The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Inspect DFS featuresGet-WindowsFeature ` FS-DFS-Namespace,FS-DFS-Replication,RSAT-DFS-Mgmt-ConView examples
Verify NTFS storageGet-Volume | Select-Object DriveLetter,FileSystem,HealthStatus,SizeRemainingView examples
List namespace rootsGet-DfsnRootView examples
List namespace foldersGet-DfsnFolder -Path '\contoso.example\Public\*'View examples
Inspect root targetsGet-DfsnRootTarget -Path '\contoso.example\Public'View examples
Inspect folder targetsGet-DfsnFolderTarget -Path ` '\contoso.example\Public\Data'View examples
Add folder targetNew-DfsnFolderTarget -Path ` '\contoso.example\Public\Data' -TargetPath ` '\FS02\Data$' -WhatIfView examples
Inspect referral settingsGet-DfsnRoot -Path '\contoso.example\Public' | Select-Object State,TimeToLiveSec,EnableSiteCostingView examples
List replication groupsGet-DfsReplicationGroupView examples
List replicated foldersGet-DfsReplicatedFolder -GroupName 'Data-RG'View examples
Inspect membershipsGet-DfsrMembership -GroupName 'Data-RG' -FolderName ` 'Data'View examples
Inspect connectionsGet-DfsrConnection -GroupName 'Data-RG'View examples
Measure replication backlogGet-DfsrBacklog -GroupName 'Data-RG' -FolderName 'Data' ` -SourceComputerName FS01 -DestinationComputerName FS02View examples
Create propagation testStart-DfsrPropagationTest -GroupName 'Data-RG' ` -FolderName 'Data' -ReferenceComputerName FS01View examples
Read DFSR eventsGet-WinEvent -LogName 'DFS Replication' -MaxEvents 100View examples
Poll AD configurationUpdate-DfsrConfigurationFromAD -ComputerName FS01View examples

DFS Namespaces provides stable logical UNC paths and referrals; DFS Replication synchronizes folder contents between servers. They are complementary but independent services. Successful deployments start with supported NTFS storage, Active Directory and site readiness, authoritative data ownership, backup, staging estimates, namespace permissions, and an explicit cutover plan. Never treat a replicated folder as a backup or manually clean its private database.

Step by step

Detailed examples

01

Verify roles, storage, AD, and data ownership

DFS Namespaces and DFS Replication are Windows Server role services; the DFSN and DFSR PowerShell modules come with management tools. DFSR supports NTFS volumes, not ReFS, FAT, or Cluster Shared Volumes, and all members of a replication group must be in the same AD forest. Verify AD schema, DNS, sites and subnets, RPC/firewall paths, antivirus compatibility, free space, VSS-aware backups, and an authoritative initial data copy. Install roles from an elevated Windows PowerShell session; a restart can be requested by servicing.

Run a read-only DFS readiness inventory
Get-WindowsFeature FS-DFS-Namespace, FS-DFS-Replication, RSAT-DFS-Mgmt-Con
Get-Volume | Select-Object DriveLetter, FileSystem, HealthStatus, SizeRemaining
Get-CimInstance Win32_ComputerSystem | Select-Object Name, Domain, PartOfDomain
Get-ADForest | Select-Object RootDomain, ForestMode
Back to quick reference ↑
02

Design namespace paths independently from storage

A DFS namespace is a metadata layer that maps logical folders to SMB shares. It does not copy files. Domain-based namespaces use AD and can have multiple namespace servers; standalone namespaces store configuration locally and can use failover clustering. Choose stable names, folder boundaries, target eligibility, access-based enumeration, and referral TTLs. Share and NTFS permissions still secure each target, so identical namespace paths do not imply identical ACLs or data.

Inventory namespace structure and settings
Get-DfsnRoot | Select-Object Path, Type, State, TimeToLiveSec
Get-DfsnFolder -Path '\contoso.example\Public\*' |
    Select-Object Path, State, TimeToLiveSec, EnableTargetFailback
Back to quick reference ↑
03

Add targets only after data and permissions are ready

A folder target is a UNC path that DFS clients can receive in referrals. New-DfsnFolderTarget does not create the SMB share, seed files, align ACLs, or validate application consistency. Prepare and validate the target first, add it disabled when possible, test direct UNC access, then enable it in a controlled change. WhatIf previews the DFSN metadata action but not client cache behavior or application effects. Removing a target does not delete its files.

Compare direct targets before changing referrals
$Root = '\contoso.example\Public'
$Path = '\contoso.example\Public\Data'
Get-DfsnRootTarget -Path $Root | Select-Object TargetPath, State
Get-DfsnFolderTarget -Path $Path | Select-Object Path, TargetPath, State
Test-Path '\FS01\Data$'
Test-Path '\FS02\Data$'
# New-DfsnFolderTarget -Path $Path -TargetPath '\FS02\Data$' -WhatIf
Back to quick reference ↑
04

Align referrals with AD site topology

Clients cache namespace and folder referrals for their TTL. Site costing directs clients toward lower-cost targets only when AD sites, subnets, and server locations are correct. Target priority can override normal ordering and should be used sparingly. A changed target state may not affect clients until cached referrals expire or are flushed. Test from representative subnets and avoid using dfsutil cache flushing as a broad production workaround.

Review client and server referral evidence
Get-DfsnRoot -Path '\contoso.example\Public' |
    Select-Object Path, EnableSiteCosting, TimeToLiveSec
Get-DfsnFolderTarget -Path '\contoso.example\Public\Data' |
    Select-Object TargetPath, State, ReferralPriorityClass, ReferralPriorityRank
dfsutil.exe cache referral
Back to quick reference ↑
05

Design topology, staging, and conflict behavior

DFSR is multi-master replication, not distributed locking, shared storage, backup, or synchronous application replication. Concurrent edits can create conflicts and last-writer outcomes. Size staging and ConflictAndDeleted quotas for workload churn and largest files, design connections around bandwidth and AD sites, and exclude unsupported or transient application data. Database files and workloads requiring coordinated writes need application-aware replication. Seed data with a documented process before enabling membership to reduce transfer volume.

Inventory replicated-folder policy
Get-DfsReplicationGroup | Select-Object GroupName, DomainName
Get-DfsReplicatedFolder -GroupName 'Data-RG' |
    Select-Object FolderName, DfsnPath, FileNameToExclude, DirectoryNameToExclude
Get-DfsrMembership -GroupName 'Data-RG' -FolderName 'Data' |
    Select-Object ComputerName, ContentPath, StagingPathQuotaInMB, State
Back to quick reference ↑
06

Treat primary membership and connections as cutover state

The primary member flag matters only during initial synchronization and does not permanently make one server authoritative. Enable memberships only after confirming the intended authoritative data and backups. DFSR connections are directional; a two-way topology needs connections in both directions. AD changes must replicate to domain controllers and members must poll before behavior changes. Cmdlets support WhatIf on many mutations, but no preview can model file conflict outcomes.

Review topology in both directions
Get-DfsrMembership -GroupName 'Data-RG' -FolderName 'Data' |
    Select-Object ComputerName, ContentPath, Enabled, PrimaryMember
Get-DfsrConnection -GroupName 'Data-RG' |
    Select-Object SourceComputerName, DestinationComputerName, Enabled, State
# Update-DfsrConfigurationFromAD only after approved AD configuration changes.
Back to quick reference ↑
07

Measure backlog directionally and over time

Backlog is source-to-destination and must be checked in both directions for multi-master groups. A count alone does not reveal bytes, oldest age, locked files, or whether progress is occurring. Sample backlog repeatedly, correlate bandwidth and DFSR events, and use propagation tests for synthetic latency measurements. Get-DfsrBacklog can be expensive on very large queues and returns only a limited number of file records while exposing a verbose count message in common usage; plan monitoring accordingly.

Sample both directions without changing data
$Common = @{ GroupName='Data-RG'; FolderName='Data' }
Get-DfsrBacklog @Common -SourceComputerName FS01 -DestinationComputerName FS02
Get-DfsrBacklog @Common -SourceComputerName FS02 -DestinationComputerName FS01
Get-DfsrState -ComputerName FS01 | Select-Object FileName, UpdateState
Back to quick reference ↑
08

Recover from supported backups and documented procedures

Never delete the System Volume Information DFSR database or manipulate private folders as routine repair. Diagnose service, AD configuration, disk, journal, staging, connectivity, and event IDs first. Restoring files from backup can trigger replication and conflicts; authoritative and non-authoritative recovery require product-specific procedures, especially for SYSVOL. Keep offline backups because ransomware and deletion replicate. Update-DfsrConfigurationFromAD polls configuration but does not repair bad data or force instant convergence.

Collect DFSR evidence before remediation
Get-Service DFSR | Select-Object Status, StartType
Get-WinEvent -LogName 'DFS Replication' -MaxEvents 100 |
    Select-Object TimeCreated, Id, LevelDisplayName, Message
Get-DfsrState -ComputerName FS01
Get-DfsrConnection -GroupName 'Data-RG' | Select-Object *
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Microsoft LearnDFS Namespaces overviewlearn.microsoft.com
  2. Microsoft LearnDFS Replication overviewlearn.microsoft.com
  3. Microsoft LearnInstall DFS Replicationlearn.microsoft.com
  4. Microsoft LearnDFSN modulelearn.microsoft.com
  5. Microsoft LearnDFSR modulelearn.microsoft.com
  6. Microsoft LearnDelegate management permissions for DFS Namespaceslearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback