Directory replication is a privileged capability

The permission that lets a domain controller synchronise with another can be used to extract every credential in the directory.

It is a legitimate function held by legitimate systems, and if it is granted to an ordinary account it is equivalent to compromising the entire domain. Auditing who holds it is a short exercise that occasionally produces alarming answers.

More on Windows and Active Directory