Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error Event ID 2095

Event ID 2095 USN rollback: a domain controller restored from a snapshot

12 min read Updated October 4, 2026 Windows Server: AD, DNS & Group Policy

Fix it now

Event ID 2095 is a domain controller reporting that a partner received replication data from it using already-acknowledged USN tracking numbers. Microsoft names an improper restore as the most probable cause. There are three documented recovery options, so read them before you demote anything.

Run these on the suspected DC and on a healthy partner

reg query "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" /v "Dsa Not Writable"
netdom query fsmo
repadmin /replsummary
  1. Confirm the quarantine: a Dsa Not Writable value of 0x4 confirms a detected rollback. Do not delete that value, and do not try to restart replication.
  2. Check whether Net Logon is paused on that DC. Microsoft documents that pause as the deliberate consequence, taken to stop the DC originating any more updates.
  3. Decide between the three documented options before acting: remove the DC from the domain, restore a system state backup taken before the rollback, or – for a virtual DC on Hyper-V – restore using a snapshot as the backup source or assign a new invocation ID.
  4. If you are removing it and it holds operations master roles, seize them first: ntdsutil, roles, connections, connect to server <healthy dc>, quit, then the seize command for each role.
  5. Then force-demote it with Uninstall-ADDSDomainController -ForceRemoval, clean its metadata from a healthy DC, and rebuild.

Seizing a role needs the right group: Enterprise Admins for the naming master, Schema Admins for the schema master, and Domain Admins for the infrastructure master, PDC emulator and RID master.

If the DC is out of the forest and a rebuilt one is replicating, stop here. The next section explains what a rollback does to the arithmetic and why the damage is invisible from the affected machine.

Why it happens

Every DC stamps each originating change with an increasing update sequence number, and every database instance carries an invocation ID. Partners remember the pair: I have seen changes up to USN N from invocation ID X. Restore through an Active Directory-aware path and the DC is given a fresh invocation ID, so partners discard their old high-water mark and resynchronise cleanly.

Apply a checkpoint or write a virtual disk back by hand and none of that happens. The USN counter jumps backwards while the invocation ID stays the same, so the DC starts issuing numbers its partners have already recorded as processed. Every one of those changes is silently ignored. Accounts created, passwords set and memberships changed on that DC after the rollback point exist nowhere else and never will.

Event 2095 is the detection, and its wording is worth reading in full: because the remote DC believes it has a more up-to-date database than the local DC, it will not apply future changes from this DC or replicate them onward, and if not resolved immediately the databases will diverge in users, computers, trust relationships, passwords, security groups and group memberships. Microsoft’s stated most probable cause is the improper restore of Active Directory on the local domain controller, and its stated user action, where that is what happened, is to forcibly demote the DC.

A virtual DC was reverted to a checkpoint

You have this one if The hypervisor shows a checkpoint applied, or a machine restored from an export, shortly before the first 2095.

  1. Stop making changes on that DC. Every one you make now exists only there.
  2. Seize any operations master roles onto a healthy DC with ntdsutil, and enable the global catalog elsewhere if this was the only one in its site.
  3. Force-demote it: Uninstall-ADDSDomainController -ForceRemoval, which is documented for exactly this case – removing a DC with no connectivity to the rest of the domain topology.
  4. Clean the metadata from a healthy DC, remove its DNS records, then rebuild and re-promote.
  5. Delete the checkpoint chain afterwards. Checkpoints are not a backup.

A hypervisor that exposes a VM generation identifier to a supported guest handles a revert safely: the DC takes a new invocation ID and discards its RID pool. Copying a disk back by hand bypasses that.

There is a good system state backup from before the rollback

You have this one if The rollback is recent, and you have a system state backup taken before it happened.

  1. Take Microsoft’s second documented option seriously: restore the system state from the most recent valid backup made before the rollback occurred.
  2. That path gives the DC a fresh invocation ID, which is the whole point, and partners resynchronise cleanly.
  3. Confirm afterwards that Dsa Not Writable is gone and Net Logon is running.
  4. Confirm replication in both directions before returning it to service.

This is the option most articles omit entirely, and it is the one that saves you a rebuild.

The rollback happened weeks ago and nobody noticed

You have this one if No 2095 remains in the log, but objects created against one DC never appear elsewhere and tickets about missing accounts keep arriving.

  1. Check the registry value on every DC, not only the one you suspect: reg query "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters" /v "Dsa Not Writable"
  2. Check which DCs have Net Logon paused. That is a fast forest-wide sweep and it needs no log at all.
  3. Compare an object that should exist everywhere: repadmin /showobjmeta <dc> <distinguishedName>.
  4. Recreate by hand anything that only ever existed on the quarantined machine, because nothing will replicate it for you.

The quarantined DC holds operations master roles

You have this one if netdom query fsmo names the broken machine, and users report logon delays or stale group memberships.

  1. Seize the roles with ntdsutil: roles, connections, connect to server <healthy dc>, quit, then seize naming master, seize schema master, seize infrastructure master, seize pdc or seize rid master as needed.
  2. Use an account in the right group for each: Enterprise Admins for the naming master, Schema Admins for the schema master, Domain Admins for the other three.
  3. Enable the global catalog on another DC in the same site and let it finish building.
  4. Only then remove the quarantined machine from the forest.

Microsoft notes that after seizing the infrastructure master you may hit an error later if you need to run adprep /rodcprep, so check that before you seize if RODCs are in your future.

Full reference

Reading the evidence

What you find What it means
Event 2095 in the Directory Service log A partner received data using already-acknowledged USNs. Microsoft names an improper restore as the most probable cause
Dsa Not Writable = 0x4 A rollback was detected and the DC is quarantined. This survives after the events have aged out
Net Logon paused The documented consequence: the DC is prevented from creating further unique originating updates
repadmin /showrepl looks clean A rollback can look fine from one side. Check every partner
Objects created here that exist nowhere else Changes originated after the rollback point, silently ignored forest-wide

Do not modify or delete the Dsa Not Writable value to bring the DC back. Doing so leaves the domain controller unsupported and lets it resume originating changes with reused USNs that partners will permanently ignore. The divergence becomes both permanent and invisible.

The three documented recovery options

Option What it involves When it fits
Remove the DC from the domain Force demotion to a standalone server, metadata cleanup, transfer or seizure of any operations master roles, then optionally reinstall AD DS The usual answer, and the one Microsoft’s own 2095 user action names
Restore the system state from a good backup Restore the most recent valid system state backup made before the rollback occurred When such a backup exists. This is the option most write-ups leave out
Restore without system state backup data For virtual DCs in a Hyper-V environment: use a snapshot as the backup source, or assign a new invocation ID Virtualised DCs where the platform can supply what is needed

Seizing the roles, with the right credentials

Role Credentials ntdsutil command
Domain naming master Enterprise Admins seize naming master
Schema master Schema Admins seize schema master
Infrastructure master Domain Admins seize infrastructure master
PDC emulator Domain Admins seize pdc
RID master Domain Admins seize rid master

The sequence is ntdsutil, then roles, then connections, then connect to server <fully qualified name of a healthy DC>, then quit, and then the seize command. If the machine was not the RID master and you try to seize that role, you get a prompt asking whether to continue despite being unable to synchronise with a partner.

Metadata cleanup, three ways

  1. Active Directory Users and Computers: connect to a replication partner, expand Domain Controllers, right-click the computer object, Delete, then confirm that the DC is permanently offline and cannot be demoted, and let it move any operations master roles.
  2. Active Directory Sites and Services: expand the site, Servers, the server, right-click NTDS Settings, Delete, confirm the same prompt, then delete the server object itself.
  3. ntdsutil: metadata cleanup, connections, connect to server <partner>, quit, remove selected server <name>, then quit out of both prompts.
  4. If any of those returns access denied, clear “Protect object from accidental deletion” on the computer object and on the NTDS Settings object, then try again.
  5. Confirm afterwards that the DC no longer appears under Domain Controllers and that its server object has no NTDS Settings beneath it.

Commands worth having open

Command What it does
repadmin /showrepl Inbound status and last error per partner
repadmin /replsummary A forest-wide view of failing links
repadmin /showobjmeta <dc> <dn> Per-attribute origin and USN for one object, which is how you prove a change never left
netdom query fsmo Where the five operations master roles live
Uninstall-ADDSDomainController -ForceRemoval Forces removal of a DC where there is no connectivity to the rest of the domain topology

Three event IDs in this article that Microsoft does not publish

Event ID 2103, Event ID 1084 and Event ID 1173 are all quoted in USN rollback material and none of them has a published meaning this article could find. They are recorded as such below. It does not matter much, because the two pieces of evidence that decide this case – the Dsa Not Writable value and the paused Net Logon service – are both documented and both survive log rotation, which the events do not.

When a licence is the actual fix

Rebuilding means a fresh Windows Server installation. Reinstalling on hardware you already licence costs nothing extra, because the licence follows the hardware rather than the installation. It becomes a purchase when the rebuild is also the moment you add a domain controller, move to a new host, or run more Windows virtual machines on that host than your edition permits. That last point is the one worth checking properly: Standard limits how many Windows virtual instances you may run on the licensed cores, and Datacenter does not, so at high density Datacenter can be the cheaper answer and at low density it is not. Arco can work through your host core counts, say which edition works out cheaper for your actual density, supply the key, and check what your existing agreement already covers before you spend anything.

Every code this article covers

Code What it points at Source
Event ID 2095 During a replication request, the local DC identified a remote DC that has received replication data from it using already-acknowledged USN tracking numbers. Microsoft names an improper restore as the most probable cause Microsoft Learn
Event ID 2103 Quoted as the record of an unsupported restore stopping replication and Net Logon. Microsoft publishes no meaning for it; the documented evidence is the paused Net Logon service and Dsa Not Writable set to 0x4 not published by the vendor
Event ID 1084 Quoted as an inbound change that could not be applied to a local object. No published meaning found; read the entry itself and the status it carries not published by the vendor
Event ID 1173 Quoted as an internal directory service exception. No published meaning found not published by the vendor

Confirm the fix worked

  1. No new Event ID 2095 appears on the rebuilt DC after a full day in service.
  2. The Dsa Not Writable value no longer exists under the NTDS Parameters key.
  3. The Net Logon service is running rather than paused.
  4. repadmin /replsummary shows no failures in either direction for the new DC.
  5. net share lists SYSVOL and NETLOGON, and the DC advertises correctly.

Questions people ask about this

Can I repair the DC instead of rebuilding it?

Sometimes. Microsoft documents three options, not one: remove the DC from the domain, restore a system state backup taken before the rollback, or – for a virtual DC on Hyper-V – restore using a snapshot as the backup source or assign a new invocation ID. Removal is the option named in the event’s own user action, but it is not the only one.

Does the rollback damage the other domain controllers?

Their databases are fine. What is lost is anything that only ever existed on the rolled-back DC after the restore point, because those changes carried USNs partners had already acknowledged and were ignored forest-wide.

Is reverting a virtual DC ever safe?

On a hypervisor that exposes a VM generation identifier to a supported guest, a revert is detected and handled: the DC takes a new invocation ID and discards its RID pool. Copying a virtual disk back by hand bypasses that entirely, and that is what produces a 2095.

The events have aged out. How do I confirm it happened?

Two things survive. Dsa Not Writable set to 0x4 under HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters confirms a detected rollback, and Net Logon being paused on that DC is the documented consequence. Check both across every DC, not only the one you suspect.

Do I need a licence to rebuild the DC?

Not if you are reinstalling on hardware already covered, because the licence follows the hardware. You need one if the rebuild adds a server, moves you to a version you are not entitled to, or takes you past the number of Windows virtual instances your edition permits on that host.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix Event ID 50: the time service found a difference too large to accept License Error DHCP Event ID 14: the scope address pool is exhausted and leases now fail License Error Error 8568: the functional level will not rise while legacy DCs remain Free Fix Event ID 4521: DNS cannot load an Active Directory integrated zone
โ† Back to Knowledge Base