For domain-joined computers, the key setting is to make clients sync from the Active Directory domain hierarchy, not from a manually configured peer.
Use this on affected clients to force them back to the domain hierarchy:
w32tm /config /syncfromflags:domhier /update
net stop w32time
net start w32time
Then verify the effective configuration:
w32tm /query /configuration
w32tm /query /source
Important points for this scenario:
- If Configure Windows NTP Client GPO sets NtpServer, that policy overrides the
NtpServerregistry value for domain members. In that case, changing the registry alone will not move clients. - In Group Policy, review Computer Configuration > Administrative Templates > System > Windows Time Service > Time Providers > Configure Windows NTP Client.
- For domain-joined computers, the documented default Type is NT5DS.
- NtpServer is used for manually specified time sources.
- If a GPO was previously targeting the 2019 DC as a manual peer, remove that manual peer configuration or change clients back to domain hierarchy sync.
- If the 2025 DC is intended to serve NTP requests, ensure Enable Windows NTP Server is enabled on that server.
- If the 2025 DC is now the authoritative/root time source, configure it as a reliable time server and point it to the external NTP source.
If Group Policy is being used for the PDC emulator only, make sure the policy is scoped only to the machine holding the PDC Emulator role. The documented approach is to remove Authenticated Users, add the PDC Emulator machine account, and link the GPO to the Domain Controllers OU.
Risk note: changing W32Time by registry or GPO can affect authentication and domain operations if time becomes inconsistent. Apply the change first to the server that should own the authoritative time role, then refresh clients.