I have two domain controllers and two dhcp servers. If the domain controller which holds the FSMO roles is powered off users cannot authenticate. When the dc is powered up all is fine again. DHCP is set to give out both dc's DNS to the client machines. DNS settings on both controllers looks similar as do the forward lookups. Both DC's have GC option ticked. Thanks for looking, any suggestions appreciated.