You’re using a bit strange method here. First you enter a PS remoting session, than you use Invoke-Command. That’s not the way to go. You can just use this if the server you connect to is domain joined:
Here, the Enter-PSSession is redundant. Just remove that and the Exit-PSSession. Invoke-Command will then spin up a new session to the remote machine, and that new session will be spun up using the credentials you desire. What you’r currently doing is…
Connecting from ComputerA to ComputerB, and delegating your ComputerA credentials
Asking ComputerB to connect to ComputerC (which is in fact still ComputerB), using a set of specified credentials - this isn’t legal using Kerberos, which is the default authentication protocol
It might be worth reading up a bit on some of Remoting’s basics, so that you have a better feel for how sessions are used and managed. We have a free Remoting book (on our eBooks page) that goes over the foundations, if that helps.
Thanks for the replies, i kinda knew what i was doing was wrong. But i was just testing different methods to see if i could get it working.
Anyway, if i remove the Enter-PSSession i still get the same issue. I need to pass the local Admin creds to allow me to run the command w32tm /resync.
Basically, the Domain Controllers are being aged (Date changed to the future) and i need to reysnc all the times as quickly as possible. I want to try to avoid having to log onto each server and run the command. So i need to use the local admin account rather than the domain account as this is blocked due to the time difference between host and DC.
So… I’m not actually sure that’ll work. At least not with Kerberos, and at least not how you’re doing it. You’re probably going to have to enable, and then use, Basic authentication. That’ll mean either implementing SSL on the DCs, or adding them to your local TrustedHosts list. Be aware that without SSL, you’re passing username/password in clear text.
The problem is that Kerberos doesn’t let you authenticate using non-Domain credentials. That’s more or less the point of it, in fact. So if the domain isn’t an option, then neither is Kerberos. Nothing else will be enabled on the DCs by default, though, so you’ll have to enable Basic or something else - possibly using a Group Policy, if possible, or manually if not.