Solved

Why would "net time /set" target a DC that does not hold the PDC emulator role?

Posted on 2009-04-06
3
353 Views
Last Modified: 2012-05-06
Greetings -

I'm seeing what I perceive to be strange behaviors of the "net time" command in my domain.  Perhaps I need to be educated so I know what's going on.

I have almost 20 DCs in my domain.  One of those holds all five (5) FSMO roles.  It is my understanding that the DC holding the PDC Emulator role is the only one in the Domain responsible for time synchronization.  Am I wrong?

My workstations and servers *are* syncing time correctly.  However, when I run "net time /set", the DC that the command attempts to target is not the DC holding the PDC emulator role and most surprising to me, the DC is out of site.  Why might this be the case?

Also, when I run "net time /querysntp", should I see the PDC DC listed?  When I run that command, all I see is time.windows.com.

Any help is appreciated, thanks.  If you have questions, fire away.
0
Comment
Question by:amendala
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 85

Accepted Solution

by:
oBdA earned 500 total points
ID: 24079177
"net time" is a deprecated command; it dates back to NT and will only return any DC from the browser list. it knows exactly *nothing* about AD and its time hierarchy.
Domain members will sync with the DC authenticating them, DCs will sync with the PDC emulator, and the only machine that needs to sync with an external source is the PDCe.
Domain members are configured to use the domain hierarchy to sync, a manually configured time server will not be used (unless the domain sync is explicitly disabled).
0
 
LVL 7

Expert Comment

by:tplaya07
ID: 24079322
I have a login script that runs whenever a client logs into the domain that maps drives and uses the following command to sync time:
net time \\PRIMARYDOMAINCONTROLLER /set /yes
0
 
LVL 85

Expert Comment

by:oBdA
ID: 24079404
tplaya07,
you can remove that form your script, because
1) it's unnecessary: any NT based Windows since 2000 has the time service running and will *by* *default* sync with the domain hierarchy I explained above if it's a domain member (and can be manually configured if not), and
2) regular users don't have permissions to change the time anyway.
0

Featured Post

Online Training Solution

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action. Forget about retraining and skyrocket knowledge retention rates.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
Here's a look at newsworthy articles and community happenings during the last month.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

691 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question