If the domain's Key Distribution Center (KDC) clock and the Kerberos client's clock differ by more than 5 minutes, authentication will fail. If you suspect this reason for a user's inability to log on, you can verify if the user's computer time is synchronized by using NETDOM.EXE from the Windows Support Tools. The Syntax is:
netdom time ComputerName /verify
Examplenetdom time jsi005 /verify
If the ComputerName is synchronized, you will receive:
Computer Status ===NOTE: See How do I configure an authoritative time server in Windows 2000?