Diagnose Windows Time Synchronization with w32tm
Time skew can break Kerberos authentication, certificate validation, log correlation, and scheduled jobs. Use w32tm to inspect the configured source and synchronization status before changing settings.
Domain-joined computers normally follow the Active Directory time hierarchy. Do not point a domain member or domain controller at an unrelated public time source without following your domain time design. Run configuration changes only with authorization and a rollback plan.
Step 1: Check the Current Source and Status
Inspect Synchronization State and Configuration
BaselineRun these commands in an elevated Command Prompt. Review the last successful sync, current source, stratum, and the configured sync mode. Record whether the device is domain-joined before interpreting the source.
w32tm /query /statusw32tm /query /sourcew32tm /query /configuration❯ View Expected Console Output
Leap Indicator: 0 (no warning)Stratum: 3Source: dc01.corp.contoso.comLast Successful Sync Time: 10/4/2026 10:25:00 AM
Figure 1: Check the Windows date, time, and time-zone settings.
Step 2: Check Peer Reachability and Offset
Compare with the Intended Time Peer
Peer TestQuery configured peers and measure a short strip chart against the intended peer. A peer that is absent or unreachable may point to DNS, routing, firewall, or service configuration. UDP port 123 must be permitted along the path for NTP traffic.
w32tm /query /peersw32tm /stripchart /computer:dc01.corp.contoso.com /dataonly /samples:5❯ View Expected Console Output
Tracking dc01.corp.contoso.com [10.20.30.10:123].10:30:01, +00.0012345s10:30:03, +00.0011980s
Figure 2: Use w32tm to inspect synchronization state and peer offset.
Step 3: Request a Normal Resynchronization
Resync After Confirming the Correct Source
RecoveryIf the device is configured to use the correct time hierarchy and the peer is reachable, request a resynchronization. This does not set a new peer; it asks Windows Time to sync from its current configured source. If it reports that no time data is available, return to peer and firewall checks rather than repeatedly forcing the command.
w32tm /resyncw32tm /query /status❯ View Expected Console Output
The command completed successfully.The Last Successful Sync Time is updated.Step 4: Check the Windows Time Event Log
Correlate Failures with Service Events
EvidenceReview recent Windows Time Service events around the failed synchronization. Correlate timestamps with DNS, firewall, and domain-controller events before changing the provider or peer list.
Get-WinEvent -FilterHashtable @{ LogName = 'System' ProviderName = 'Microsoft-Windows-Time-Service' StartTime = (Get-Date).AddHours(-24)} | Select-Object TimeCreated, Id, LevelDisplayName, Message -First 20❯ View Expected Console Output
TimeCreated Id LevelDisplayName Message----------- -- ---------------- -------... ... Information Time service synchronized...
Figure 3: Correlate Time-Service events with the synchronization check.
See Microsoft’s w32tm tools and settings for command details.