Not sure but you might try this: Troubleshoot AD replication error -2146893022 - Windows Server | Microsoft Learn
Short version, stop KDC service, disable it, restart the DC, try replication test again, set kdc to auto again, restart the service.
--
John Wright
IT Support Specialist
![]()
1800 Old Bluegrass Avenue, Louisville, KY 40215
Please submit IT requests to Hazelwoo...@bluegrass.org
24 Hour Helpline 1.800.928.8000
CONFIDENTIALITY NOTICE: This message contains confidential information and is intended only for the individual(s) addressed in the message. If you are not the named addressee, you should not disseminate, distribute, or copy this e-mail. If you are not the intended recipient, you are notified that disclosing, distributing, or copying this e-mail is strictly prohibited.
From: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
On Behalf Of Mike Leone
Sent: Monday, March 16, 2026 11:56 AM
To: NTSysAdmin <ntsys...@googlegroups.com>
Subject: [ntsysadmin] DC replication - target principal name is incorrect??
|
EXTERNAL EMAIL - This email was sent by a person from outside your organization. Exercise caution when clicking links, opening attachments or taking further action, before validating its authenticity. |
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion visit
https://groups.google.com/d/msgid/ntsysadmin/CAHBr%2B%2BgeTSsK2zYrrPQUCQ2-rMTmi8cLzSDb-OiOx-RCnm_ebQ%40mail.gmail.com.
netdom resetpwd /server:PDCEmulatorName /userd:Domain\Admin /passwordd:*klist -li 0x3e7 purge._msdcs) are correct and check for duplicate SPNs.To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/CA%2BZrOWwFs%3DWAJw3a4TsjKATPVYpaKSV12L6q_AAv7Otz%3DCeLyQ%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/CAHBr%2B%2BhS6AFsrpEmg6zMwkQHRp5DM9XF6aoSMPaPb876xgN1aQ%40mail.gmail.com.
If it's still not at logon prompt, can it be reached any other way (WinRM, psexec, etc.)? Those methods might not work if this is a secure channel issue but it might be worth trying to see if you can re-enable/restart the kdc service.
Do you have a backup of the FSMO Role holder?
With two DCs this one is fairly easy to fix.
Start Restore DC0.
Shut down DC1 just as restore is complete.
Log on to DC0.
Verify FSMO Roles
# Check FSMO
Get-ADForest | FT SchemaMaster,DomainNamingMaster
Get-ADDomain | FT PDCEmulator,RIDMaster,InfrastructureMaster
If they show anything but DC0 SEIZE THEM:
# Seize FSMO Roles
$DestinationDC = “DC0”
Move-ADDirectoryServerOperationMasterRole -Identity $DestinationDC -OperationMasterRole 0,1,2,3,4 -Force -confirm:$False
Get-ADForest | Format-Table SchemaMaster,DomainNamingMaster
Get-ADDomain | Format-Table PDCEmulator,RIDMaster,InfrastructureMaster
Verify in the ADDS event logs that everything is happy.
Make sure SYSVOL and NETLOGON are presented via UNC.
TEST:
\\DC0\ ?
Do you see SYSVOL and NETLOGON?
YES?
Perform Metadata Clean-up and remove ALL other DCs found
Mount OS install and boot to it for DC1.
Re-install Windows
Re-install ADDS Roles
DCPromo IN
Make sure your PDCe is set to time authority and the newly promo’d DC is second to it.
W32Tm.
Philip Elder MCTS
Senior Technical Architect
Microsoft High Availability MVP
MPECS Inc.
E-mail: Phili...@MPECSInc.Ca
Phone: +1 (780) 458-2028
Web: www.MPECSInc.Com
Blog: Blog.MPECSInc.Com
Twitter: Twitter.com/MPECSInc
Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/CA%2BZrOWxiJfiknx8N0%2BwNCAcdzh6t6DMRz68hkU7V5vUHQOd8gA%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/e3a0603553274a0eac7fe924c0c176c1%40MPECSInc.Ca.
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/CA%2BZrOWx-pfmKTJCzh6bUiyJyjLnd0vB6V4COQbgygEJ1H_bC5g%40mail.gmail.com.
Directory Services Restore Mode = DC Safe Mode.
Make sure the DSRM password is a known commodity which it seems to be in this case.
Would I have done that?
Probably not.
I’d rather start with a now known good FSMO Role holder, best practice is to _always_ have them all on one DC, after seizing and verifying they are there and the SYSVOL and NETLOGON shows up as they should.
BURFLAGS is really easy too in a DFS-R situation. All DCs in the domain are available in ADSIEdit.
Oh, and _check your _msdcs stub zone NS records_ to make sure they are current!!!
DNS à Domain.Com à _msdcs
It’s the little grey guy. If it ain’t grey you’re AD ain’t healthy.
If it is grey but NS records are out of date you’re AD ain’t healthy.
It’s always the little things that make the big guys puke.
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/CA%2BZrOWx-pfmKTJCzh6bUiyJyjLnd0vB6V4COQbgygEJ1H_bC5g%40mail.gmail.com.
Directory Services Restore Mode = DC Safe Mode.
Make sure the DSRM password is a known commodity which it seems to be in this case.
Would I have done that?
Probably not.
I’d rather start with a now known good FSMO Role holder, best practice is to _always_ have them all on one DC, after seizing and verifying they are there and the SYSVOL and NETLOGON shows up as they should.
BURFLAGS is really easy too in a DFS-R situation. All DCs in the domain are available in ADSIEdit.
Oh, and _check your _msdcs stub zone NS records_ to make sure they are current!!!
DNS à Domain.Com à _msdcs
It’s the little grey guy. If it ain’t grey you’re AD ain’t healthy.
If it is grey but NS records are out of date you’re AD ain’t healthy.
It’s always the little things that make the big guys puke.
I see two different DCs holding FSMO Roles?

They should all be on the PDCe.
Philip Elder MCTS
Senior Technical Architect
Microsoft High Availability MVP
MPECS Inc.
E-mail: Phili...@MPECSInc.Ca
Phone: +1 (780) 458-2028
Web: www.MPECSInc.Com
Blog: Blog.MPECSInc.Com
Twitter: Twitter.com/MPECSInc
Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.
From: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
On Behalf Of Mike Leone
Sent: Monday, March 16, 2026 14:17
To: ntsys...@googlegroups.com
Subject: Re: [ntsysadmin] DC replication - target principal name is incorrect??
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/CAHBr%2B%2BhPEGsVTGiY19%2BSNqSDr78jPj2%2BbpLog7BnrsvYUkH_eg%40mail.gmail.com.
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/750e1ecc08af44e384ace8a834713cb4%40MPECSInc.Ca.
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/CAGaCHK764sR8K18xUwv-i4pYY85cCeXMFsTB2yOkRknbLqS5ig%40mail.gmail.com.