Insights /Active Directory and Group Policy

Domain sign-in fails when clocks differ by only a few minutes: how should Kerberos time synchronisation be troubleshot?

Kerberos is sensitive to clock skew. Verify the PDC Emulator time source, domain hierarchy, virtualisation time, NTP reachability, and firewall return path.

Quick answer

Kerberos is sensitive to clock skew. For this case, first verify w32tm time source and PDC Emulator role, then use client-to-domain-controller clock skew to decide whether remediation is needed.

Define the failure boundary first

For this directory and identity case, establish the failure boundary with w32tm and PDC Emulator, then continue to client-to-domain-controller clock skew. Capture the current state, incident time and one known-good comparison before changing production configuration.

Work through the dependency chain

CheckWhy it mattersRecommended action
01 · w32tm time sourceVerify w32tm time source on the affected path using logs, counters or state information rather than relying only on the configured rule.Record the current value, evidence source and timestamp for w32tm time source. If adjustment is required, change one condition only and retain the original setting for rollback.
02 · PDC Emulator roleVerify PDC Emulator role on the affected path using logs, counters or state information rather than relying only on the configured rule.Check PDC Emulator role read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation.
03 · client-to-domain-controller clock skewVerify client-to-domain-controller clock skew on the affected path using logs, counters or state information rather than relying only on the configured rule.Compare client-to-domain-controller clock skew with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production.
04 · virtualization time synchronizationReview the current state, related logs and recent changes for virtualization time synchronization, then align them with the incident timeline before deciding whether a change is required.Record the current value, evidence source and timestamp for virtualization time synchronization. If adjustment is required, change one condition only and retain the original setting for rollback.
05 · UDP 123 reachabilityReview the current state, related logs and recent changes for UDP 123 reachability, then align them with the incident timeline before deciding whether a change is required.Check UDP 123 reachability read-only and save the result. If it differs from the baseline, correlate it with the incident time and recent changes before remediation.
06 · Kerberos events and ticketsReview the current state, related logs and recent changes for Kerberos events and tickets, then align them with the incident timeline before deciding whether a change is required.Compare Kerberos events and tickets with a known-good peer, the log timeline and the real application path; confirm whether it is causal before changing production.
Read-only examples
w32tm /query /status
w32tm /query /source
w32tm /monitor

Change only after the evidence is clear

  1. Start with read-only evidence. Check w32tm time source and PDC Emulator role before changing configuration.
  2. If the first checks are normal, continue with client-to-domain-controller clock skew and virtualization time synchronization, keeping evidence tied to the incident time.
  3. Change configuration only when the evidence explains the symptom. For UDP 123 reachability, preserve the original value and define the rollback trigger before adjustment.
  4. Validate Kerberos events and tickets in a controlled scope before expanding to production users or traffic.

Validation and rollback

  • Validate the complete user or application workflow; do not stop at the single status of w32tm time source.
  • Recheck UDP 123 reachability and Kerberos events and tickets after the change and confirm that no new bypass, permission expansion or secondary error has appeared.
  • Archive evidence from w32tm time source through Kerberos events and tickets, together with before/after configuration, business validation and the rollback point.

Common wrong turns

  • Changing w32tm and PDC Emulator at the same time, which makes the original cause impossible to prove.
  • Treating a normal result for client-to-domain-controller clock skew as proof that virtualization time synchronization and the rest of the business path are healthy.
  • Leaving a temporary exception related to UDP 123 or Kerberos in production without an owner, expiry time and rollback note.

Related questions

Where should I start with “Domain sign-in fails when clocks differ by only a few minutes: how should Kerberos time synchronisation be troubleshot?”?

Start with w32tm time source and PDC Emulator role; they establish the first useful troubleshooting boundary without changing production state.

What should be checked after the first layer looks normal?

Continue with client-to-domain-controller clock skew and virtualization time synchronization, then correlate the result with the incident time and the actual user or application path.

What should be retained after the change?

Keep evidence for UDP 123 reachability and Kerberos events and tickets, plus the original configuration, validation result, observation notes and rollback point.

PreviousReplication between primary and additional domain controllers has failed: how should AD, DNS, time, and SYSVOL be checked?NextAfter a domain password change, sign-in still reports an incorrect password or the old password appears to work: what should be checked?

Need an assessment based on your actual environment?