Active Directory Branch Office Replication
An Active Directory branch office replication diagram explains where directory services run and how they reach a remote site. It distinguishes writable domain controllers at headquarters from a read-only domain controller at the branch, then shows the site link between them. This is useful when planning local sign-in performance, outage behavior, or administrative access at a smaller office. Include the local DNS role because clients commonly use the domain controller for name resolution as well as authentication. Add the client networks on each side so the reason for each controller is visible. For a larger branch, extend the view with redundant WAN paths, writable controllers, or local application services as needed.
Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.
Scenario
Plan authentication and directory availability for a small remote office.
Key decisions
- Two HQ controllers: Headquarters retains redundant writable directory services.
- RODC at branch: The branch can authenticate locally while limiting stored credentials.
- VPN site link: Replication and administrative traffic have an explicit path.
When to reuse this
Use this when a branch needs local authentication and controlled replication back to a central domain.
Frequently asked questions
What is an RODC?
How does branch replication work?
Why show the VPN path?
More active directory examples
Try the diagram makers.
Tweak it with chat, export PNG/SVG, or fork it for your own use case.