Monitoring Benefit
The AD Time monitoring test presents the status of the Time setting for each DC or RODC.
How do we verify the results received on the ENow client?
The ENow client is programmatically checking the registry to gather the Windows Time information. Note that this information is not logged, but the results are stored on the monitored domain controller in the following folder location:
\Program Files (x86)\ENow\Mailscape Agent\Cache\NetworkAgentMessage.xml
To capture the same information from the DC or RODC manually, read the registry values the client reads. Either open regedit and browse to the key below, or run the PowerShell command that follows.
Registry: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\Parameters
Look at Type and NtpServer.
Get-ItemProperty -Path 'HKLM:\SYSTEM\CurrentControlSet\Services\W32Time\Parameters' |
Select-Object Type, NtpServer
To see the domain controller's current time source and how far it has drifted, run:
w32tm /query /status
w32tm /query /source
Kerberos rejects authentication once clock skew exceeds the domain's maximum tolerance, which is five minutes by default, so a drift approaching that figure is worth acting on immediately rather than at the next maintenance window.
Comments
0 comments
Article is closed for comments.