The Local Security Authority cannot be contacted. 4625 0xC000006E


we restrict service account logged onto 1 or 2 servers in order control accounts used. in active directory using "logon to" option. before server 2012, put destination server name in "logon to" box , remote (rdp) in service account trobleshoot server. 

that no longer works server 2012. when attempting rdp server, message "an authentication error has occured. local security authority cannot contacted. " security log shows audit failure 4625 with status of 0xc000006e , sub status of 0xc0000070. have looked , means resticted ad. found if logging in "pc1" part of domain "server1", have put both "pc1" , "server1" in "logon to" box in ad. not required when rdp'ing windows server 2008 machine. becomes problem many of support people have multiple machines , "logon to" box have limit.

can explain why happening , how avoid behavior. still restrict service accounts as possible.



Windows Server  >  Windows Server 2012 General



Comments

Popular posts from this blog

Azure MFA with Azure AD and RDS

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com