiteLink -Identity "IP" -BridgeAllSiteLinks $true.
Stale Manual Connection Objects Overriding KCC repadmin /showconn displays objects with Options: 0 (manual) instead of Options: 1 (auto). Delete orphaned manual connections in dssite.msc under NTDS Settings, then force the KCC to rebuild automatically: repadmin /kcc.
Kerberos Clock Skew Between Domain Controllers (Error 1398) w32tm /monitor shows greater than 300 seconds offset between the local DC and the source partner. Resynchronise system time against the PDC Emulator: w32tm /resync /rediscover /nowait.

Remediating Topology Failures

Resolving persistent KCC replication topology failures requires systematically addressing the underlying network, DNS, and Active Directory object discrepancies identified during diagnosis.

Production note: Never delete connection objects in Active Directory Sites and Services indiscriminately. Deleting automatically generated connections while an underlying DNS or RPC fault remains unaddressed causes the KCC to recreate the exact same broken link on its next evaluation cycle, while deleting valid connections can partition replication across your forest.

Follow these steps to restore healthy topology computation:

Step 1: Repair the GUID CNAME record in DNS. Active Directory replication locates replication partners exclusively through the _msdcs subdomain using the DC object GUID. If the source DC fails to register this record, replication immediately halts with error 8524.

# On the source domain controller (e.g. DC01):
# Force registration of host and SRV records with DNS
ipconfig /registerdns

# Restart the Netlogon service to reload all DSA GUID and Kerberos records
Restart-Service -Name Netlogon -Force

# On the destination domain controller (e.g. DC02):
# Clear the local DNS resolver cache to flush stale negative lookups
Clear-DnsClientCache

Step 2: Correct missing or mismatched Service Principal Names. When Event 1645 logs error 1396 (Logon Failure: The target account name is incorrect), the destination DC contacted the source DC, but mutual authentication failed because the source server’s DSA replication GUID is not registered in the directory.

# Identify the objectGUID of the source domain controller's NTDS Settings object
$DsaGuid = (Get-ADDirectoryObject -Identity (Get-ADDomainController -Identity "DC01").ServerObjectDN -Properties objectGUID).objectGUID

# Check if the replication SPN exists on the computer account
setspn -L "DC01" | Select-String $DsaGuid

# If missing, register the replication SPN with the computer account
setspn -S "E3514235-4B06-11D1-AB04-00C04FC2DCD2/$DsaGuid/corp.example.com" "DC01"

Step 3: Remove orphaned manual connection objects and force KCC. If administrators previously created manual connection objects in dssite.msc to “force” replication during an outage, those static objects prevent the KCC from automatically optimising the spanning tree.

# List all inbound connection objects on the destination domain controller
Get-ADReplicationConnection -Filter * |
    Select-Object Name, AutoGenerated, ServerFrom, Enabled

# If obsolete manual connection objects exist, remove them using PowerShell
Remove-ADReplicationConnection -Identity "Manual-Link-DC01" -Confirm:$false

# Force an immediate topology regeneration across all domain controllers in the site
repadmin /kcc * /async

# Synchronise all partitions and verify replication health across all partners
repadmin /syncall /AePdq

How to Prevent Recurrence

Replication topology errors are preventable when directory services and underlying network services follow structured operational standards:

  • Avoid manual connection objects: Rely on the KCC and ISTG to dynamically maintain connections. Manual connections become administrative landmines when domain controllers are decommissioned, re-IPed, or replaced.
  • Audit DNS scavenging regularly: Ensure that aging and scavenging are configured accurately on all DNS zones hosting _msdcs. Premature scavenging can wipe valid DC CNAME records, while disabled scavenging leaves obsolete records that cause error 8524.
  • Monitor Directory Service event thresholds: Configure automated alerting in your monitoring platform for Directory Service Event IDs 1925, 1645, 1311, and 1865. Catching a single broken link prevents multi-day replication halts that risk exceeding the tombstone lifetime.
  • Enforce consistent firewall policies: Ensure all inter-site firewalls allow bi-directional communication for Active Directory RPC (port 135 and the dynamic port range 49152–65535), Kerberos (port 88), and DNS (port 53).

Final Thoughts

The Knowledge Consistency Checker is one of the most reliable autonomous systems inside Active Directory, but it depends completely on a functioning foundation of DNS name resolution, unhindered RPC routing, and pristine Kerberos SPN registrations. When Event 1925 and Event 1645 appear in your event viewer, resist the temptation to manually splice connection objects into the directory. Treat the embedded Win32 error code as an exact diagnostic roadmap, repair the underlying name or identity service, and allow the KCC to heal the replication tree on its own.

Key takeaway: Event 1925 is an operational symptom, not the root disease. Always inspect the embedded Win32 error code within the event payload—specifically distinguishing between DNS lookup error 8524, RPC unavailable error 1722, and Kerberos target account error 1396—before altering site links or deleting connection objects.
Next in this series

Active Directory DNS Zone Transfer Failures: Resolving Event 4015 and AXFR Replication Stalls.