SETTING AUTHORITATIVE TIME SERVER ON DOMAIN CONTROLLER
Kerberos authentication in Active Directory requires time among devices in the domain to be synced. If the time on a device is more than 5 minutes different than the domain controller, Kerberos will fail all authentication request from that device. For best practice, the PDC emulator should synchronize from reliable external time source. This external source could be an Internet time server, an internal network device such a router or switch that isn’t part of a domain or a hardware time keeping device. The other domain controllers will sync its time to PDC emulator. Member servers and workstations will sync to the available domain controllers.