Hi @rtuesca
Check if the RID master is available when you try to create new user.
RID muster shoule be available when you create new object in active directory.
To identy the domain controller with RID master role you can run the following command:
netdom query fsmo
Start by checking replication health between all domain controllers by runnning the commands below.
If the replication health is ok and the admin has required permission , he should be able to modify object AD from second domain controller.
repadmin /showrepl
repadmin /replsummary
dcdiag
Please don't forget to accept helpful answer