Article ID: 155076 - Last Review: November 1, 2006 - Revision: 2.1

Only Administrators May Log in After Applying C2 Security from the Windows NT 4.0 Resource Kit

This article was previously published under Q155076
Expand all | Collapse all

SYMPTOMS

After you apply C2 security from the Windows NT Resource Kit, only user accounts that are members of the administrator's group are allowed to log on. Others receive one of the following messages:
You are not allowed to logon from this workstation.
-or-
Your account is configured to prevent you from using this workstation.

CAUSE

The C2 configuration application is configured with CrashOnAuditFail set to 2. This value allows only administrators to log on to a server.

NOTE: An alternate error
Access Denied: an extended error has occurred
may occur when attempting to connect to a file share on a server. This may also indicate that CrashOnAuditFail is set to a value of 0x2.

RESOLUTION

WARNING: Using Registry Editor incorrectly can cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that problems resulting from the incorrect use of Registry Editor can be solved. Use Registry Editor at your own risk.
  1. Start Registry Editor (Regedt32.exe) and select the following subkey:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
  2. Look for the value CrashOnAuditFail. If the value is set to 2, follow instructions outlined in 140058  (http://support.microsoft.com/kb/140058/EN-US/ ) to change this value.

APPLIES TO
  • Microsoft Windows NT Server 3.5
  • Microsoft Windows NT Server 3.51
  • Microsoft Windows NT Server 4.0 Standard Edition
Keywords: 
kbenv kbnetwork KB155076
 

Article Translations