Non-Replicated Attributes in Active Directory

Non-Replicated Attributes in Active Directory title beside a PowerShell window listing lastLogon, badPwdCount and other attributes

Not all Active Directory attributes are replicated between domain controllers. While most attributes are synchronized across the domain, some are maintained locally on each domain controller and can contain different values. Common examples include lastLogon, badPwdCount, and whenChanged.

In this article, I'll show you how non-replicated attributes work and how to list all non-replicated attributes in your domain.

What is a non-replicated attribute?

A non-replicated attribute in Active Directory is an attribute whose value is stored and maintained locally on each domain controller rather than synchronized across the domain. This means the same attribute can have different values depending on which domain controller you query.

For example, the lastLogon attribute records the last time a user authenticated against a specific domain controller. Because this attribute is not replicated, each domain controller maintains its own value.

Non-replication example

Let's look at an example in Active Directory. I'm connected to domain controller DC1, I open the attribute editor and see the lastLogon value.

attribute editor on DC1 showing the user's lastLogon of non-replicated attribute

Now I'll connect to domain controller DC2, I open the attribute editor and the same account has a different date for lastLogon.

attribute editor on DC2 showing the user's lastLogon of non-replicated attribute

So the attribute has a value of 10/8/2026 on DC1 and a value of 10/5/2026 on DC2.

This is a great example of how an attribute is updated on one domain controller and it's not replicated to other domain controllers, therefore each domain controller has a different value.

Replication example

Now let's look at a replicated attribute so you can see the difference.

Back on my DC1, I'll look at the attribute lastLogonTimestamp this attribute is replicated so each domain controller should be the same.

attribute editor on DC1 showing the user's lastLogonTimestamp of a replicated attribute

Now on DC2.

attribute editor on DC2 showing the user's lastLogonTimestamp of a replicated attribute

You can see both domain controllers have the exact same value for this attribute and that's because that specific attribute is replicated to all domain controllers.

Why it matters

It's important to understand non-replicated attributes vs replicated attributes because their values can differ between domain controllers. If you are creating a report or investigating an issue you need to have the correct information.

Querying only one domain controller may return incomplete or outdated information. For example, to determine a user's most recent lastLogon date, you must check the lastLogon attribute on all domain controllers. Knowing which attributes are not replicated helps ensure accurate reporting, troubleshooting, and account management.

List of non-replicated attributes

Here is a list of non-replicated attributes for the default schema.

Important: back-link attributes still match on every DC

Back-link attributes, such as memberOf, directReports, managedObjects and any attribute ending in BL, are on this list because they are not replicated themselves. Each domain controller builds them from a matching forward-link attribute that does replicate. For example, a user's memberOf is built from the member attribute on each group, and directReports is built from the manager attribute on each user.

So unlike lastLogon, a back-link has the same value on every domain controller once replication has completed.

  • badPasswordTime
  • badPwdCount
  • bridgeheadServerListBL
  • directReports
  • distinguishedName
  • dSCorePropagationData
  • frsComputerReferenceBL
  • fRSMemberReferenceBL
  • isPrivilegeHolder
  • lastLogoff
  • lastLogon
  • logonCount
  • managedObjects
  • masteredBy
  • memberOf
  • modifiedCount
  • msAuthz-MemberRulesInCentralAccessPolicyBL
  • msCOM-PartitionSetLink
  • msCOM-UserLink
  • msDFSR-ComputerReferenceBL
  • msDFSR-MemberReferenceBL
  • msDS-AssignedAuthNPolicyBL
  • msDS-AssignedAuthNPolicySiloBL
  • msDS-AuthenticatedToAccountlist
  • msDS-AuthNPolicySiloMembersBL
  • msDS-BridgeHeadServersUsed
  • msDS-Cached-Membership
  • msDS-Cached-Membership-Time-Stamp
  • msDS-ClaimSharesPossibleValuesWithBL
  • msDS-ComputerAuthNPolicyBL
  • msDS-EnabledFeatureBL
  • msDS-ExecuteScriptPassword
  • msDS-GenerationId
  • msDS-HostServiceAccountBL
  • msDS-IsDomainFor
  • msDS-IsFullReplicaFor
  • msDS-IsPartialReplicaFor
  • msDS-IsPrimaryComputerFor
  • msDS-KeyCredentialLink-BL
  • msDS-KeyPrincipalBL
  • msDS-KrbTgtLinkBl
  • msDs-masteredBy
  • msds-memberOfTransitive
  • msDS-MembersForAzRoleBL
  • msDS-MembersOfResourcePropertyListBL
  • msds-memberTransitive
  • msDS-NC-RO-Replica-Locations-BL
  • msDS-NcType
  • msDS-NonMembersBL
  • msDS-ObjectReferenceBL
  • msDS-OIDToGroupLinkBl
  • msDS-OperationsForAzRoleBL
  • msDS-OperationsForAzTaskBL
  • msDS-parentdistname
  • msDS-PSOApplied
  • msDS-ReplicationEpoch
  • msDS-RetiredReplNCSignatures
  • msDS-RevealedDSAs
  • msDS-ServiceAuthNPolicyBL
  • msDS-TasksForAzRoleBL
  • msDS-TasksForAzTaskBL
  • msDS-TDOEgressBL
  • msDS-TDOIngressBL
  • msds-tokenGroupNames
  • msds-tokenGroupNamesGlobalAndUniversal
  • msds-tokenGroupNamesNoGCAcceptable
  • msDS-TransformationRulesCompiled
  • msDS-UserAuthNPolicyBL
  • msDS-USNLastSyncSuccess
  • msDS-ValueTypeReferenceBL
  • msSFU30PosixMemberOf
  • msTPM-TpmInformationForComputerBL
  • msTSPrimaryDesktopBL
  • msTSSecondaryDesktopBL
  • netbootSCPBL
  • nonSecurityMemberBL
  • objectGUID
  • ownerBL
  • partialAttributeDeletionList
  • partialAttributeSet
  • pekList
  • prefixMap
  • queryPolicyBL
  • replPropertyMetaData
  • replUpToDateVector
  • repsFrom
  • repsTo
  • rIDNextRID
  • rIDPreviousAllocationPool
  • schemaUpdate
  • serverReferenceBL
  • serverState
  • siteObjectBL
  • subRefs
  • uSNChanged
  • uSNCreated
  • uSNLastObjRem
  • whenChanged

List every non-replicated attribute with PowerShell

If you have updated your Active Directory schema you may have other non-replicated attributes. To see all non-replicated attributes in your domain run the command below.

$schema = (Get-ADRootDSE).schemaNamingContext
Get-ADObject -SearchBase $schema -LDAPFilter "(systemFlags:1.2.840.113556.1.4.803:=1)" -Properties lDAPDisplayName |
Select-Object lDAPDisplayName | Sort-Object lDAPDisplayName

Check a non-replicated attribute on every DC

Here is a script that will let you check a non-replicated attribute on every domain controller. At the top change username and the attribute value.

# Specify the user and attribute
$username = "jsmith"
$attribute = "lastLogon"

# Get all domain controllers
$domainControllers = Get-ADDomainController -Filter *

# Query each domain controller
$results = foreach ($dc in $domainControllers) {
    $user = Get-ADUser -Identity $username `
        -Server $dc.HostName `
        -Properties $attribute

    $value = $user.$attribute

    # Convert lastLogon to readable date
    if ($attribute -eq "lastLogon" -and $value -gt 0) {
        $value = [DateTime]::FromFileTime($value)
    }

    [PSCustomObject]@{
        DomainController = $dc.HostName
        Attribute        = $attribute
        Value            = $value
    }
}

$results | Format-Table -AutoSize

Here is an example of checking the whenchanged attribute on all 5 of my domain controllers.

powershell example checking non-replicated attribute on all domain controllers