The verification fails if the time difference between the client and the domain controller is more than five minutes. the user name and password are correct even if the domain member relationship is correct.
You do not need to modify the time to avoid permission verification failures when using resources in the domain.
If you do not want the client to synchronize domain control time, you can disable the windowstime service on the local machine.
If the time attribute window cannot be opened and the modification time is because the system defaults to ADMINISTRATORS, POWERUSERS can change the time, you can add a user to the two groups on the local computer or in the Group Policy of the domain, choose computer configuration-windows Settings-security policy-local policy-user permission assignment-Change the system time to a user. or user group or domainusers group, in this way, Domain Users can modify the time.
This article from the "old IT" blog, please be sure to keep this source http://lmit8.blog.51cto.com/787006/1303035