Solved

What is the best method to get a Windows domain back on the correct time?

Posted on 2015-02-16
11
109 Views
Last Modified: 2015-02-20
I have a site that has a Windows 2003 Active Directory Server.  The time is currently off by about 6 minutes into the future.  The site has about 20 Windows 7 Pro workstations and 3 other Windows 2008 Servers.

What is the best method and procedures to get the time accurate again?

I had considered bringing all other workstations and servers down, manually fix the time on the Active Directory Server, and bring up the other servers and workstations.  It appears this is not a good solution from some reading I've done.

Please advise.
0
Comment
Question by:AnthonyMCSE
11 Comments
 
LVL 25

Accepted Solution

by:
Zephyr ICT earned 250 total points
ID: 40612904
Make one of your DC's an authoritative Time Server and let your workstations sync with it (which they normally will do automatically), use an external NTP source if you don't have a trusted one on the network, something like pool.ntp.org
0
 
LVL 34

Assisted Solution

by:Seth Simmons
Seth Simmons earned 250 total points
ID: 40612921
the domain controller holding the PDC emulator role should be configured as an authoritative time server

How to configure an authoritative time server in Windows Server
https://support.microsoft.com/kb/816042?wa=wsignin1.0
0
 

Author Comment

by:AnthonyMCSE
ID: 40612979
The other servers and workstations are already in sync with the PDC, my sense is that it is the PDC itself that is not syncing with an external time source.  Once I configure the PDC with an external NTP source, will the server suddenly jump back in time 5 minutes?  Can this cause issues?  Also don't want the workstations and other servers to slowly get in sync again with the PDC, I'd rather they all get in sync immediately.
0
 
LVL 24

Expert Comment

by:Mohammed Khawaja
ID: 40612985
Also note that if you have a forest (root domain with child domains) then you should make your forest PDC emulator (root domain PDC emulator) as the authoritative time server.
0
 

Author Comment

by:AnthonyMCSE
ID: 40612991
Just the one domain and just the one domain controller for now.
0
Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

 
LVL 34

Expert Comment

by:Seth Simmons
ID: 40613012
shouldn't be issues when the PDC and members make the adjustment
0
 

Author Comment

by:AnthonyMCSE
ID: 40613268
OK, so I noticed that my active directory server had almost been correctly configured for an external time source, the NTPServer registry entry had the place holder values of "Server1,0x1 Server2,0x1"  which I replaced with "0.us.pool.ntp.org,0x1 1.us.poolntp.org,0x1"
Then I stopped and started the w32time service.  The PDC updated its time within a few minutes.

The member servers don't appear to updating their time, at least not very quickly.  Using the command "w32tm /query /status" they appear to be updating their time, perhaps by 1 second every minute, based on this output:

C:\Users\administrator.DFP>w32tm /query /status
Leap Indicator: 3(last minute has 61 seconds)
Stratum: 3 (secondary reference - syncd by (S)NTP)
Precision: -6 (15.625ms per tick)
Root Delay: 0.1249542s
Root Dispersion: 7.6108138s
ReferenceId: 0xC0A800CA (source IP:  192.168.0.202)
Last Successful Sync Time: 2/16/2015 5:10:48 PM
Source: dfp-server.dfp.local
Poll Interval: 10 (1024s)

Why is it doing that?
0
 

Author Comment

by:AnthonyMCSE
ID: 40613276
And looking at a workstation, I see this:

C:\Users\Officemgr>w32tm /query /status
Leap Indicator: 0(no warning)
Stratum: 2 (secondary reference - syncd by (S)NTP)
Precision: -6 (15.625ms per tick)
Root Delay: 0.0312500s
Root Dispersion: 10.1061775s
ReferenceId: 0xC0A800CA (source IP:  192.168.0.202)
Last Successful Sync Time: 2/16/2015 4:34:29 PM
Source: dfp-server.dfp.local
Poll Interval: 12 (4096s)
0
 

Author Comment

by:AnthonyMCSE
ID: 40613300
Hmm...now the member server above shows the right time and looks like this:

C:\Users\administrator.DFP>w32tm /query /status
Leap Indicator: 0(no warning)
Stratum: 3 (secondary reference - syncd by (S)NTP)
Precision: -6 (15.625ms per tick)
Root Delay: 0.1249542s
Root Dispersion: 4.9915208s
ReferenceId: 0xC0A800CA (source IP:  192.168.0.202)
Last Successful Sync Time: 2/16/2015 5:39:17 PM
Source: dfp-server.dfp.local
Poll Interval: 10 (1024s)

I don't get it.
0
 

Author Comment

by:AnthonyMCSE
ID: 40613314
Hmmm...and here is one of my Hyper-V VM's....Looks like it is dueling the domain controller time with the VM Integrated Services time...that can't be good:  

C:\Users\administrator.DFP>w32tm /query /status
Leap Indicator: 0(no warning)
Stratum: 3 (secondary reference - syncd by (S)NTP)
Precision: -6 (15.625ms per tick)
Root Delay: 0.1249542s
Root Dispersion: 1.7611385s
ReferenceId: 0xC0A800CA (source IP:  192.168.0.202)
Last Successful Sync Time: 2/16/2015 5:43:12 PM
Source: dfp-server.dfp.local
Poll Interval: 10 (1024s)


C:\Users\administrator.DFP>w32tm /query /status
Leap Indicator: 3(last minute has 61 seconds)
Stratum: 0 (unspecified)
Precision: -6 (15.625ms per tick)
Root Delay: 0.0000000s
Root Dispersion: 0.0100000s
ReferenceId: 0x00000000 (unspecified)
Last Successful Sync Time: 2/16/2015 5:58:03 PM
Source: VM IC Time Synchronization Provider
Poll Interval: 10 (1024s)
0
 

Author Comment

by:AnthonyMCSE
ID: 40613320
Well, it took a few hours but times all seem to be synced up now.  I'll double check in the morning.  Just had to be patient. The dueling VM time sync right above has me a bit concerned, but the Hyper-V host is synced with the domain controller. Still doesn't seem like I should have two time sources duking it out.
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Join & Write a Comment

Suggested Solutions

Companies that have implemented Microsoft’s Active Directory need to ensure that the Active Directory is configured and operating properly. If there are issues found and not resolved, it eventually leads the components to fail or stop working and fi…
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now