Article ID: 318266 - View products that this article applies to.
This article was previously published under Q318266
After you join a Windows XP-based client to a Windows NT 4.0-based domain, the client may be unable to log on to the domain. You may receive the following error message:
Event ID 5723 may also be recorded on a domain controller in the domain when the client attempts to log on:
Windows cannot connect to the domain either because the domain controller is down or otherwise unavailable or because your computer account was not found.
You may also see the following entry in Event Viewer on the client:
The session setup from the computer Computername failed to authenticate. The name of the account referenced in the security database is Computername. The following error occurred: Access is denied.
Event Source: NETLOGON
Event ID: 3227
The session setup to the Windows NT or Windows 2000 domain controller \\Server for the domain Domainname failed because \\Server does not support signing or sealing the Netlogon session. Either upgrade the domain controller or set the RequireSignOrSeal registry entry on this machine to 0.
This behavior occurs because the Windows XP-based client tries to sign or seal the secure channel. Windows XP Professional does this by default. However, Windows NT 4.0 is not configured to do this by default.
To resolve this issue:
For additional information, click the article number below to view the article in the Microsoft Knowledge Base:
(http://support.microsoft.com/kb/183859/EN-US/ )Integrity Checking on Secure Channels with Domain Controllers