Multiple domain controllers and domain time server

%3CLINGO-SUB%20id%3D%22lingo-sub-2111790%22%20slang%3D%22en-US%22%3EMultiple%20domain%20controllers%20and%20domain%20time%20server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2111790%22%20slang%3D%22en-US%22%3E%3CP%3EI%20maintain%20existing%20solutions%2C%20almost%20never%20setting%20up%20an%20entire%20new%20network.%3C%2FP%3E%3CP%3EOne%20of%20my%20customers%20has%20three%20DC's%20(DC1%2C%20DC2%2C%20DC3).%3CBR%20%2F%3EWhen%20running%20%3CSPAN%3Enltest%20%2Fdsgetdc%3A%3CDOMNAME%3E%20%2Ftimeserv%3C%2FDOMNAME%3E%3C%2FSPAN%3E%20on%20the%20servers%20I'm%20getting%20different%20results.%20Some%20times%20pointing%20to%20DC1%2C%20some%20times%20DC3.%3C%2FP%3E%3CP%3E%3CSPAN%3EW32tm%20%2Fquery%20%2Fsource%3C%2FSPAN%3E%20also%20gives%20varying%20results%2C%20some%20looking%20to%20free%20running%20clock%2C%20some%20to%20a%20DC%2C%20some%20to%20CMOS.%3CBR%20%2F%3E%3CBR%20%2F%3EI've%20read%20this%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fservices-hub%2Fhealth%2Fremediation-steps-ad%2Fconfigure-the-root-pdc-with-an-authoritative-time-source-and-avoid-widespread-time-skew%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3EMS%20article%3C%2FA%3E%20about%20network%20time%20servers.%3C%2FP%3E%3CP%3EThe%20customer's%20Default%20Domain%20Controller%20Policy%20(group%20policy)%20has%20the%20following%20settings%20enabled%3CBR%20%2F%3E-%20Configure%20Windows%20NTP%20Client%3C%2FP%3E%3CP%3E-%20Enable%20Windows%20NTP%20Client%3C%2FP%3E%3CP%3E-%20Enable%20Windows%20NTP%20Server%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWith%20the%20settings%20in%20place%2C%20on%20the%20Default%20Domain%20Controller%20Policy%20(which%20is%20applied%20to%20each%20of%20the%20DC)%2C%20wouldn't%20it%20make%20each%20DC%20fight%20over%20who%20is%20the%20time%20server%20for%20the%20domain%3F%3CBR%20%2F%3E%3CBR%20%2F%3EThank%20you%20in%20advance.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2111790%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Edomain%20controller%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2111870%22%20slang%3D%22en-US%22%3ERe%3A%20Multiple%20domain%20controllers%20and%20domain%20time%20server%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2111870%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSTRONG%3ESome%20general%20info%3C%2FSTRONG%3E%3CBR%20%2F%3E-%20All%20domain%20members%20should%20use%20NT5DS%20domain%20time.%20%3CBR%20%2F%3E-%20Desktops%20and%20member%20servers%20sync%20with%20any%20domain%20controller.%20%3CBR%20%2F%3E-%20Domain%20controllers%20sync%20with%20PDC%20emulator%20(one%20per%20domain)%20%3CBR%20%2F%3E-%20PDC%20emulator%20in%20child%20domain%20can%20sync%20with%20any%20domain%20controller%20in%20parent%20domain.%20%3CBR%20%2F%3E-%20PDC%20emulator%20in%20parent%20domain%20syncs%20with%20either%20a%20hardware%20clock%20or%20possibly%20an%20external%20source.%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Fnepapfe%2F2013%2F03%2F01%2Fits-simple-time-configuration-in-active-directory%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.technet.microsoft.com%2Fnepapfe%2F2013%2F03%2F01%2Fits-simple-time-configuration-in-active-directory%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Visitor

I maintain existing solutions, almost never setting up an entire new network.

One of my customers has three DC's (DC1, DC2, DC3).
When running nltest /dsgetdc:<DomName> /timeserv on the servers I'm getting different results. Some times pointing to DC1, some times DC3.

W32tm /query /source also gives varying results, some looking to free running clock, some to a DC, some to CMOS.

I've read this MS article about network time servers.

The customer's Default Domain Controller Policy (group policy) has the following settings enabled
- Configure Windows NTP Client

- Enable Windows NTP Client

- Enable Windows NTP Server

 

With the settings in place, on the Default Domain Controller Policy (which is applied to each of the DC), wouldn't it make each DC fight over who is the time server for the domain?

Thank you in advance.

1 Reply

Some general info
- All domain members should use NT5DS domain time.
- Desktops and member servers sync with any domain controller.
- Domain controllers sync with PDC emulator (one per domain)
- PDC emulator in child domain can sync with any domain controller in parent domain.
- PDC emulator in parent domain syncs with either a hardware clock or possibly an external source.
https://blogs.technet.microsoft.com/nepapfe/2013/03/01/its-simple-time-configuration-in-active-direc...