ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Computers not syncing with Domain Controller. Is my GPO blocking it?

    IT Discussion
    time ntp
    4
    10
    1.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • CCWTechC
      CCWTech
      last edited by

      Computers in a domain are not syncing time with the Domain Controller (Hyper-V). They are all set to the local CMOS clock.

      I had to restrict the ability for local users to change time by themselves. Is the GP that I created preventing the computers from syncing to the domain?

      0_1538061340847_1.png
      0_1538061350915_2.png

      dbeatoD KellyK 2 Replies Last reply Reply Quote 1
      • momurdaM
        momurda
        last edited by

        Dont you need to be an administrator to change the time? Here i get a uac prompt if i try to change.

        Did the computers sync correctly before this change?

        CCWTechC 1 Reply Last reply Reply Quote 1
        • dbeatoD
          dbeato @CCWTech
          last edited by

          @ccwtech said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

          Computers in a domain are not syncing time with the Domain Controller (Hyper-V). They are all set to the local CMOS clock.

          I had to restrict the ability for local users to change time by themselves. Is the GP that I created preventing the computers from syncing to the domain?

          0_1538061340847_1.png
          0_1538061350915_2.png

          The time can be in different zones and not affect connectivity to the domain as long as it is 5 minutes from the DC time via UTC. Now I would really make the computers to just point to the DC as their NTP Server instead of anything else.

          CCWTechC 1 Reply Last reply Reply Quote 1
          • CCWTechC
            CCWTech @momurda
            last edited by

            @momurda said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

            Dont you need to be an administrator to change the time? Here i get a uac prompt if i try to change.

            Did the computers sync correctly before this change?

            No, even a local admin can't change the time. I don't know when it started, the GPO has been in place for a long time and I am just now hearing about the issue, so when it started is unclear.

            1 Reply Last reply Reply Quote 0
            • CCWTechC
              CCWTech @dbeato
              last edited by

              @dbeato said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

              @ccwtech said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

              Computers in a domain are not syncing time with the Domain Controller (Hyper-V). They are all set to the local CMOS clock.

              I had to restrict the ability for local users to change time by themselves. Is the GP that I created preventing the computers from syncing to the domain?

              0_1538061340847_1.png
              0_1538061350915_2.png

              The time can be in different zones and not affect connectivity to the domain as long as it is 5 minutes from the DC time via UTC. Now I would really make the computers to just point to the DC as their NTP Server instead of anything else.

              I thought they did by default in a domain.

              dbeatoD 1 Reply Last reply Reply Quote 0
              • KellyK
                Kelly @CCWTech
                last edited by

                @ccwtech said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                Computers in a domain are not syncing time with the Domain Controller (Hyper-V). They are all set to the local CMOS clock.

                I had to restrict the ability for local users to change time by themselves. Is the GP that I created preventing the computers from syncing to the domain?

                How have you confirmed that the ntp server is not the DC?

                CCWTechC 1 Reply Last reply Reply Quote 0
                • dbeatoD
                  dbeato @CCWTech
                  last edited by

                  @ccwtech said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                  @dbeato said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                  @ccwtech said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                  Computers in a domain are not syncing time with the Domain Controller (Hyper-V). They are all set to the local CMOS clock.

                  I had to restrict the ability for local users to change time by themselves. Is the GP that I created preventing the computers from syncing to the domain?

                  0_1538061340847_1.png
                  0_1538061350915_2.png

                  The time can be in different zones and not affect connectivity to the domain as long as it is 5 minutes from the DC time via UTC. Now I would really make the computers to just point to the DC as their NTP Server instead of anything else.

                  I thought they did by default in a domain.

                  They should but it is not enforced.

                  CCWTechC 1 Reply Last reply Reply Quote 0
                  • CCWTechC
                    CCWTech @dbeato
                    last edited by

                    @dbeato said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                    @ccwtech said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                    @dbeato said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                    @ccwtech said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                    Computers in a domain are not syncing time with the Domain Controller (Hyper-V). They are all set to the local CMOS clock.

                    I had to restrict the ability for local users to change time by themselves. Is the GP that I created preventing the computers from syncing to the domain?

                    0_1538061340847_1.png
                    0_1538061350915_2.png

                    The time can be in different zones and not affect connectivity to the domain as long as it is 5 minutes from the DC time via UTC. Now I would really make the computers to just point to the DC as their NTP Server instead of anything else.

                    I thought they did by default in a domain.

                    They should but it is not enforced.

                    What do I need to do to enforce it? Or point them to the DC to use?

                    dbeatoD 1 Reply Last reply Reply Quote 0
                    • CCWTechC
                      CCWTech @Kelly
                      last edited by

                      @kelly said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                      @ccwtech said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                      Computers in a domain are not syncing time with the Domain Controller (Hyper-V). They are all set to the local CMOS clock.

                      I had to restrict the ability for local users to change time by themselves. Is the GP that I created preventing the computers from syncing to the domain?

                      How have you confirmed that the ntp server is not the DC?

                      Looks like they are just using the local CMOS Clock.

                      1 Reply Last reply Reply Quote 0
                      • dbeatoD
                        dbeato @CCWTech
                        last edited by

                        @ccwtech said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                        @dbeato said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                        @ccwtech said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                        @dbeato said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                        @ccwtech said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                        Computers in a domain are not syncing time with the Domain Controller (Hyper-V). They are all set to the local CMOS clock.

                        I had to restrict the ability for local users to change time by themselves. Is the GP that I created preventing the computers from syncing to the domain?

                        0_1538061340847_1.png
                        0_1538061350915_2.png

                        The time can be in different zones and not affect connectivity to the domain as long as it is 5 minutes from the DC time via UTC. Now I would really make the computers to just point to the DC as their NTP Server instead of anything else.

                        I thought they did by default in a domain.

                        They should but it is not enforced.

                        What do I need to do to enforce it? Or point them to the DC to use?

                        @ccwtech said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                        @dbeato said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                        @ccwtech said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                        @dbeato said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                        @ccwtech said in Computers not syncing with Domain Controller. Is my GPO blocking it?:

                        Computers in a domain are not syncing time with the Domain Controller (Hyper-V). They are all set to the local CMOS clock.

                        I had to restrict the ability for local users to change time by themselves. Is the GP that I created preventing the computers from syncing to the domain?

                        0_1538061340847_1.png
                        0_1538061350915_2.png

                        The time can be in different zones and not affect connectivity to the domain as long as it is 5 minutes from the DC time via UTC. Now I would really make the computers to just point to the DC as their NTP Server instead of anything else.

                        I thought they did by default in a domain.

                        They should but it is not enforced.

                        What do I need to do to enforce it? Or point them to the DC to use?

                        Enforce the time source on the DC
                        https://blogs.technet.microsoft.com/nepapfe/2013/03/01/its-simple-time-configuration-in-active-directory/

                        For clients look at this one
                        https://www.altaro.com/hyper-v/configuring-time-synchronization-for-all-computers-in-windows-domain/

                        1 Reply Last reply Reply Quote 3
                        • 1 / 1
                        • First post
                          Last post