Skip to content

Diagnose Windows Time Synchronization with w32tm

Time skew can break Kerberos authentication, certificate validation, log correlation, and scheduled jobs. Use w32tm to inspect the configured source and synchronization status before changing settings.

Domain-joined computers normally follow the Active Directory time hierarchy. Do not point a domain member or domain controller at an unrelated public time source without following your domain time design. Run configuration changes only with authorization and a rollback plan.


Step 1: Check the Current Source and Status

01

Inspect Synchronization State and Configuration

Baseline

Run these commands in an elevated Command Prompt. Review the last successful sync, current source, stratum, and the configured sync mode. Record whether the device is domain-joined before interpreting the source.

Terminal window
w32tm /query /status
w32tm /query /source
w32tm /query /configuration
❯ View Expected Console Output
Leap Indicator: 0 (no warning)
Stratum: 3
Source: dc01.corp.contoso.com
Last Successful Sync Time: 10/4/2026 10:25:00 AM
Windows 11 Date and time Settings showing automatic time and the configured time zone

Figure 1: Check the Windows date, time, and time-zone settings.


Step 2: Check Peer Reachability and Offset

02

Compare with the Intended Time Peer

Peer Test

Query configured peers and measure a short strip chart against the intended peer. A peer that is absent or unreachable may point to DNS, routing, firewall, or service configuration. UDP port 123 must be permitted along the path for NTP traffic.

Terminal window
w32tm /query /peers
w32tm /stripchart /computer:dc01.corp.contoso.com /dataonly /samples:5
❯ View Expected Console Output
Tracking dc01.corp.contoso.com [10.20.30.10:123].
10:30:01, +00.0012345s
10:30:03, +00.0011980s
Windows Terminal Command Prompt showing w32tm status, source, and stripchart output for the domain time peer

Figure 2: Use w32tm to inspect synchronization state and peer offset.


Step 3: Request a Normal Resynchronization

03

Resync After Confirming the Correct Source

Recovery

If the device is configured to use the correct time hierarchy and the peer is reachable, request a resynchronization. This does not set a new peer; it asks Windows Time to sync from its current configured source. If it reports that no time data is available, return to peer and firewall checks rather than repeatedly forcing the command.

Terminal window
w32tm /resync
w32tm /query /status
❯ View Expected Console Output
The command completed successfully.
The Last Successful Sync Time is updated.

Step 4: Check the Windows Time Event Log

04

Correlate Failures with Service Events

Evidence

Review recent Windows Time Service events around the failed synchronization. Correlate timestamps with DNS, firewall, and domain-controller events before changing the provider or peer list.

Terminal window
Get-WinEvent -FilterHashtable @{
LogName = 'System'
ProviderName = 'Microsoft-Windows-Time-Service'
StartTime = (Get-Date).AddHours(-24)
} | Select-Object TimeCreated, Id, LevelDisplayName, Message -First 20
❯ View Expected Console Output
TimeCreated Id LevelDisplayName Message
----------- -- ---------------- -------
... ... Information Time service synchronized...
Windows Event Viewer System log showing Time-Service event 35 for synchronization with the domain time source

Figure 3: Correlate Time-Service events with the synchronization check.

See Microsoft’s w32tm tools and settings for command details.

Comments