← Back to case studies
WINDOWS SERVER · ACTIVE DIRECTORY

Restoring Reliable Time Synchronisation in an AD Environment

A domain time-skew incident that required tracing the Windows Time hierarchy, correcting the authoritative source and verifying that domain members were synchronising correctly.

Active DirectoryEnvironment
Windows TimeService investigated
ResolvedHierarchy verified

Two domain controllers were approximately three minutes apart. In an Active Directory environment, that is not just a cosmetic clock problem. Reliable time is important to authentication and other domain services, so the source and hierarchy had to be verified rather than manually adjusting clocks.

Trace the source before changing the configuration.

  • Queried Windows Time status and source information with w32tm.
  • Confirmed which server was acting as the upstream time source.
  • Corrected the time hierarchy so the appropriate domain controller synchronised with an external NTP source.
  • Forced resynchronisation and then checked source, stratum and last successful sync information.
  • Verified that downstream domain systems were taking time from the domain hierarchy rather than arbitrary external sources.
Windows ServerActive Directoryw32tmNTPPowerShell
Operational lesson

A successful resync command does not prove that the architecture is correct. The important verification is where the machine is actually sourcing time from, and whether that source fits the intended AD time hierarchy.