You want the PDC Emulator in the root domain to be using NTP and all other DCs to be using NT5DS to sync time. As long as everything is within 5 minutes of each other Kerberos (within the forest realm ...
Fixing out of sync VM clocks may be a bit annoying, but it's 100 percent doable. Here's how. One of the nice things about Hyper-V is that you usually don't have to worry about setting virtual machine ...
IIRC windows doesn't run ntp by default, it runs some propretary w32time service instead. I think it has an ntp client built in, but I'm not sure if it can be an NTP server out of the box.