Free tools Windows power users keep installed
One-click scans. No signup required.
First try signing in with a domain-qualified account, such as DOMAINAdministrator or administrator@example.com. If you still cannot sign in, check whether the new domain controller has finished initializing: missing SYSVOL or NETLOGON shares, failed DNS discovery, or incomplete replication can make a promotion look successful while the server is not ready to provide normal domain services.
What changed when the server became a domain controller?
A server joined to a domain remains a member server; a promoted server runs Active Directory Domain Services (AD DS) and participates in domain authentication. After promotion, a sign-in depends on the domain and its services, including DNS, Kerberos, and Netlogon. SYSVOL is also important: it carries Group Policy data, and its initialization is a useful indicator of whether a new DC is ready.
The recovery path depends on which promotion you performed. An additional DC must communicate with an existing DC and receive directory and SYSVOL data. The first DC in a new forest has no upstream partner, so a failure there may affect the only copy of the directory. A read-only domain controller (RODC) has different credential-caching behavior. Promotion can also be only partially complete if configuration or the required reboot did not finish.
Try the right sign-in identity first
| Purpose | Sign-in format | Credential to use |
|---|---|---|
| Ordinary domain sign-in | DOMAINusername or username@example.com |
The account’s domain password |
| Directory Services Restore Mode (DSRM) | .administrator |
The DSRM password set during promotion |
| Pre-promotion member-server local account | Not a reliable assumption on a domain controller | Do not keep retrying the old local Administrator password as though the server were still a member server |
At the sign-in screen, choose Other user if needed, then explicitly enter the domain or UPN. Check Caps Lock and keyboard layout, and verify the selected domain. If the account is from a child domain, use that domain’s name or UPN. Confirm that the account is enabled, not locked or expired, and permitted to sign in to the server. Credentials entered in the wrong naming form can cause authentication and promotion problems; see Microsoft’s guidance on DC promotion and NetBIOS/DNS credential issues.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- Spacious Design: Measuring 21.1" wide and 14.1" deep, our lap desk comfortably fits most laptops up to 15.6". Extra room for accessories ensures convenience.
- Enhanced Functionality: Packed with handy features, including a 5x9" precision tracking mouse pad and a built-in phone slot for seamless work or video calls. Plus, enjoy ergonomic support with the integrated cushioned wrist rest.
- Cool Comfort: Enjoy a stable surface with our lap desk's dual bolster cushion, designed for comfort and airflow, keeping your lap cool during extended use.
- Durable Surface: Work with confidence on our lap desk's solid surface, featuring a sleek black carbon color, ensuring optimal air circulation to prevent your laptop from overheating.
- On-the-Go Convenience: With an integrated handle and lightweight design (2.8 lbs), our lap desk is portable for travel or moving around the house, offering flexibility in any space.
Record the exact message. “Username or password is incorrect,” “no logon servers,” a trust error, and a profile or service failure point to different layers. Also confirm that the server completed its post-promotion reboot. If a correctly qualified domain account works, the original issue was likely account context; if domain sign-in fails, continue with readiness checks rather than repeatedly changing passwords.
Check whether the new DC is ready
From an administrative session or console, run:
net share
dir \localhostSYSVOL
dir \localhostNETLOGON
sc query ntds
sc query netlogon
sc query dfsr
An operational writable DC should normally publish the SYSVOL and NETLOGON shares. Their absence is a significant warning that SYSVOL initialization or replication has not completed; it does not, by itself, prove that every interactive logon must fail. Microsoft’s DFSR troubleshooting guidance for missing SYSVOL and Netlogon shares describes newly promoted DCs waiting for initial synchronization and upstream replication problems as common causes.
Read DFS Replication events
Open Event Viewer → Applications and Services Logs → DFS Replication. Event 4614 indicates that a newly promoted DC is waiting for initial SYSVOL replication; event 4604 indicates SYSVOL initialization completed. Event 4614 alone can be a normal waiting state. It becomes more concerning when it persists without 4604 or appears alongside replication errors. Event 4012 can indicate content-freshness or prolonged replication issues, while event 2213 on an upstream DC can mean replication paused after a dirty shutdown.
Rank #2
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
You can ask DFSR to reread its Active Directory configuration with:
dfsrdiag pollad
This is a configuration poll, not a repair for broken DNS, blocked RPC, an unhealthy replication partner, or a damaged topology.
Verify DNS and domain-controller discovery
AD authentication relies on finding domain controllers through the AD DNS namespace and its service (SRV) records. A public DNS resolver may resolve ordinary websites but cannot supply the private AD records needed for domain discovery. During promotion, the new server commonly needs to use an existing internal DC for DNS resolution; the correct final DNS configuration depends on the domain design, so do not apply a blanket “point every DC only to itself” rule.
Rank #3
- Note: Not suitable for MacBooks released after 2023 or devices with a protruding front camera; Not applicable to full-screen or notch-style tempered glass screen protectors; Do not use on the rear camera of the phone.
- 💻 Why Do You Need a Webcam Cover Slide? — Safeguard your privacy by covering your webcam with our reliable webcam cover when not in use. Don't let anyone secretly watch you. Stay protected!
- ✅ Thin & Stylish — Enhance your laptop's functionality and aesthetics with our 0.027" ultra-thin webcam covers. Seamlessly close your laptop while adding a touch of sophistication.
- ✅ Fits Most Devices — Compatible with laptops, phones, tablets, desktops! Keep your privacy intact on Ap/ple, Mac/Book, iPh/one, iP/ad, H/P, L/novo, De/ll, Ac/er, As/us, Sa/msung devices.
- ✅ 365 Days Protection — Our upgraded 3.0 adhesive ensures a strong hold that won't damage your equipment. Experience reliable, long-term privacy protection day in and day out.
Replace example.com below with the actual AD DNS domain:
ipconfig /all
nslookup -type=SRV _ldap._tcp.dc._msdcs.example.com
nslookup -type=SRV _kerberos._tcp.example.com
nltest /dsgetdc:example.com
Check that the configured DNS servers can resolve the AD namespace and locate the expected DCs. If records are missing or look stale, investigate the DNS zone, delegation, suffix configuration, and replication of _msdcs records. A failure to locate a DC is more relevant to domain sign-in than whether the server can browse public websites. After correcting a known DNS issue, you can clear the local resolver cache with ipconfig /flushdns; this does not repair missing records at the DNS server.
Check Active Directory replication and DC advertising
Run these commands from a DC or an administrative workstation with the appropriate tools and permissions:
Rank #4
- Anti-Slip Surface - Transform your laptop into a mobile workstation with the AboveTEK portable laptop lap desk. The anti-slip surface provides a strong grip for laptops up to 15.6 inches(Diagonal), while the double rubber strip on the bottom ensures a stable display or typing experience on your lap, couch, or bed.
- Retractable Mouse Pad - Retractable laptop mouse pad extends on both directions for the left/right handed with elevation along the edges for stopping mouse from falling off. The size of laptop tray is 14" X 9.7" and the size of mouse pad is 7.4" X 6.1".
- Effective Heat Shield - The effective heat shield made of sturdy and thick material protects your laptop from overheating. Prioritizes your comfort and safety, an ideal lap pad or board for working anywhere.
- EASY to Carry and Store - With an ergonomic and simplistic design, the lap desk is portable to store in a backpack. Only 15" in size, 2.2 lb of weight and with slim 0.6 inch thickness, it is ready to be easily carried around.
- Widely Applicable - The smooth platform accommodates laptops and tablets up to 15.6 inches(Diagonal), making it a versatile accessory and one of the best gifts for mom, dad, students and professionals. Perfect for use as a laptop bed tray or tablet holder anywhere at home, library, or park.
repadmin /replsummary
repadmin /showrepl
repadmin /showrepl NEWDC
dcdiag /v
dcdiag /test:dns /v
dcdiag /test:sysvolcheck /test:advertising
Replace NEWDC with the server’s actual DC name. Review replication failures for DNS or RPC errors, access denied, unreachable partners, missing naming contexts, and long gaps since successful inbound replication. Replication timing varies by site, so a brief delay immediately after promotion is not the same as a persistent failure. Microsoft’s guidance recommends repadmin /showrepl for inspecting replication; see its SYSVOL and Netlogon troubleshooting article.
The Advertising test helps determine whether the DC is advertising services clients need. For a saved diagnostic record, use:
mkdir C:Temp
dcdiag /v /f:C:Tempdcdiag.txt
repadmin /replsummary > C:Tempreplsummary.txt
repadmin /showrepl > C:Tempshowrepl.txt
Microsoft documents detailed DC diagnostics and log output in its domain-controller diagnostic guidance. For deployment failures, also review System, Application, Directory Service, DFS Replication, DNS Server, and Directory Services Deployment logs, plus %systemroot%debugdcpromo.log and related dcpromo*.log files. Microsoft’s deployment troubleshooting article lists these logs.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- Spacious Design: Measuring 21.1" wide and 12" deep, our lap desk comfortably fits most laptops up to 15.6". Extra room for accessories ensures convenience.
- Enhanced Functionality: Packed with handy features, including a 5x9" precision tracking mouse pad and a built-in phone slot for seamless work or video calls. Plus, enjoy laptop support with the integrated device ledge.
- Cool Comfort: Enjoy a stable surface with our lap desk's dual bolster cushion, designed for comfort and airflow, keeping your lap cool during extended use.
- Durable Surface: Work with confidence on our lap desk's solid surface, featuring a blush pink color, ensuring optimal air circulation to prevent your laptop from overheating.
- On-the-Go Convenience: With an integrated handle and lightweight design (2.14 lbs), our lap desk is portable for travel or moving around the house, offering flexibility in any space.
Use DSRM only to recover the directory
If ordinary domain authentication is unavailable, DSRM provides a separate recovery sign-in. Boot into Directory Services Restore Mode using the server’s advanced startup or boot options. At the sign-in screen, choose Other user if necessary, enter .administrator, and use the DSRM password configured during promotion. Confirm that SAFE MODE appears in the screen corners so you know the server is in the intended mode. Microsoft’s no-logon-servers guidance documents this sign-in format.
DSRM is not a way to reset or replace the domain Administrator password, and DSRM credentials will not work for ordinary domain sign-in. If DSRM also fails, verify the boot mode and password, use console or hypervisor access rather than relying only on RDP, and preserve logs before attempting recovery.
Choose repair or re-promotion based on the domain’s condition
Another healthy DC exists
If this was an additional DC, another DC is healthy, and the new server has no unique application data, persistent promotion or replication failures may make a clean demotion and re-promotion safer than invasive repairs. Before rebuilding, preserve the promotion logs and event logs and confirm the partner DC is genuinely healthy. If demotion fails, follow Microsoft’s supported domain-controller demotion guidance and metadata-cleanup procedure; do not simply delete the DC’s computer account from Active Directory.
This is the first or only DC
Stop before demoting, rebuilding, deleting SYSVOL data, or resetting replication state. Treat this as a forest-recovery problem because there may be no other copy of the domain directory or SYSVOL. Preserve evidence and use a documented recovery plan or Microsoft support where appropriate.
Recommended Free Tools
SYSVOL recovery is being considered
Do not manually copy SYSVOL from another DC, delete the DFSR database, set SysvolReady to 1, or force an authoritative/non-authoritative reset as a first response. Those actions can produce divergent policy data, hide the underlying cause, or lose data. Identify the authoritative source and follow a documented procedure for the actual topology. Microsoft’s missing-share guidance warns that an incorrectly performed DFSR SYSVOL reset can cause data loss.
Quick Recap
Account for special cases
- RODC: Credential caching and sign-in behavior differ from a writable DC; assess the account’s credential-replication policy and the availability of a writable partner.
- Virtual machine, clone, or restored snapshot: A DC rollback or unsupported clone can create directory identity and replication problems. If there are invocation-ID or USN rollback symptoms, do not keep retrying sign-ins or restore another snapshot; use supported virtualized-DC safeguards and recovery procedures.
- RDP only: Remote Desktop can fail because of policy, firewall, or RDP configuration even when console authentication works. Use the physical, hypervisor, or out-of-band console to separate access-path issues from domain authentication.
- Windows Server 2025: A Microsoft Q&A post describes one user’s post-promotion sign-in problem, but it is anecdotal and does not establish a general product defect: the report.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

