The domain controller holding the PDCe FSMO role in the forest root domain is the authoritative source for time in an Active Directory domain in the default time synchronization hierarchy.
Configuring the Primary Domain Controller emulator to synchronize time with a reliable source
Getting ready
Before a Windows Server installation can synchronize time, the Network Time Protocol (NTP) should be available. By default, NTP is allowed toward domain controllers through their Windows Firewalls. However, NTP traffic toward the internet might not be available.
When an organization has deployed a reliable time source within the network, with, for instance, a GPS-enabled network time appliance, than the IP address or the hostname...