NtpClient Error 0x800706E1


When W32Time starts to output warning  in your system logs you may often get the following message for NtpClient Error 0x800706E1: “NtpClient was unable to set a domain peer to use as a time source because of discovery error. NtpClient will try again in 3473457 minutes and double the reattempt interval thereafter. The error was: The entry is not found. (0x800706E1)”.

As the message mentions the error occurs because the W32Time service cannot find the time source it thinks it needs:

  • If it is a client computer or member server, it should be a Domain Controller of its domain
  • It it is a stand-alone computer, by default it it an external source
  • If it is a domain controller, this should be the domain controller holding the PDC Emulator role in the top domain of the forest

Firewall / Time Difference between computers

Easy thought as usual: check your firewall rules: the NTP ans SNTP protocol operate on UDP/123. One easy way to check this from a Windows computer is:

This command will try to connect  to the remote computer and check the clock difference between that computer and yours.

If there is no NTP server out there, you’ll get an answer such as  error: 0x80070584

The delay (d) is the delay between computers and the offset is the time difference between the 2 computers

Checking the configuration

To check the configuration, you have two options:

  • looking at the registry under HKLM\System\CurrentControlSet\Services\W32Time; Two subkeys are often of interest: Parameters and Config
  • Use w32tm to display that configuration. This one has the advantage to let you know if the configuration was set up locally or using a Group Policy Object (GPO).  Result sample is:

Common mistakes

Common configuration mistakes include

    • using a comma separated list for the NTP Server list whereas the separator is the space. The comma is used to indicate flags if any. Even Microsoft based websites have issues with that but this page is right. So typically you would have for a standalone:

      You can even update a configuration remotely by using
    • Using anything else than synchronization to domain controllers for domain-joined machines. The following command will help you reset the flag Type to NT5DS
    • Synchronizing all Domain Controllers to an external NTP Source. All Domain controllers but the PDC emulator in the top domain must also have the NT5DS type as for a domain-joined machine
    • However, you’d better not set the  current PDC regitry entry to NTP. Since your PDC emulator server may change over time, you must have a strategy to have the entry set to NTP whenever the server is holding the PDC emulator role and revert back to NT5DS when it is no longer a PDC.
      To accommodate the floating FSMO issue, the trick is to:

    • For non-PDC DC servers, you would think to create another GPO to apply the NT5DS setting. This is cumbersome and highly risky. Instead remember that a GPO reverts the setting back to its previous value when it is no longer applied. Therefore, make sure every DC has the correct setting NT5DS when it is not holding the PDC role and you’re fine (You may still have to transfer the role once for the current PDC holder to be set up correctly)

If this section doesn’t soilve your issue you have to dive into the logs

Enabling the debug log

To enable the debug log you can once again use of the two following methods:

  • registry as described in article KB 816043.
  • running the w32tm command. Contrary to other w32tm commands you cannot use the computer parameter and therefore you must run this command locally (Or use powershell remote sessions, etc.)

To disable the debug log, you can issue

Searching for 0x800706E1 error

Once the logs are enabled, you may run into several different cases:

  • you see LDAP connections attempts to check the nearest Domain Controller and they fail. The scenario has been described here altogether with its solution
  • another alternative is you don’t even see LDAP Requests. In this case the log loooks like

    You may then want to check the AnnounceFlags registry settings. It should be 5 on a PDC but 10 on any other machine.

 

Leave a comment

Your email address will not be published. Required fields are marked *