# PDC Emulator NTP Time Sync: Reliable Domain Time

Source: https://srvscripts.com/guides/pdc-emulator-ntp-time-sync/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

In short: On the forest-root PDC emulator run w32tm /config /manualpeerlist:”0.pool.ntp.org,0x8 1.pool.ntp.org,0x8″ /syncfromflags:manual /reliable:yes /update followed by Restart-Service w32time and w32tm /resync.

Kerberos tolerates a clock difference of five minutes; beyond that, authentication fails, replication logs error 8453 and Group Policy stops applying. Windows keeps every domain member within that window through a hierarchy: clients sync from the DC that authenticated them, DCs sync from the PDC emulator of their domain, and the PDC emulator of the forest root is supposed to sync from a reliable external source. If nobody configures that last step, the whole forest drifts together and nothing complains until an external system, a certificate or a cloud service disagrees. These settings apply to Windows Server 2019, 2022 and 2025.

**Short answer:** On the forest-root PDC emulator run `w32tm /config /manualpeerlist:"0.pool.ntp.org,0x8 1.pool.ntp.org,0x8" /syncfromflags:manual /reliable:yes /update` followed by `Restart-Service w32time` and `w32tm /resync`. Leave every other DC and client at `/syncfromflags:domhier`, disable the hypervisor’s time synchronisation for DCs, and confirm with `w32tm /monitor` that every DC sits within a second of the PDC. If the PDC emulator role moves, repeat the configuration on the new holder.

## Identify the PDC emulator and check current state

```
netdom query fsmo
w32tm /query /source
w32tm /query /configuration
w32tm /monitor
```

`/query /source` on the PDC emulator should name an external server; if it shows “Local CMOS Clock” or “VM IC Time Synchronization Provider”, it is free-running or taking time from the hypervisor. `/monitor` lists each DC’s offset from the PDC; anything over a second or two is worth fixing today.

## Configure the PDC emulator

Use at least two, preferably four, upstream servers. The `0x8` flag tells w32tm to use client mode with each peer, which is what public NTP pools expect; `0x1` adds a special polling interval, and `0x9` combines both.

```
w32tm /config /manualpeerlist:"0.pool.ntp.org,0x8 1.pool.ntp.org,0x8 2.pool.ntp.org,0x8" /syncfromflags:manual /reliable:yes /update
Restart-Service w32time
w32tm /resync /rediscover
w32tm /query /status
```

Open UDP 123 outbound from the PDC emulator on the firewall. If the organisation runs an internal GPS or appliance NTP source, use it instead of public pools. Two registry values under `HKLM\SYSTEM\CurrentControlSet\Services\W32Time\Config` control how much correction the service will make: `MaxPosPhaseCorrection` and `MaxNegPhaseCorrection` (REG_DWORD, seconds). Windows Server defaults to 172800 (48 hours) for DCs; set both to 3600 on the PDC so a bad upstream cannot jump the whole domain by a day, but expect a manual correction to be needed if the clock is ever more than an hour out.

Doing this with Group Policy is cleaner because it follows the role if it moves. Create a GPO linked to the Domain Controllers OU with a WMI filter of `Select * from Win32_ComputerSystem where DomainRole = 5` (5 is primary domain controller), and set Computer Configuration » Policies » Administrative Templates » System » Windows Time Service » Time Providers » “Configure Windows NTP Client” with NtpServer `0.pool.ntp.org,0x8 1.pool.ntp.org,0x8`, Type NTP, and “Enable Windows NTP Client” enabled. A second GPO with `DomainRole = 4` (backup DC) sets Type to NT5DS so other DCs use the hierarchy.

## Keep every other machine on the domain hierarchy

Other DCs and all clients should have `w32tm /query /source` return a DC name. If someone has hard-coded a peer list on a member server, reset it:

```
w32tm /config /syncfromflags:domhier /update
Restart-Service w32time
w32tm /resync
```

Do not configure NTP on clients through the same GPO as the PDC; a client with a manual peer list ignores the DC and, if the external source is blocked, drifts.

## Stop the hypervisor fighting w32tm

Virtual DCs get time from two places unless you intervene. On Hyper-V, disable Time Synchronization under Integration Services for every DC, or leave it on and set the registry value `HKLM\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\VMICTimeProvider\Enabled` (REG_DWORD) to 0 on the PDC emulator. On VMware ESXi 7, 8 and 9, untick “Synchronize guest time with host” in the VM’s options and also disable the one-off synchronisation on power operations with `time.synchronize.continue = "FALSE"`, `time.synchronize.restore = "FALSE"`, `time.synchronize.resume.disk = "FALSE"`, `time.synchronize.shrink = "FALSE"` and `time.synchronize.tools.startup = "FALSE"` in the VM’s advanced configuration. The ESXi hosts themselves should still sync to NTP so snapshots and logs line up.

## Verify

```
w32tm /monitor
w32tm /stripchart /computer:DC02 /samples:5 /dataonly
w32tm /query /source
```

On every DC, the offset shown by `/monitor` should be under one second and `/source` on the PDC must be the external server. In the System log, Event ID 37 confirms the time provider is synchronising and Event ID 47 or 29 means the peer is unreachable. A common pitfall is a firewall that blocks UDP 123 from the PDC but not from clients, so the PDC silently reverts to the CMOS clock; after any firewall change, re-run `/query /source`. If skew has already broken authentication, fix time first, then follow [fix AD replication errors 8453 and 1722](/guides/ad-replication-error-1722-8453/) to clear the replication backlog.

## PDC emulator NTP at a glance

**Official documentation:** [Windows Server documentation](https://learn.microsoft.com/en-us/windows-server/).

**Related guides:** [Change a domain controller’s IP address without breaking replication](https://srvscripts.com/guides/change-domain-controller-ip-address/) · [Fix “The trust relationship between this workstation and the primary domain failed”](https://srvscripts.com/guides/trust-relationship-failed-fix/) · [Raise the AD forest and domain functional level safely](https://srvscripts.com/guides/raise-ad-functional-level/).

## Frequently asked questions

### Does the PDC emulator NTP setting also apply to child domains?

No; the PDC emulator of each child domain syncs from any DC in the parent domain automatically through the hierarchy, so only the forest-root PDC emulator needs an external peer list.

### How long does it take for clients to correct their time after fixing the PDC?

The PDC corrects at the next poll, other DCs within their poll interval of up to 15 minutes, and clients at their next poll, which is typically once per hour by default, so allow an hour for the whole domain to converge.

### Can I undo the external NTP configuration?

Yes; `w32tm /config /syncfromflags:domhier /reliable:no /update` returns the DC to the domain hierarchy, and `w32tm /unregister` followed by `w32tm /register` resets the service to defaults entirely.
