TL;DR: Kerberos clock skew: “There is a time and/or date difference between the client and server” (KRB_AP_ERR_SKEW)
The fix only. No explanation, no diagnosis. Read the full article if any of this does not match what you are seeing.
- Open an elevated Command Prompt on the affected PC. Check the time zone and date are right first. A wrong time zone looks like a wrong clock.
- Measure how far off it is, and see where it gets its time from.
w32tm /stripchart /computer:<domain controller name> /samples:5 /dataonly
w32tm /query /source
w32tm /query /status- Make the PC re-find its time source and resync.
w32tm /resync /rediscover- If the PC was set to a manual time server and should follow the domain, put it back on the domain hierarchy.
w32tm /config /syncfromflags:domhier /update
net stop w32time
net start w32time
w32tm /resync /rediscover- If many machines are wrong, the problem is above them. Find the PDC emulator and check where it gets its time.
nltest /dsgetdc:<domain name> /pdc
w32tm /monitor /domain:<domain name>- On the forest root PDC emulator only, point it at an external time source.
w32tm /config /syncfromflags:manual /manualpeerlist:"<time server 1>,0x8 <time server 2>,0x8 <time server 3>,0x8" /reliable:yes /update
w32tm /resync /rediscover- For a virtual machine, make sure the hypervisor is not feeding it a different time (see the article).
Do not set the clock by hand on a domain controller or PDC emulator. It drifts back, and time jumps on a DC can cause replication trouble.
Do not run w32tm /unregister as a routine fix. It deletes the Windows Time configuration.