Fix it now
Microsoft publishes 4013 as the DNS server being unable to open Active Directory, configured to use directory information, unable to operate without it, and waiting for the directory to start. It is not a DNS fault. Fix inbound replication and the zones load on their own.
repadmin /replsummary
repadmin /showrepl
ipconfig /all
w32tm /query /status
- Read the last inbound attempt for every partner and every naming context. An access denial, an RPC failure and a name resolution failure lead in three different directions.
- Check what the server itself resolves through. Microsoft’s guidance is that domain controllers hosting directory-integrated zones should not point exclusively at themselves: a hub-site DC should use another DC in the same site as preferred and alternate and then itself, and a branch-site DC should use a hub-site DNS server as preferred, an in-site server as alternate, and itself last.
- If the companion is Event 4000 rather than only 4013, read the next section: Microsoft’s documented cause for that pair is a lost secure channel, and no amount of replication work will clear it.
- If 4013 clears within a minute or two of every reboot and never otherwise, nothing is wrong. That is the wait working as designed.
Microsoft documents a registry value that lets the server start without waiting, and describes it as not recommended for production. It is a recovery measure, and you put it back afterwards.
If the zones load and stay loaded across a reboot, you are done. If not, the next section explains the deadlock this event is describing.
Why it happens
A directory-integrated zone is not a file. It is a set of objects held in a directory partition, and the DNS server reads them out of the directory at startup. A domain controller that has just booted is not immediately ready to serve those objects, so DNS waits rather than loading whatever happens to be in the local database. Microsoft’s published text for 4013 says exactly that: the server is configured to use directory service information, cannot operate without access to the directory, and will wait for the directory to start.
The reason this becomes a deadlock rather than a pause is the circular dependency Microsoft documents alongside the event. DNS waits for the directory to complete its initial replication; the directory needs DNS to resolve the domain controllers it wants to replicate from. When several domain controllers boot together, each waits for the others while DNS queries fail slowly rather than quickly, multiplied across every naming context. The status code in the event narrows it: Microsoft lists 9717 DNS_ERROR_DS_UNAVAILABLE, 9005 DNS_ERROR_RCODE_REFUSED and 9002 DNS_ERROR_RCODE_SERVER_FAILURE as the common ones.
The companions matter because two of them are not about waiting at all. Event 4000 is published as the DNS server being unable to open Active Directory for a zone it cannot load without, and Microsoft’s documented cause for it is that the domain controller has lost its secure channel with itself or with the primary domain controller emulator. Event 4015 is a critical error handed back by the directory, and Microsoft documents three quite different readings of it depending on the status embedded in the text.
Inbound replication is failing from every partner
You have this one if repadmin /replsummary shows a failure percentage against this server and the same error repeats for each partner.
- Read the actual error in
repadmin /showrepland follow it. Microsoft’s own list of causes for the RPC failure case runs from link-local and DHCP failures through DNS and routing to IPSec and resource limits. - Check time:
w32tm /query /statuson both ends, anddcdiag /test:CheckSecurityError /ReplSource:<partner>, which tests the skew against the 300-second Kerberos limit. - Run
dcdiag /test:Replicationsand work through what it reports before touching DNS again.
The domain controller resolves only through itself
You have this one if The server’s own address or the loopback is the only resolver configured, and the locator cannot find anything.
- Follow Microsoft’s documented ordering: a hub-site domain controller points at DNS servers in the same site as preferred and alternate and then at itself; a branch-site domain controller points at a hub-site DNS server as preferred, an in-site server as alternate, and itself last.
- Keep the server itself in the list. Removing it entirely leaves the machine with no resolver when its partners are down.
- Flush the resolver cache, then restart the DNS service and confirm the zones load.
- Apply the same pattern to every domain controller rather than only to the one that failed.
The secure channel is broken, so the directory refuses
You have this one if Event 4000, or 4000 and 4007 together, rather than 4013 alone.
- Microsoft’s documented cause here is that the domain controller has lost its secure channel with itself or with the primary domain controller emulator, and it happens on single-DC environments that hold all the operations master roles and point at themselves.
- Stop the KDC service on the affected domain controller.
- Run
netdom resetpwd /server:<PDC.domain.com> /userd:<Domain\admin> /passwordd:*with elevated rights and supply the password when prompted. - Reboot the server. On a single domain controller, Microsoft says to use the server’s own address in place of the PDC name, since it is the PDC.
This is the cause that makes a healthy-looking directory refuse to hand over its zones. Nothing in the replication output points at it.
A replication partner no longer exists
You have this one if The replication output names a server that was decommissioned, rebuilt or restored, and every attempt against it fails to resolve.
- Confirm the server is genuinely gone rather than switched off.
- Remove the stale references so the domain controller stops waiting for something that will never answer. Microsoft lists removing references to offline, non-functioning or non-existent domain controllers as one of the resolutions for this event.
- Check no operations master role is still assigned to it.
- Let replication run against the remaining partners, then restart the DNS service.
Cleaning up directory metadata is not reversible. Take a system state backup of a healthy domain controller before you start.
The server has to start with no partner reachable
You have this one if A single domain controller, or an isolated one you are recovering, that will otherwise never complete an initial synchronisation.
- Under
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters, set the REG_DWORD valueRepl Perform Initial Synchronizationsto 0. - Reboot. The directory now advertises without waiting and DNS loads the zones behind it.
- Repair or remove the missing partners, then put the value back and confirm replication is healthy.
Microsoft’s own wording is that this is not recommended for production and should be used only for critical temporary problems, with the default restored afterwards.
Full reference
The events
| Event | Status | What it says |
|---|---|---|
| 4013 | Published | The DNS server was unable to open the Active Directory. It is configured to use directory service information, cannot operate without access to the directory, and will wait for the directory to start |
| 4000 | Published | The DNS server was unable to open Active Directory. It is configured to obtain and use information from the directory for this zone and cannot load the zone without it |
| 4015 | Published | The DNS server has encountered a critical error from the Active Directory. The extended error debug information, which may be empty, is in the entry |
| 4016 | Not published | A DNS entry about a directory operation. Note that Group Policy also has a 4016, which is a different and unrelated event |
Reading the status inside a 4015
| Status in the entry | Microsoft’s documented cause | What to do |
|---|---|---|
| 00002095, problem 5012 DIR_ERROR | A read-only domain controller running DNS cannot connect to a writable domain controller | Run nltest /dsgetdc:<domain> /WRITABLE /AVOIDSELF /TRY_NEXT_CLOSEST_SITE /DS_6 and confirm the answer is writable, runs DNS, and has correct records |
| 0000051B, problem 1005 CONSTRAINT_ATT_TYPE | SYSTEM is not the owner of the DNS zone object, or the domain Users group is missing members | Check ownership in ADSI Edit; check net localgroup users /domain contains Domain Users, Authenticated Users and INTERACTIVE |
| 00002024, problem 5008 ADMIN_LIMIT_EXCEEDED | A dnsNode object’s multi-valued dnsRecord attribute holds too many values, usually orphaned records from repeated promotions and demotions | Enumerate the records with repadmin /showattr against the MicrosoftDNS containers, then remove the orphans |
The status codes that accompany 4013
| Hex | Decimal | Symbolic | Meaning |
|---|---|---|---|
| 000025f5 | 9717 | DNS_ERROR_DS_UNAVAILABLE | The directory service is unavailable |
| 0000232d | 9005 | DNS_ERROR_RCODE_REFUSED | DNS operation refused |
| 0000232a | 9002 | DNS_ERROR_RCODE_SERVER_FAILURE | DNS server failure |
Microsoft’s other documented resolutions
- Make sure DNS servers are available at Windows startup, and that they host, forward or delegate the _msdcs zone for the forest root and the primary DNS suffix zones.
- Enable scavenging appropriately, but not aggressively, so stale records do not accumulate and are not removed while still in use.
- Stagger domain controller reboots so that several are not unavailable simultaneously.
- Where a server keeps booting into a known-bad state, set the DNS Server service to manual, reboot, wait for the domain controller to advertise, and start DNS by hand.
- Avoid single points of failure – one DNS server, or every DNS server on one physical host.
Confirming that a partner can be resolved
Microsoft points at directory events 2087 and 2088 in the Directory Service log alongside this problem. They record a destination domain controller that could not resolve a source domain controller’s alias record to a host record, and had to fall back to another name resolution method. If you see them, the replication failure and the DNS failure have the same root, and repairing the alias records breaks the deadlock in both directions at once.
How long to wait before acting
A few minutes on a healthy server. If the DNS service has not loaded its zones by the time you have signed in and opened Event Viewer, treat it as a replication problem rather than a slow start. The failure mode to watch for is the estate-wide one: several domain controllers restarted together, each waiting for the others, each taking twelve seconds per failed query across several naming contexts. That resolves itself eventually on a healthy network and does not on a broken one, which is why the replication output matters more than the clock.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
Event ID 4013 |
The DNS server was unable to open the Active Directory, is configured to use directory service information, cannot operate without it, and will wait for the directory to start | Microsoft Learn |
Event ID 4000 |
The DNS server was unable to open Active Directory for a zone it cannot load without. Microsoft’s documented cause is a lost secure channel with itself or with the PDC emulator | Microsoft Learn |
Event ID 4015 |
The DNS server encountered a critical error from Active Directory; the extended debug information in the entry decides which of three documented causes applies | Microsoft Learn |
Event ID 4016 |
A DNS entry about a directory operation. Not published by the vendor, and not to be confused with the unrelated Group Policy event of the same number | not published by the vendor |
Confirm the fix worked
- The directory-integrated zones are present and loaded on the affected server.
- A record from one of those zones is answered authoritatively when queried against this server directly.
repadmin /replsummaryshows no failures for this server in either direction.- Reboot once more and confirm 4013 either does not appear or clears within a minute or two.
- The
Repl Perform Initial Synchronizationsvalue is back at its default if you changed it.
Questions people ask about this
Does this cost anything to fix?
No. This is replication repair on servers you already run and licence. No product or upgrade makes a domain controller synchronise faster.
How long should I wait before acting?
A few minutes on a healthy server. If the zones have not loaded by the time you have signed in and opened Event Viewer, treat it as replication rather than a slow boot.
Should a domain controller point at itself for DNS?
Not exclusively. Microsoft’s documented guidance is that domain controllers hosting directory-integrated zones should not point only at themselves: use another domain controller as preferred, and list this server last.
Is it safe to leave the initial synchronisation requirement off?
No. Microsoft describes setting it to 0 as not recommended for production and as something to use only for critical temporary problems, restoring the default afterwards.
I have 4000 as well as 4013. Is that the same problem?
Not necessarily. Microsoft’s documented cause for 4000, and for 4007 alongside it, is that the domain controller has lost its secure channel with itself or with the PDC emulator, repaired by stopping the KDC service, running netdom resetpwd against the PDC and rebooting.
