We have multiple Active Directory forests in different locations as part of the requirement and design. There are some applications deployed in one site that feed information to apps installed in other AD forests. Last month we had an incident in one of our sites that they had a time difference of some 15 minutes in their AD and the admin wanted to correct the time and changed the system clock on the PDC by 3 minutes. I am told that that change caused a major downtime where users were not able to access file shares and some couldn’t log on. They logged in to the DC form the hypervisor and changed it back to the original time and things got better.
Now we have time related issues in other sites also. all domain controllers are virtualized. So far the PDC are taking time locally and no time server is configured. We have configured switched in each of the sites as time sources.
There is a time difference of 15 minutes. This is what is scaring me. Time will change 15 mts ahead. I have the commands and the procedure. That is not the issue.
I want to explore the safest options where the time does not change abruptly and cause issues. I think when the PDC is configured to sync time with the time source the time should change gradually and not at one time.
Looking for the safest options to change time. 15 mts time difference between the PDC and the time source.