Emergency server help: get in touch

PDC Emulator NTP Time Sync: Reliable Domain Time

Point the PDC emulator at external NTP servers with w32tm, leave every other DC and client on the domain hierarchy, stop hypervisors from overriding the clock, and verify offsets with w32tm /monitor so Kerberos never fails on time skew.

Published Updated 5 min read

Kerberos tolerates a clock difference of five minutes; beyond that, authentication fails, replication logs error 8453 and Group Policy stops applying. Windows keeps every domain member within that window through a hierarchy: clients sync from the DC that authenticated them, DCs sync from the PDC emulator of their domain, and the PDC emulator of the forest root is supposed to sync from a reliable external source. If nobody configures that last step, the whole forest drifts together and nothing complains until an external system, a certificate or a cloud service disagrees. These settings apply to Windows Server 2019, 2022 and 2025.

Short answer: On the forest-root PDC emulator run w32tm /config /manualpeerlist:"0.pool.ntp.org,0x8 1.pool.ntp.org,0x8" /syncfromflags:manual /reliable:yes /update followed by Restart-Service w32time and w32tm /resync. Leave every other DC and client at /syncfromflags:domhier, disable the hypervisor’s time synchronisation for DCs, and confirm with w32tm /monitor that every DC sits within a second of the PDC. If the PDC emulator role moves, repeat the configuration on the new holder.

Identify the PDC emulator and check current state

netdom query fsmo
w32tm /query /source
w32tm /query /configuration
w32tm /monitor

/query /source on the PDC emulator should name an external server; if it shows “Local CMOS Clock” or “VM IC Time Synchronization Provider”, it is free-running or taking time from the hypervisor. /monitor lists each DC’s offset from the PDC; anything over a second or two is worth fixing today.

Configure the PDC emulator

Use at least two, preferably four, upstream servers. The 0x8 flag tells w32tm to use client mode with each peer, which is what public NTP pools expect; 0x1 adds a special polling interval, and 0x9 combines both.

w32tm /config /manualpeerlist:"0.pool.ntp.org,0x8 1.pool.ntp.org,0x8 2.pool.ntp.org,0x8" /syncfromflags:manual /reliable:yes /update
Restart-Service w32time
w32tm /resync /rediscover
w32tm /query /status

Open UDP 123 outbound from the PDC emulator on the firewall. If the organisation runs an internal GPS or appliance NTP source, use it instead of public pools. Two registry values under HKLM\SYSTEM\CurrentControlSet\Services\W32Time\Config control how much correction the service will make: MaxPosPhaseCorrection and MaxNegPhaseCorrection (REG_DWORD, seconds). Windows Server defaults to 172800 (48 hours) for DCs; set both to 3600 on the PDC so a bad upstream cannot jump the whole domain by a day, but expect a manual correction to be needed if the clock is ever more than an hour out.

Doing this with Group Policy is cleaner because it follows the role if it moves. Create a GPO linked to the Domain Controllers OU with a WMI filter of Select * from Win32_ComputerSystem where DomainRole = 5 (5 is primary domain controller), and set Computer Configuration » Policies » Administrative Templates » System » Windows Time Service » Time Providers » “Configure Windows NTP Client” with NtpServer 0.pool.ntp.org,0x8 1.pool.ntp.org,0x8, Type NTP, and “Enable Windows NTP Client” enabled. A second GPO with DomainRole = 4 (backup DC) sets Type to NT5DS so other DCs use the hierarchy.

Keep every other machine on the domain hierarchy

Other DCs and all clients should have w32tm /query /source return a DC name. If someone has hard-coded a peer list on a member server, reset it:

w32tm /config /syncfromflags:domhier /update
Restart-Service w32time
w32tm /resync

Do not configure NTP on clients through the same GPO as the PDC; a client with a manual peer list ignores the DC and, if the external source is blocked, drifts.

Stop the hypervisor fighting w32tm

Virtual DCs get time from two places unless you intervene. On Hyper-V, disable Time Synchronization under Integration Services for every DC, or leave it on and set the registry value HKLM\SYSTEM\CurrentControlSet\Services\W32Time\TimeProviders\VMICTimeProvider\Enabled (REG_DWORD) to 0 on the PDC emulator. On VMware ESXi 7, 8 and 9, untick “Synchronize guest time with host” in the VM’s options and also disable the one-off synchronisation on power operations with time.synchronize.continue = "FALSE", time.synchronize.restore = "FALSE", time.synchronize.resume.disk = "FALSE", time.synchronize.shrink = "FALSE" and time.synchronize.tools.startup = "FALSE" in the VM’s advanced configuration. The ESXi hosts themselves should still sync to NTP so snapshots and logs line up.

Verify

w32tm /monitor
w32tm /stripchart /computer:DC02 /samples:5 /dataonly
w32tm /query /source

On every DC, the offset shown by /monitor should be under one second and /source on the PDC must be the external server. In the System log, Event ID 37 confirms the time provider is synchronising and Event ID 47 or 29 means the peer is unreachable. A common pitfall is a firewall that blocks UDP 123 from the PDC but not from clients, so the PDC silently reverts to the CMOS clock; after any firewall change, re-run /query /source. If skew has already broken authentication, fix time first, then follow fix AD replication errors 8453 and 1722 to clear the replication backlog.

PDC emulator NTP at a glance

PDC Emulator NTP Time Sync summary card: On the forest-root PDC emulator run w32tm /config /manualpeerlist:"0.pool.ntp.org,0x8 1.pool.ntp.org,0x8"…
In short: On the forest-root PDC emulator run w32tm /config /manualpeerlist:”0.pool.ntp.org,0x8 1.pool.ntp.org,0x8″ /syncfromflags:manual /reliable:yes /update followed by Restart-Service w32time and w32tm /resync.

Official documentation: Windows Server documentation.

Related guides: Change a domain controller’s IP address without breaking replication · Fix “The trust relationship between this workstation and the primary domain failed” · Raise the AD forest and domain functional level safely.

Frequently asked questions

Does the PDC emulator NTP setting also apply to child domains?

No; the PDC emulator of each child domain syncs from any DC in the parent domain automatically through the hierarchy, so only the forest-root PDC emulator needs an external peer list.

How long does it take for clients to correct their time after fixing the PDC?

The PDC corrects at the next poll, other DCs within their poll interval of up to 15 minutes, and clients at their next poll, which is typically once per hour by default, so allow an hour for the whole domain to converge.

Can I undo the external NTP configuration?

Yes; w32tm /config /syncfromflags:domhier /reliable:no /update returns the DC to the domain hierarchy, and w32tm /unregister followed by w32tm /register resets the service to defaults entirely.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.