ACTIVE DIRECTORY

Active Directory Branch Office Replication

An Active Directory branch office replication diagram explains where directory services run and how they reach a remote site. It distinguishes writable domain controllers at headquarters from a read-only domain controller at the branch, then shows the site link between them. This is useful when planning local sign-in performance, outage behavior, or administrative access at a smaller office. Include the local DNS role because clients commonly use the domain controller for name resolution as well as authentication. Add the client networks on each side so the reason for each controller is visible. For a larger branch, extend the view with redundant WAN paths, writable controllers, or local application services as needed.

UPDATED 2026-09-24
EXAMPLEActive Directory Branch Office Replication
Make this diagram your own.

Open it in the AI editor with a prompt pre-filled — keep what works, change what doesn't.

CASE ANALYSIS

Scenario

Plan authentication and directory availability for a small remote office.

Key decisions

  • Two HQ controllers: Headquarters retains redundant writable directory services.
  • RODC at branch: The branch can authenticate locally while limiting stored credentials.
  • VPN site link: Replication and administrative traffic have an explicit path.

When to reuse this

Use this when a branch needs local authentication and controlled replication back to a central domain.

FAQ

Frequently asked questions

What is an RODC?01
A read-only domain controller holds a read-only copy of Active Directory and is often used where physical or administrative security is limited.
How does branch replication work?02
The branch controller receives replicated directory data from writable domain controllers through a configured site link.
Why show the VPN path?03
It identifies the connection that carries replication and remote administration between the locations.
Open this example in the editor →

Tweak it with chat, export PNG/SVG, or fork it for your own use case.