A reliable time source within an Active Directory environment (or networks in general) is critical.
A prefer an expensive GPS Clock; others don’t care… I decided a while ago that I sync my DCs with an NTP source.
Please keep in Mind, that your servers need access to the NTP Servers on the UDP Port 123 (NTP) to sync the clock with them. So your Firwall needs to allow this.
In a minimum your Server with the FSMO Role PDC should sync. Here is how to find this server:
rem Get the PDC FSMO Role (Or apply it to all your DCs)
netdom /query fsmo
rem This will show you all FSMO Roles, see the PDC role for your main DC server
You can do that on all your DCs (or at least on one in every location/Site).