The Local Security Authority cannot be contacted. 4625 0xC000006E


we restrict service account logged onto 1 or 2 servers in order control accounts used. in active directory using "logon to" option. before server 2012, put destination server name in "logon to" box , remote (rdp) in service account trobleshoot server. 

that no longer works server 2012. when attempting rdp server, message "an authentication error has occured. local security authority cannot contacted. " security log shows audit failure 4625 with status of 0xc000006e , sub status of 0xc0000070. have looked , means resticted ad. found if logging in "pc1" part of domain "server1", have put both "pc1" , "server1" in "logon to" box in ad. not required when rdp'ing windows server 2008 machine. becomes problem many of support people have multiple machines , "logon to" box have limit.

can explain why happening , how avoid behavior. still restrict service accounts as possible.



Windows Server  >  Windows Server 2012 General



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS