Change w32tm source

Susan Dodds 421 Reputation points
2026-10-06T23:13:33.41+00:00

Server 2019 and Server 2025 DC's.

Decommissioning the 2019 server that is also acting as the NTP server.

In group policy, NTP client and NTP server were enabled on 2019.

I turned off NTP server on 2019.

I turned on NTP client/server on 2025.

Connected computers still see 2019 as the source and no other peers.

Even 2025 was seeing 2019 as the w32tm source and then switched to local CMOS time after a net stop/start w32time.

Did a net stop, unregister/register, net start, resync for it to go back to 2019 as the source on 2025 itself.

What setting do I need to do to force them to switch to 2025? 2019 is still on the network for the time being.

Thanks

Edit: got 2025 to finally use NTP as a source but connected workstations still on 2019.

Windows for business | Windows Server | Directory services | Deploy group policy objects
0 comments No comments

2 answers

Sort by: Most helpful
  1. Domic Vo 34,410 Reputation points Independent Advisor
    2026-10-07T00:17:09.9333333+00:00

    Hello,

    The key point is that domain-joined workstations normally follow the AD time hierarchy (NT5DS), not whichever DC has NTP Server enabled. The PDC Emulator should be the authoritative time source.

    First confirm the FSMO role:

    netdom query fsmo
    

    If the 2019 DC still owns the PDC Emulator, transfer that role to the 2025 DC. On 2025, configure the authoritative NTP source:

    w32tm /config /manualpeerlist:"<NTP-server>,0x8" /syncfromflags:manual /reliable:yes /update
    net stop w32time
    net start w32time
    w32tm /resync /rediscover
    

    Then verify:

    w32tm /query /source
    w32tm /query /status
    

    For workstations, make sure they are using NT5DS. If they were manually configured to use 2019, reset them with:

    w32tm /config /syncfromflags:domhier /update
    net stop w32time
    net start w32time
    w32tm /resync /rediscover
    

    If 2025 already owns the PDC Emulator but clients still select 2019, check the applied GPO and w32tm /query /configuration on an affected workstation; a manual NTP configuration is likely overriding the domain hierarchy.

    I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!

    Domic Vo.

    Was this answer helpful?


  2. AI answer

    2026-10-06T23:13:51.34+00:00

    For domain-joined computers, the key setting is to make clients sync from the Active Directory domain hierarchy, not from a manually configured peer.

    Use this on affected clients to force them back to the domain hierarchy:

    w32tm /config /syncfromflags:domhier /update
    net stop w32time
    net start w32time
    

    Then verify the effective configuration:

    w32tm /query /configuration
    w32tm /query /source
    

    Important points for this scenario:

    1. If Configure Windows NTP Client GPO sets NtpServer, that policy overrides the NtpServer registry value for domain members. In that case, changing the registry alone will not move clients.
    2. In Group Policy, review Computer Configuration > Administrative Templates > System > Windows Time Service > Time Providers > Configure Windows NTP Client.
      • For domain-joined computers, the documented default Type is NT5DS.
      • NtpServer is used for manually specified time sources.
    3. If a GPO was previously targeting the 2019 DC as a manual peer, remove that manual peer configuration or change clients back to domain hierarchy sync.
    4. If the 2025 DC is intended to serve NTP requests, ensure Enable Windows NTP Server is enabled on that server.
    5. If the 2025 DC is now the authoritative/root time source, configure it as a reliable time server and point it to the external NTP source.

    If Group Policy is being used for the PDC emulator only, make sure the policy is scoped only to the machine holding the PDC Emulator role. The documented approach is to remove Authenticated Users, add the PDC Emulator machine account, and link the GPO to the Domain Controllers OU.

    Risk note: changing W32Time by registry or GPO can affect authentication and domain operations if time becomes inconsistent. Apply the change first to the server that should own the authoritative time role, then refresh clients.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.