Unlike standalone Windows systems, computers joined to an Active Directory domain normally do not require individual NTP configuration. Instead, Windows automatically builds a hierarchy that distributes accurate time throughout the domain.
In a correctly configured environment, only the PDC Emulator in the forest root domain should obtain its time from an external source. Every other computer in the forest ultimately synchronises from that server.
Although the Windows Time Service requires very little day-to-day administration, incorrect configuration can cause authentication failures, replication problems and unexpected behaviour across the domain. Fortunately, most issues can be avoided by understanding how the hierarchy is designed to operate.
This section explains how Windows Time Service works within Active Directory, how to configure the PDC Emulator correctly and how to verify that the domain hierarchy is functioning as expected.
Topics in this section
Understanding the Windows Time hierarchy
Learn how Windows distributes time through an Active Directory forest, how the hierarchy is constructed and why only one server should synchronise with an external time source.
Configuring the PDC Emulator
The PDC Emulator is the authoritative time source for the forest. Learn how to configure it correctly, choose reliable external NTP servers and verify that the configuration is working.
Verifying the configuration
Confirm how the Windows Time Service is currently operating, identify the PDC Emulator and verify synchronisation across the domain.
Common configuration mistakes
Many Windows Time problems are caused by overriding the default Active Directory hierarchy. Learn which mistakes occur most frequently and how to avoid them.