To remotely configure time on a domain-joined workstation, the modern command-line tool is w32tm, which replaces the legacy net time command for synchronizing clocks. Use w32tm /resync /computer:<DNSNameOrIP> from an elevated command prompt to force the remote machine to immediately resynchronize its clock with the domain hierarchy.
Why use w32tm to remotely configure time on a workstation?
Windows Time service (W32Time) and its w32tm command-line tool are the preferred methods for configuring, monitoring, and troubleshooting time synchronization in modern Windows Server domains. The legacy net time command is deprecated and lacks the diagnostic and resync capabilities that w32tm provides. A manual resync fixes immediate clock drift, which is critical because Kerberos V5 authentication, the backbone of Active Directory, requires synchronized clocks; a time difference greater than 5 minutes between a workstation and a domain controller causes authentication failures. When a user suddenly cannot log in or receives "clock skew" errors, forcing a remote resync with w32tm is the fastest way to restore access without waiting for the next automatic sync cycle.
Prerequisites for remote time synchronization
Before running any w32tm command against a remote workstation, you must meet three essential requirements. First, you need membership in the Domain Admins group, local Administrator rights on your own machine are not sufficient for remote operations. Second, UDP port 123 must be open on firewalls for both outbound requests and inbound responses, because time synchronization relies entirely on this protocol. Third, understand that the domain hierarchy normally handles time automatically: all domain-joined computers sync through the domain hierarchy, with the Primary Domain Controller (PDC) emulator in the forest root domain acting as the authoritative time source. Your manual resync is a corrective action, not a replacement for this automatic process.
Check the current time source and configuration
Before forcing a resync, diagnose the remote workstation's current time state. Open an elevated command prompt on your administrative machine and run the following commands to inspect the remote computer:
- Run
w32tm /query /computer:<DNSNameOrIP> /sourceto see which time source the workstation is currently using. The output should show the domain hierarchy path (e.g., the PDC emulator name) or an external NTP server if explicitly configured. - Run
w32tm /query /computer:<DNSNameOrIP> /configurationto view the full Windows Time service configuration, including the sync type, poll intervals, and whether the service is running.
These two queries tell you whether the workstation is pointed at the correct source and whether the service is healthy.
Force a remote time resync with w32tm
Once you have confirmed the configuration, force the remote workstation to resynchronize its clock immediately. From an elevated command prompt on your administrative machine, run the following command:
- Execute
w32tm /resync /computer:<DNSNameOrIP>, replacing<DNSNameOrIP>with the actual DNS name or IP address of the target workstation. - Wait for the command to complete. The output will confirm whether the resync was successful or report an error code.
- If the resync fails, check the workstation name or IP address for typos, and verify that the target machine is reachable on the network.
This command instructs the remote Windows Time service to immediately contact its configured time source and update the local clock. The resync is a one-time corrective action; it does not change the workstation's ongoing sync policy.
Verify the updated time on the remote workstation
After the resync command completes, confirm that the remote clock is now accurate. Run w32tm /query /computer:<DNSNameOrIP> /source again to verify the time source is correct, then check the actual system time on the remote workstation using w32tm /query /computer:<DNSNameOrIP> /status or simply compare the remote clock against your local machine's time. If the displayed time matches your domain's authoritative time within an acceptable range (typically under a few seconds), the resync was successful. If the time is still significantly off, the problem lies elsewhere, likely in the time source hierarchy or the PDC emulator's own external synchronization.
Troubleshooting common w32tm errors
When remote resync fails, the error message usually points to one of three specific issues. If the resync succeeds but the time is still wrong, the problem is upstream: check the PDC emulator's external NTP source by running w32tm /query /source on the PDC itself. If the PDC is not syncing with a reliable external NTP server, every workstation in the domain will inherit that inaccuracy, and no amount of remote resyncs will fix it.
Configuring persistent time settings via Group Policy
For a permanent fix rather than a one-time manual resync, use Group Policy Objects (GPOs) to centrally configure Windows Time service settings for all domain members. GPOs are the recommended method for setting NTP clients and servers, including specifying the authoritative time source, poll intervals, and sync type. By linking a GPO that configures the Windows Time service, you eliminate the need for manual remote resyncs entirely, every workstation will automatically maintain correct time through the domain hierarchy. For detailed GPO configuration steps, consult the official Microsoft documentation on Windows Time service tools and settings, which provides the specific policy paths and registry-based options for fine-tuning time synchronization across your entire domain.

















