The Local Security Authority cannot be contacted. 4625 0xC000006E
we restrict service account logged onto 1 or 2 servers in order control accounts used. in active directory using "logon to" option. before server 2012, put destination server name in "logon to" box , remote (rdp) in service account trobleshoot server.
that no longer works server 2012. when attempting rdp server, message "an authentication error has occured. local security authority cannot contacted. " security log shows audit failure 4625 with status of 0xc000006e , sub status of 0xc0000070. have looked , means resticted ad. found if logging in "pc1" part of domain "server1", have put both "pc1" , "server1" in "logon to" box in ad. not required when rdp'ing windows server 2008 machine. becomes problem many of support people have multiple machines , "logon to" box have limit.
can explain why happening , how avoid behavior. still restrict service accounts as possible.
Windows Server > Windows Server 2012 General
Comments
Post a Comment