Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Free Fix Event ID 4013

Event ID 4013: the DNS server is waiting for Active Directory to synchronise

11 min read Updated October 4, 2026 Windows Server: AD, DNS & Group Policy

Fix it now

Microsoft publishes 4013 as the DNS server being unable to open Active Directory, configured to use directory information, unable to operate without it, and waiting for the directory to start. It is not a DNS fault. Fix inbound replication and the zones load on their own.

Run these on the affected domain controller, in an elevated prompt

repadmin /replsummary
repadmin /showrepl
ipconfig /all
w32tm /query /status
  1. Read the last inbound attempt for every partner and every naming context. An access denial, an RPC failure and a name resolution failure lead in three different directions.
  2. Check what the server itself resolves through. Microsoft’s guidance is that domain controllers hosting directory-integrated zones should not point exclusively at themselves: a hub-site DC should use another DC in the same site as preferred and alternate and then itself, and a branch-site DC should use a hub-site DNS server as preferred, an in-site server as alternate, and itself last.
  3. If the companion is Event 4000 rather than only 4013, read the next section: Microsoft’s documented cause for that pair is a lost secure channel, and no amount of replication work will clear it.
  4. If 4013 clears within a minute or two of every reboot and never otherwise, nothing is wrong. That is the wait working as designed.

Microsoft documents a registry value that lets the server start without waiting, and describes it as not recommended for production. It is a recovery measure, and you put it back afterwards.

If the zones load and stay loaded across a reboot, you are done. If not, the next section explains the deadlock this event is describing.

Why it happens

A directory-integrated zone is not a file. It is a set of objects held in a directory partition, and the DNS server reads them out of the directory at startup. A domain controller that has just booted is not immediately ready to serve those objects, so DNS waits rather than loading whatever happens to be in the local database. Microsoft’s published text for 4013 says exactly that: the server is configured to use directory service information, cannot operate without access to the directory, and will wait for the directory to start.

The reason this becomes a deadlock rather than a pause is the circular dependency Microsoft documents alongside the event. DNS waits for the directory to complete its initial replication; the directory needs DNS to resolve the domain controllers it wants to replicate from. When several domain controllers boot together, each waits for the others while DNS queries fail slowly rather than quickly, multiplied across every naming context. The status code in the event narrows it: Microsoft lists 9717 DNS_ERROR_DS_UNAVAILABLE, 9005 DNS_ERROR_RCODE_REFUSED and 9002 DNS_ERROR_RCODE_SERVER_FAILURE as the common ones.

The companions matter because two of them are not about waiting at all. Event 4000 is published as the DNS server being unable to open Active Directory for a zone it cannot load without, and Microsoft’s documented cause for it is that the domain controller has lost its secure channel with itself or with the primary domain controller emulator. Event 4015 is a critical error handed back by the directory, and Microsoft documents three quite different readings of it depending on the status embedded in the text.

Inbound replication is failing from every partner

You have this one if repadmin /replsummary shows a failure percentage against this server and the same error repeats for each partner.

  1. Read the actual error in repadmin /showrepl and follow it. Microsoft’s own list of causes for the RPC failure case runs from link-local and DHCP failures through DNS and routing to IPSec and resource limits.
  2. Check time: w32tm /query /status on both ends, and dcdiag /test:CheckSecurityError /ReplSource:<partner>, which tests the skew against the 300-second Kerberos limit.
  3. Run dcdiag /test:Replications and work through what it reports before touching DNS again.

The domain controller resolves only through itself

You have this one if The server’s own address or the loopback is the only resolver configured, and the locator cannot find anything.

  1. Follow Microsoft’s documented ordering: a hub-site domain controller points at DNS servers in the same site as preferred and alternate and then at itself; a branch-site domain controller points at a hub-site DNS server as preferred, an in-site server as alternate, and itself last.
  2. Keep the server itself in the list. Removing it entirely leaves the machine with no resolver when its partners are down.
  3. Flush the resolver cache, then restart the DNS service and confirm the zones load.
  4. Apply the same pattern to every domain controller rather than only to the one that failed.

The secure channel is broken, so the directory refuses

You have this one if Event 4000, or 4000 and 4007 together, rather than 4013 alone.

  1. Microsoft’s documented cause here is that the domain controller has lost its secure channel with itself or with the primary domain controller emulator, and it happens on single-DC environments that hold all the operations master roles and point at themselves.
  2. Stop the KDC service on the affected domain controller.
  3. Run netdom resetpwd /server:<PDC.domain.com> /userd:<Domain\admin> /passwordd:* with elevated rights and supply the password when prompted.
  4. Reboot the server. On a single domain controller, Microsoft says to use the server’s own address in place of the PDC name, since it is the PDC.

This is the cause that makes a healthy-looking directory refuse to hand over its zones. Nothing in the replication output points at it.

A replication partner no longer exists

You have this one if The replication output names a server that was decommissioned, rebuilt or restored, and every attempt against it fails to resolve.

  1. Confirm the server is genuinely gone rather than switched off.
  2. Remove the stale references so the domain controller stops waiting for something that will never answer. Microsoft lists removing references to offline, non-functioning or non-existent domain controllers as one of the resolutions for this event.
  3. Check no operations master role is still assigned to it.
  4. Let replication run against the remaining partners, then restart the DNS service.

Cleaning up directory metadata is not reversible. Take a system state backup of a healthy domain controller before you start.

The server has to start with no partner reachable

You have this one if A single domain controller, or an isolated one you are recovering, that will otherwise never complete an initial synchronisation.

  1. Under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Parameters, set the REG_DWORD value Repl Perform Initial Synchronizations to 0.
  2. Reboot. The directory now advertises without waiting and DNS loads the zones behind it.
  3. Repair or remove the missing partners, then put the value back and confirm replication is healthy.

Microsoft’s own wording is that this is not recommended for production and should be used only for critical temporary problems, with the default restored afterwards.

Full reference

The events

Event Status What it says
4013 Published The DNS server was unable to open the Active Directory. It is configured to use directory service information, cannot operate without access to the directory, and will wait for the directory to start
4000 Published The DNS server was unable to open Active Directory. It is configured to obtain and use information from the directory for this zone and cannot load the zone without it
4015 Published The DNS server has encountered a critical error from the Active Directory. The extended error debug information, which may be empty, is in the entry
4016 Not published A DNS entry about a directory operation. Note that Group Policy also has a 4016, which is a different and unrelated event

Reading the status inside a 4015

Status in the entry Microsoft’s documented cause What to do
00002095, problem 5012 DIR_ERROR A read-only domain controller running DNS cannot connect to a writable domain controller Run nltest /dsgetdc:<domain> /WRITABLE /AVOIDSELF /TRY_NEXT_CLOSEST_SITE /DS_6 and confirm the answer is writable, runs DNS, and has correct records
0000051B, problem 1005 CONSTRAINT_ATT_TYPE SYSTEM is not the owner of the DNS zone object, or the domain Users group is missing members Check ownership in ADSI Edit; check net localgroup users /domain contains Domain Users, Authenticated Users and INTERACTIVE
00002024, problem 5008 ADMIN_LIMIT_EXCEEDED A dnsNode object’s multi-valued dnsRecord attribute holds too many values, usually orphaned records from repeated promotions and demotions Enumerate the records with repadmin /showattr against the MicrosoftDNS containers, then remove the orphans

The status codes that accompany 4013

Hex Decimal Symbolic Meaning
000025f5 9717 DNS_ERROR_DS_UNAVAILABLE The directory service is unavailable
0000232d 9005 DNS_ERROR_RCODE_REFUSED DNS operation refused
0000232a 9002 DNS_ERROR_RCODE_SERVER_FAILURE DNS server failure

Microsoft’s other documented resolutions

  • Make sure DNS servers are available at Windows startup, and that they host, forward or delegate the _msdcs zone for the forest root and the primary DNS suffix zones.
  • Enable scavenging appropriately, but not aggressively, so stale records do not accumulate and are not removed while still in use.
  • Stagger domain controller reboots so that several are not unavailable simultaneously.
  • Where a server keeps booting into a known-bad state, set the DNS Server service to manual, reboot, wait for the domain controller to advertise, and start DNS by hand.
  • Avoid single points of failure – one DNS server, or every DNS server on one physical host.

Confirming that a partner can be resolved

Microsoft points at directory events 2087 and 2088 in the Directory Service log alongside this problem. They record a destination domain controller that could not resolve a source domain controller’s alias record to a host record, and had to fall back to another name resolution method. If you see them, the replication failure and the DNS failure have the same root, and repairing the alias records breaks the deadlock in both directions at once.

How long to wait before acting

A few minutes on a healthy server. If the DNS service has not loaded its zones by the time you have signed in and opened Event Viewer, treat it as a replication problem rather than a slow start. The failure mode to watch for is the estate-wide one: several domain controllers restarted together, each waiting for the others, each taking twelve seconds per failed query across several naming contexts. That resolves itself eventually on a healthy network and does not on a broken one, which is why the replication output matters more than the clock.

Every code this article covers

Code What it points at Source
Event ID 4013 The DNS server was unable to open the Active Directory, is configured to use directory service information, cannot operate without it, and will wait for the directory to start Microsoft Learn
Event ID 4000 The DNS server was unable to open Active Directory for a zone it cannot load without. Microsoft’s documented cause is a lost secure channel with itself or with the PDC emulator Microsoft Learn
Event ID 4015 The DNS server encountered a critical error from Active Directory; the extended debug information in the entry decides which of three documented causes applies Microsoft Learn
Event ID 4016 A DNS entry about a directory operation. Not published by the vendor, and not to be confused with the unrelated Group Policy event of the same number not published by the vendor

Confirm the fix worked

  1. The directory-integrated zones are present and loaded on the affected server.
  2. A record from one of those zones is answered authoritatively when queried against this server directly.
  3. repadmin /replsummary shows no failures for this server in either direction.
  4. Reboot once more and confirm 4013 either does not appear or clears within a minute or two.
  5. The Repl Perform Initial Synchronizations value is back at its default if you changed it.

Questions people ask about this

Does this cost anything to fix?

No. This is replication repair on servers you already run and licence. No product or upgrade makes a domain controller synchronise faster.

How long should I wait before acting?

A few minutes on a healthy server. If the zones have not loaded by the time you have signed in and opened Event Viewer, treat it as replication rather than a slow boot.

Should a domain controller point at itself for DNS?

Not exclusively. Microsoft’s documented guidance is that domain controllers hosting directory-integrated zones should not point only at themselves: use another domain controller as preferred, and list this server last.

Is it safe to leave the initial synchronisation requirement off?

No. Microsoft describes setting it to 0 as not recommended for production and as something to use only for critical temporary problems, restoring the default afterwards.

I have 4000 as well as 4013. Is that the same problem?

Not necessarily. Microsoft’s documented cause for 4000, and for 4007 alongside it, is that the domain controller has lost its secure channel with itself or with the PDC emulator, repaired by stopping the KDC service, running netdom resetpwd against the PDC and rebooting.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix LDAP 49 with data 52e: bind failures that are really bad credentials Free Fix Event ID 1311 KCC errors: site links that cannot build a working topology Free Fix Error 8524 DNS lookup failure: replication cannot resolve the source DC License Error DFSR Event ID 4012: SYSVOL replication stopped after too long offline
โ† Back to Knowledge Base