Active Directory Replication
Active Directory replication failed because the target principal name is incorrect
The target principal name is incorrect.
Active Directory replication failed because Kerberos authentication between domain controllers could not validate the expected service principal name.
Observed message
The target principal name is incorrect.
Why it happens
- The secure channel or machine-account password between domain controllers is out of sync.
- Kerberos SPN or ticket data does not match the target controller correctly.
- The destination controller received an invalid service ticket for the source controller.
How to fix it
- Check the secure channel and machine-account password state between the affected controllers.
- Review SPN registration and Kerberos ticket behavior on both domain controllers.
- Reset the secure channel or machine password if the controllers are out of sync.