Create Windows Time Service Configuration Policy

Admins can create a Time Service Configuration policy to configure Network Time Protocol (NTP) servers, polling intervals, and additional time synchronization settings on their Windows devices enrolled in JumpCloud MDM. You can apply this configuration to both individual devices and devices groups.

To create a Windows Time Synchronisation policy:

  1. Log in to the JumpCloud Admin Portal.
  2. Go to DEVICE MANAGEMENT > Policy Management.
  3. In the All tab, click (+).
  4. On the New Policy panel, select the Windows tab.
  5. Select Windows Time Service Configuration from the list, then click configure.
  6. (Optional) In the Policy Name field, enter a new name for the policy or keep the default. Policy names must be unique.
  7. (Optional) In the Policy Notes field, enter details like when you created the policy, where you tested it, and where you deployed it.
  8. In the Settings section, select the Enable Windows NTP Client checkbox.
  9. Select the Configure Windows NTP Client checkbox to configure the required details.

Note:

For more information about individual fields, see Microsoft’s Policy CSP - ADMX_W32Time documentation.

  1. Enter the name or IP address of the NTP time source in the NTP Server field.

Note:
  • The default value time.windows.com,0x09 is pre-populated.
  • You can specify the NTP servers that you want your devices to synchronise the time with, each separated by a comma.
  1. In the Type field, select the type of authentication that W32time uses. NT5DS is selected by default.
  2. In the Cross Site Sync Flags dropdown, select the time sources that Windows Time will use from outside its local site.

Note:
  • The default value of 2 is selected by default.
    • 0 - Time synchronisation will not be attempted outside of the local site.
    • 1 - Only computers acting as Primary Domain Controller (PDC) emulators in other domains can be used as time sync partners outside the local site.
    • 2 - Any synchronization partner can be used.
  1. In the Resolve Peer Back off (in minutes) field, specify how long Windows Time should wait before retrying to resolve the time server address after a failed attempt. This is set to 15 mins by default.
  2. In the Resolve Peer Back off (attempts) field, specify how many times Windows Time will retry resolving the time server address after a failure. After reaching the limit, it stops attempting to contact the server. This is set to 7 times by default.
  3. In the Special Poll Interval (in seconds) field, specify how often the system will synchronize its time with a configured NTP server when using a manual time source. This is set to 1024 seconds by default.
  4. In the Event Log Flags, the value 3 is selected by default.
  1. Select the Enable Windows NTP Server checkbox.
  2. (Optional) Select the Device Groups tab. Select one or more device groups where you want to apply this policy. For device groups with multiple OS member types, the policy is applied only to the supported OS.
  3. (Optional) Select the Devices tab. Select one or more devices where you want to apply this policy.
  4. Click Save. If prompted, click Save again. No further action is needed for this policy to take effect. 
Back to Top

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case