AD Time Skew Monitor. This monitor generates an alert when the time difference between a domain controller and the PDC exceeds a specified threshold.
This means that two domain controller disagree about the current time. If the time skew grows too large, Kerberos authentication can be affected.
Possible causes include the following:
PDC not configured to use external time source
Multiple DCs configured to use different external time sources
Verify each DC is syncing from either the PDC or a Gtime server. Verify that which ever DC all other DCs are syncing time from is set to use an external time source.
You can use the command line tool w32tm.exe to configure time on the DCs. See external resources below.
For more information, see:
How the Windows Time Service Works
Troubleshooting Windows Time Service Problems
Configuring Time service for the forest