Synchronize the Domain Controllers Time Service with the PDC
Hi All,
I'm having problems with time synchronization between DC and PDC.
PDC is configured with external time sources.
I want to be sure that DC gets time from the PDC, but every time I run a "w32tm /query /source" I see a different time source, rather than the PDC.
I used:
net stop w32time
w32tm /unregister
w32tm /register
net start w32time
w32tm /config /syncfromflags:domhier /update
net stop w32time
net start w32time
but still I see the old time source or "local clock..."
How can I force the tie synchronization between DCs and PDC?
Thanks
Hi,
Do you have any progresses by now?
If the present PDC emulator role was transferred, then there are extra steps that need to be done, please refer to this article below:
Time Service Configuration on DC with PDC Emulator FSMO Role
http://social.technet.microsoft.com/wiki/contents/articles/8863.time-service-configuration-on-dc-with-pdc-emulator-fsmo-role.aspx
Best Regards,
Amy Wang
Similar Messages
-
Domain Controller - Time Syncing with CMOS Clock
Hello!
We have a DC that is syncing time from "local CMOS clock." This DC is a VM (hyper V). Integration services has "time sync" turned off.
I've attempted syncing the DC to an external time source per http://www.thirdtier.net/2011/02/how-to-set-an-ntp-time-server-in-windows-2008-sbs-2008-and-sbs-2011/ and the issue persists.
Also of note - I've attempted syncing the VMHOST to an external source as well, and it is only syncing with CMOS clock
w32tm /config /manualpeerlist:"time.windows.com" /syncfromflags:manual /reliable:yes /update
- results>
I manually restarted Windows Time service, still syncing to CMOS
w32tm /resync /rediscover
- results>
the computer did not resync because no time data was available
w32tm /stripchart /computer:time.windows.com /samples:5 /dataonly
- results>
Tracking time.windows.com [65.55.56.206:123].
Collecting 5 samples.
The current time is 4/14/2014 12:34:41 PM.
12:34:41, -16.0686354s
12:34:43, error: 0x800705B4
12:34:46, -16.0885249s
12:34:48, -16.0981303s
12:34:50, -16.0785199s
w32tm /monitor
- results>
EVEREST.COMPANYNAME.local[192.168.45.34:123]:
ICMP: 0ms delay
NTP: +17.4000482s offset from COMPANYNAME-DC1.COMPANYNAME.local
RefID: 'LOCL' [0x4C434F4C]
Stratum: 1
COMPANYNAME-DC1.COMPANYNAME.local *** PDC ***[192.168.45.31:123]:
ICMP: 0ms delay
NTP: +0.0000000s offset from COMPANYNAME-DC1.COMPANYNAME.local
RefID: 'LOCL' [0x4C434F4C]
Stratum: 1
COMPANYNAME-MGMT.COMPANYNAME.local[192.168.45.33:123]:
ICMP: error IP_REQ_TIMED_OUT - no response in 1000ms
NTP: error ERROR_TIMEOUT - no response from server in 1000ms
COMPANYNAME-DS1.COMPANYNAME.local[192.168.45.32:123]:
ICMP: 0ms delay
NTP: +14.7149589s offset from COMPANYNAME-DC1.COMPANYNAME.local
RefID: 80.84.77.86.rev.sfr.net [86.77.84.80]
Stratum: 2
EVEREST.COMPANYNAME.local = 2k3 box
COMPANYNAME-MGMT.COMPANYNAME.local = old DC improperly removed from domain (aka was just deleted from Hyper V by another technician...)
COMPANYNAME-DC1.COMPANYNAME.local = primary "main" DC, 2k8
COMPANYNAME-DS1.COMPANYNAME.local = backup DC, 2k8
I can provide whatever other info that may prove useful. I've looked @ other posts RE: this issue and feel like I might be missing something obvious, but I am at a loss.
Thank you!Hi,
Is UDP 123 open on the machine? I suggest you try to disable firewall to see if it works.
More information for you:
Can't get NTP time working on SErver 2008 R2 DC
http://social.technet.microsoft.com/Forums/windowsserver/en-US/e5e26e4f-1988-4ec1-8837-6d1d503130e7/cant-get-ntp-time-working-on-server-2008-r2-dc?forum=windowsserver2008r2general
Configuring the Windows Time Service for Windows Server
http://msmvps.com/blogs/acefekay/archive/2009/09/18/configuring-the-windows-time-service-for-windows-server.aspx
Error message when you run the "w32tm /resync" command to synchronize Windows Server 2003 or Windows SBS to an external time source: "The computer did not resync because no time data
was available"
http://support.microsoft.com/kb/929276
Time synchronization is not performed even though the W32Time service is successfully started in Windows Server 2008 or in Windows Server 2008 R2
http://support.microsoft.com/kb/2493006
Best Regards,
Amy -
WebLogic Timer services.
WebLogic has deprecated Timer services with version 6.1 and recommend using Flux.
What is the rationale behind that? What do other scheduling services offer over the
standard JDK java.util.Timer class where I can kick of scheduled tasks?
Thanks ahead of time for your response.
Regards,
Amit.... but if done from startup, a timer is not in an app and thus can't see
the app's environment?
Cameron Purdy
Tangosol, Inc.
http://www.tangosol.com
+1.617.623.5782
WebLogic Consulting Available
"Rob Woollen" <[email protected]> wrote in message
news:[email protected]..
Yes, that should work fine. What is the error?
-- Rob
Satish Yellanki wrote:
Hi,
I am trying to use the weblogic timer services.
I implemented the TriggerDef interface and deployed
the trigger using "Scheduler" and "Trigger" classes.
(Server-side triggers.)
However, when the trigger is run, will I be able to
do a InitialContext() without any parameters and use
it to do JNDI lookup? I am running into an error doing
that and am not sure if I am doing the right thing.
Thanks,
Satish--
Coming Soon: Building J2EE Applications & BEA WebLogic Server
by Michael Girdley, Rob Woollen, and Sandra Emerson
http://learnweblogic.com -
In Windows Server Essentials 2012 R2, all of our online services integration features, including Azure Active Directory and Office 365, are supported only in environments that
have a single domain controller. In environments with more than one domain controller, integration of these services is blocked due limitations in the user account and password synchronization mechanism in Windows Server Essentials.
I am happy to announce that with the recent Windows August Update released on (8/12/2014, PST), this limitation has been removed. This update adds support for both Azure
Active Directory integration and Office 365 integration features in domain environments consisting of a single domain controller, multiple domain controllers, or Windows Server Essentials as a domain member server.
For more information, please go to
http://support.microsoft.com/kb/2974308Hi JoeBeck,
Thanks for the comment. Could you please tell which link you clicked to download?
Please go to PinPoint check details and start download
http://pinpoint.microsoft.com/en-US/applications/Dynamics-CRM-Online-Add-in-12884966386
Thanks,
Shanghai Wicresoft -
Hi,
We are receiving several eventids '26007' from the OpsMgr log on our Domain Controllers, also eventids '26008' with similar description are logged
The EventLog service reported that the Security event log on computer '<Domain Controller Computer>' is corrupt. The Windows Event Log Provider will attempt to recover by re-opening log.
I'll appreciate any suggestion in order to solve this issue.
Regards.I guess this issue is caused by event ID 4661 is corrupted in security event log.
Please check if you have many 4661 events in security event log and XML view cannot be viewed.
Running the below command on DC will disable the auditing of the SAM Object access. This should stop the Event ID 4661 from being logged which should stop the Alert regarding corrupt Event log:
auditpol /set /subcategory:"SAM" /success:disable /failure:disable
Regards, -
I have the iphone 4 and PC with Windows Vista Basic. When I bought my iPhone syncs with iTunes on my computer, but now when I try to sync it tells me that Mobile Device Service was closed and I can not synchronize the phone. Try restarting Mobile Device Service and uninstall and reinstall Itunes but still giving me the same error.
http://support.apple.com/kb/HT3965
-
How to synchronize the FieldPoint time with my computer time?
When I using MAX to read the values from my FieldPoint cFP-1804 module, there is and timestamp generated for every measurement, but it does not match my PC's system time. How to synchronize the FieldPoint time with my windows PC?
I found a thread on the forum regarding this problem (http://digital.ni.com/public.nsf/allkb/C4E56AD6450FC5FD86256DFF0007FF01), it ask me to select the Time Zone on the System Setting tab, but I didn't find any System Setting tab and Time Zone setting in my MAX screen. (MAX version4.4)
I'm using the cFP-1804 without embedded CPU module, I'm using asp.net, measurement studio to link with the cFP-1804, not by using Labview. Does cFP-1804 have a Time Server function? Please tell me how to match the FieldPoint time with my PC.
ThanksHi Presario2100,
In order to obtain an updated timestamp with each FieldPoint Read, you should
use a Flat Sequence structure. In the same frame as the
FieldPoint Read, use a Get Date/Time In
Seconds node.
The program obtains a fresh Timestamp each time the FieldPoint Read VI is
called.
I hope this helps.
Message Edited by Pie56694 on 08-15-2008 05:58 PM
Attachments:
TSUpdates.jpg 38 KB
FlatSequence.jpg 54 KB -
Hi Folks,
I'd like to know what's the best way to edit the Exchange Server 2007 entry
In-Site entries and removing the entries from Out-Of-Site safely without causing any downtime or problem with the workstations ?
From the MSExchange ADAccess Event ID 2080, I can see that the Domain Controllers that is currently used by Exchange Servers is all on the
In-Site lists which I need to decommission due to office building migration and downsizing, the workstations remain in the same building only the servers must go.
Current configuration:
Exchange Servers AD Site: HQ1 (for all roles)
Workstations AD Site: HQ1
Proposed configuration:
Exchange Servers AD Site: Prod-DC1 (for all roles)
Workstations AD Site: HQ1
Thanks.
/* Server Support Specialist */Hi,
Steve's clarification is right.
From your description, you want to change the DC used by Exchange server. If I have misunderstood your concern, please let me know.
Please make sure the following things before setting the DC for Exchange:
1. New DC has its own IP in its TCP/IP as primary DNS server.
2. New DC is global catalog.
3. New DC has correct DNS settings in the MSDC folder.
4. Restart the Exchange active directory topology discovery service and watch the event viewer, there should be an event that discover both domain controllers. If this happens, then turn off the old DC.
Besides, topology information will remain in the system attendant service for 15 min, so the time to switch to the new one is about 15 minutes.
Hope my clarification is helpful.
Best regards,
If you have feedback for TechNet Subscriber Support, contact
[email protected]
Amy Wang
TechNet Community Support
Amy,
The Exchange Server has been rebooted couple of times but yes, all of the In-Site AD servers are still on not rebooted yet.
So in this case do you suggest me to demote the oldDC and turn off all of the In-Site DC/GC first and then reboot Exchange Server after wards one by one ?
/* Server Support Specialist */ -
I need to find domain controllers that have been removed but never demoted.
Here's the story...
I came on an Active Directory administrator for an organization which has 600+ domain controllers, most running Server 2003, but I have some Server 2008R2. Throughout all this time the organization has had DCs that have stopped working, crashed or failed
for some reason and all the IT department has done is created another domain controller name it the same thing with an (A), (B) appended to the name and then never removed any of the failed controllers from the directory.
Thing is this has been going on for quite some time, don’t know for sure how long as I am still trying to clean up DNS replication problems and have been having to go around and reset machine passwords for the forest. What I need to be able to do is to script
something that will return all the failed DCs so that I can go into the directory and use NTDUTIL to clean the machines. I don’t want to go into the directory and remove a machine that’s still out there. No one in the organization has a list or record of failed
machines.
You can see this may be a gargantuan task, but I need to be able to make it easier on
myself by finding the machines first and cleaning out DNS, cleaning the DCs out of the “Sites” and cleaning them out of the directory.
Appreciate any help I can get…Hi,
Thanks for posting in the forum.
Regarding your question, maybe we should remove these orphaned DC from AD, please try to refer to the following articles to perform the cleanup task.
How to remove completely orphaned Domain Controller
http://support.microsoft.com/kb/555846
Complete Step by Step to Remove an Orphaned Domain controller
http://msmvps.com/blogs/acefekay/archive/2010/10/05/complete-step-by-step-to-remove-an-orphaned-domain-controller.aspx
Metadata Cleanup of a Domain controller
http://sandeshdubey.wordpress.com/2011/10/12/metadata-cleanup-of-a-domain-controller/
Here is a similar thread as reference, hope it helps.
Remove References of a Failed DC/Domain
http://social.technet.microsoft.com/Forums/windowsserver/en-US/87516188-731a-4b7f-a4cc-06ce4ad27b19/remove-references-of-a-failed-dcdomain
Best Regards,
Andy Qi
TechNet Subscriber Support
If you are
TechNet Subscription user and have any feedback on our support quality, please send your feedback
here.
Andy Qi
TechNet Community Support -
Audit/Log GPO changes and Logging of new addition of Domain Controllers in the Event Log
Hi all,
We am trying to log the following items in the event log for Windows 2012. This applies to a domain controller.
1) Audit any changes made to the Group Policy
2) Log the addition of new domain controllers added to the system.
We need the windows event log to record the above events for security purposes. Can anyone advise if this is doable? If yes what are the steps.
Thank youHi,
>>1) Audit any changes made to the Group Policy
We can enable audit for directory service object access and configure specific SACL for group policy files to do this.
Regarding how to step-to-step guide for auditing changes of group policy, the following two blogs can be referred to for more information.
Monitoring Group Policy Changes with Windows Auditing
http://blogs.msdn.com/b/ericfitz/archive/2005/08/04/447951.aspx
Auditing Group Policy changes
http://blogs.msdn.com/b/canberrapfe/archive/2012/05/02/auditing-group-policy-changes.aspx
>>2) Log the addition of new domain controllers added to the system.
Based on my knowledge, when a server is successfully promoted to be domain controller, event ID 29223 will be logged in the System log.
Regarding this point, the following thread can be referred to for more information.
Is an Event ID for a completed Domain Controller promotion logged on the PDC?
https://social.technet.microsoft.com/Forums/windowsserver/en-US/11b18816-7db0-49e2-9a65-3de0e7a9645e/is-an-event-id-for-a-completed-domain-controller-promotion-logged-on-the-pdc?forum=winserverDS
Best regards,
Frank Shen -
Fetch client IP addresses from the Netlogon.log file of all domain controllers in the domain
Hi,
The event ID 5807 is logged in the system logs of domain controllers as a result of which the IP addresses for the missing subnets are logged in Netlogon.log under %systemroot%/debug. The end goal is to fetch the IP addresses along with rest of the respective
attributes from the Netlogon.log for all the domain controllers in the domain. I have the following script however, it gives me a 0KB file despite the fact that the Netlogon.log on the DC contains ample entries from last two months.
function GetDomainControllers {
$DCs=[system.directoryservices.activedirectory.domain]::GetCurrentDomain() | ForEach-Object {$_.DomainControllers} | ForEach-Object {$_.Name}
return $DCs
function GetNetLogonFile ($server) {
$path= '\\' + $server + '\c$\windows\debug\netlogon.log'
try {$netlogon=get-content -Path $path -ErrorAction stop}
catch { "Can't open $path"}
#reverse the array's order to the end of the file
[array]::Reverse($netlogon)
$IPs=@()
foreach ($line in $netlogon) {
#split the line into pieces using a space as the delimiter
$splitline=$line.split(' ')
#Get the date stamp which is in the mm/dd format
$logdate=$splitline[0]
#split the date
$logdatesplit=($logdate.split('/'))
[int]$logmonth=$logdatesplit[0]
#last month and this month
if (($logmonth -eq $thismonth) -or ($logmonth -eq $lastmonth)) {
#only push it into an array if it matches an IP address format
if ($splitline[5] -match '\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b'){
$objuser = new-object system.object
$objuser | add-member -type NoteProperty -name IPaddress -value $splitline[5]
$objuser | add-member -type NoteProperty -name Computername -value $splitline[4]
$objuser | add-member -type NoteProperty -name Server -value $server
$objuser | add-member -type NoteProperty -name Date -value $splitline[0]
$objuser | add-member -type NoteProperty -name Time -value $splitline[1]
$IPs+=$objuser
} else {
#break out of loop if the date is not this month or last month
break
return $IPs
#Get last month's date
$thismonth=(get-date).month
$lastmonth=((get-date).addmonths(-1)).month
#get all the domain controllers
$DomainControllers=GetDomainControllers
#Get the Netlogon.log from each DC
Foreach ($DomainController in $DomainControllers) {
$IPsFromDC=GetNetLogonFile($DomainController)
$allIPs+=$IPsFromDC
$allIPs | Sort-Object -Property IPaddress -Unique | Export-Csv "E:\bin\NetlogonIPs.csv"
PLEASE HELP!!Hi jrv,
Thanks a lot for your help.
I understand you cannot keep on iterating the code for me. However, I am stuck at this error :-
ERROR : Exception calling "Parse" with "1" argument(s): "String was not recognized as a valid DateTime."
After the following code finishes executing, I get the following output :-
$csv=cat c:\windows\debug\netlogon.log |
%{'{0}|{1}' -f $_.SubString(0,14),$_.SubString(15,$_.Length-15)}|
ConvertFrom-Csv -Delimiter '|' -header time,message
time message
04/14 01:18:45
NO_CLIENT_SITE: ServerX 10.x.x.x
04/14 01:17:45
NO_CLIENT_SITE: ServerY 10.x.x.x
04/14 01:17:44
NO_CLIENT_SITE: ServerY 10.x.x.x
04/14 01:17:43
NO_CLIENT_SITE: ServerX 10.x.x.x
However, I get the above mentioned error at the following line :-
$csv|%{$_.time=[datetime]::Parse(($_.time -replace ' ','/2015 '))}
I would later want to run the query just for logs from past day.
Entire code is as follows :-
function GetDomainControllers {
$DCs=[system.directoryservices.activedirectory.domain]::GetCurrentDomain() | ForEach-Object {$_.DomainControllers} | ForEach-Object {$_.Name}
return $DCs
function GetNetLogonFile ($server) {
$path= 'C:\Test\netlogon.log'
try {$netlogon=get-content -Path $path -ErrorAction stop}
catch { "Can't open $path"}
#reverse the array's order to the end of the file
[array]::Reverse($netlogon)
foreach ($line in $netlogon) {
$csv= $netlogon | %{'{0}|{1}' -f $_.SubString(0,14),$_.SubString(15,$_.Length-15)}| ConvertFrom-Csv -Delimiter '|' -header time,message | Out-Gridview
$csv|%{$_.time=[datetime]::Parse(($_.time -replace ' ','/2015 '))}
#get all the domain controllers
$DomainControllers=GetDomainControllers
#Get the Netlogon.log from each DC
Foreach ($DomainController in $DomainControllers) {
GetNetLogonFile($DomainController)
Please help!! Any help will be highly appreciated. -
I have 2 domain controllers running 2003 server, server1 and server2. I ran dcpromo on server1 and removed AD and removed him from the domain and disconnected from network. I then added a 2012 server
with the same name and IP address server1 with no problem. Replication from sites and services work fine on both controllers.
The new 2012 server1 is GC. I transferred all FSMO roles to server1. Again no problem and replicating using sites and services. AD on server1 is populated correctly.
Now what I had intended on doing was a dcpromo to remove server2 from the domain so I can then add another 2012 server. That is when I get the: "The box indicating that this domain controller is the last controller for the domain
is unchecked. However, no other Active Directory domain controllers for that domain can be contacted.
I have DNS installed on both servers and both look good with replicating there. Strange thing is when on the 2012 server within DNS if I right click and connect to another DNS server I can add server2 just fine but from server2 adding server1 it tells me it
is not available.
Help please!Hi,
As there is server 2012 DC (SERVER1) DC is operational in a domain then "This domain controller is the last controller for the domain" should be remain unchecked when you demote SERVER2 DC.
If you are getting error "Active Directory domain controllers for that domain can be contacted" while demoting SERVER2 DC then check the DNS pointing on both as per below article, disable windows firewall on all DC, less possiblities but worth to check if both
are different site then check the ports are open on firewall.
http://abhijitw.wordpress.com/2012/03/03/best-practices-for-dns-client-settings-on-domain-controller/
http://technet.microsoft.com/en-us/library/cc766337(v=ws.10).aspx
http://social.technet.microsoft.com/wiki/contents/articles/584.active-directory-replication-over-firewalls.aspx
run “ipconfig /flushdns & ipconfig /registerdns“, restart DNS server and NETLOGON service on each DC and try to demote server2 DC.
If issue reoccurs, post dcdiag /q result.
NOTE: If initial replication was completed between both DC (new 2012 and old DC) then you may remove the server2 DC from Active Directory forcefully (DCPROMO /FORCEREMOVAL) and perform metadata cleanup.
Active Directory Metadata Cleanup
http://abhijitw.wordpress.com/2012/03/03/active-directory-metadata-cleanup/
Best regards,
Abhijit Waikar.
MCSA | MCSA:Messaging | MCITP:SA | MCC:2012
Blog: http://abhijitw.wordpress.com
Disclaimer: This posting is provided "AS IS" with no warranties or guarantees and confers no rights. -
Losing connection to the Domain Controllers at a remote site
We have a remote site with a IPsec tunnel for a site to site connection and there are about a dozen window 7 systems on site. Every 3 to 5 weeks, the systems start to lose the ability to log into the domain. Running some tests, the DNS names
keep resolving, their subnet is setup in Sites and Services to the group with the DC's and they are setup correctly for IP settings but seems like they still can't connect back to the DC's. From there, under network profiles, it says the domain network
is unauthenticated.
The only way we have found to fix this is to dis-join the computer from the domain and rejoin it.
Is there a way from the computer to force it to re-authenticate without having to do this or a better fix?Hello Technsopyder,
Do you means all the Windows 7 use the IPsec will lose connection to the Domain Controllers every 3 to 5 weeks?
Do you receive the error code 5719 and 3210? Could you please provide the whole error message?
Please check if you need to change the password before this issue as Brano Lukic mentioned.
Best regards,
Fangzhou CHEN
Fangzhou CHEN
TechNet Community Support -
Having horrible service with 4GLTE I have had 3G for several weeks (I am not the only person I know having this problem), I have reset my network settings and it did not resolve the issue. I am also unable to send SMS and text messages without them either failing or not sending at all. Is there an outage in the Cleveland, Ohio area (zip codes 44129, 44134, 44137) or anything else I can do to resolve this issue?
Not that I'm a Verizon employee, but I have experience in the field. An LTE tower will only extend up to, on a perfect day, with no elevation, 6-7 miles. On a typical day, you will be lucky at four (4) miles. The three ZIP codes you've given are all within about a 12 mile radius. That would mean that 2-3 towers are currently down at the same time, and Verizon would know about it within the hour. Being it's Cleveland, I'm sure they would receive numerous calls regarding an outage of that size.
My point is that if you're having issues in all three ZIP codes, chances are it's a phone issue. If you're handset is simply not receiving LTE, but still receiving 3G, that would signify a SIM card issue. You need to get your SIM card replaced. -
On the moment that I connect the Iphone 5 on Windows 8, it is not recognized by Itunes, but actually it appears as a usual USB cable, or as a camera. And then I can't synchronize the Iphone 5 with Itunes. So, what do i do?
Hi pedro109,
If your iPhone is recognized by the computer, but not seen by iTunes, you may need to restart the Apple Mobile Device Service, as described in this article -
How to restart the Apple Mobile Device Service (AMDS) on Windows
http://support.apple.com/kb/TS1567
Once iTunes recognizes the iPhone you should be able to sync it with iTunes. See this article
iTunes 11 for Windows: Sync contacts, calendars, and other info with iPod, iPhone, or iPad
http://support.apple.com/kb/PH12317
Thanks for using Apple Support Communities.
Best,
Brett L
Maybe you are looking for
-
4S has wifi failing erratically over last few days. Have restored, also upgraded iOS from 6.1.3 to 7. 0.4 all with no improvement. Fails after on for a few minutes. As in one support doc, wifi slider dimmed. Support actions taken and NG. support
-
Is it possible to connect Sqlfire server with oracle using DBSynchronizer using default license
is it possible to connect Sqlfire server with oracle using DBSynchronizer using default license Sql fire is my machine Oracle is another machine When i connect sqlfire with oracle using DBsynchronizer It shows the error message as Wan is not supporte
-
Is the ABAP Webdynpro CATS available in both ESS and MSS?
Hi experts, We are in the process of implementing the WDA CATS application for ESS (ECC 6 EHP5) but our scenario is actually for managers to enter in time in CATS on behalf of their employees. I can't find any information on this scenario using the W
-
HT4113 How to find passcode?
How can I find a forgotten passcode for Ipod Touch 4th Generation with IOS 6? The Ipod Touch has been reset and will only go back to passcode screen one time. After that, the Ipod only shoes IOS 6 on the screen. The Ipod will not go to a red scree
-
how to delete the lock