behavior of MEDS replica set

Mobu 50 Reputation points Microsoft External Staff
2025-02-19T06:01:33.8533333+00:00

Hi,

I have added an extra replica set in another region in Entra Domain Service.

Q1: When I use MEDS, which replica set is used by default? Is there a primary set?

Q2: When there is disaster in one of the replica set, how can I know? And also how to know whether it has successfully failed over to the other set? And after the disaster recovery, how can I know whether the failed replica set has recovered? Anywhere I can monitor from the portal?

Thanks in advance.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,771 questions
{count} votes

1 answer

Sort by: Most helpful
  1. BANDELA Siri Chandana 1,800 Reputation points Microsoft External Staff
    2025-02-20T09:41:31.95+00:00

    Hi @Mobu
    Thank you for posting your issue on Microsoft Q&A.

    I understand that you have added an extra replica set in another region in Entra Domain Service. Additional replica sets in different Azure regions provide geographical disaster recovery for legacy applications if an Azure region goes offline.

    Each managed domain includes one initial replica set in the selected region. All replica sets are placed in the same Active Directory site. As the result, all changes are propagated using intrasite replication for quick convergence.

    When you use Microsoft Entra Domain Services (MEDS), there isn't a specific "primary" replica set. All replica sets are considered equal, and changes are propagated across all sets using AD DS replication. This ensures that each replica set contains the same data and configuration.

    You need to perform specific operations for each replica set in the Domain Services instance. The operations simulate an outage for each replica set. When domain controllers aren't reachable, the client automatically fails over to a reachable domain controller.

    Tools like nslookup, nltest, and PowerShell cmdlets can help you check the status of domain controllers and ensure DNS resolution is working properly.

    Perform validation checks using tools like Get-AdDomain and nltest to ensure the domain controllers are back online and functioning correctly.

    Follow the document for further information: https://learn.microsoft.com/en-us/entra/identity/domain-services/concepts-replica-sets
    https://learn.microsoft.com/en-us/entra/identity/domain-services/tutorial-perform-disaster-recovery-drill

    Hope this helps. Do let us know if you have any further queries. If this answers your query, do click `Accept Answer` and `Yes`.

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.