Hi liuwei@cesm,
Thank you for posting in Q&A forum.
Based on your description, it seems that you had to add the user to the local administrators group of the server to propagate the domain controller.
The reason why you had to add the user to the local administrators group is because even though the user is a member of the domain admin group, it does not automatically grant the user full administrative rights on the server. The domain admin group is a member of the local administrators group by default, but it does not have the same rights as the local administrator account.
When you add a user to the local administrators group, it grants the user full administrative rights on the server, which allows the user to perform administrative tasks without any restrictions.
Hope the information above is helpful.
If you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.