I'm running Windows 11 OS on the client.
The system administrator has restricted the types of logon (network or interactive) that you may use.
I have a Windows 2019 domain controller that is throwing the exception below when anybody but the administrator logs into. This recently changed, but I'm not sure what triggered the change. My profile is part of the Remote Desktop user group and the server is running NLA (part of the default group policy). I'm able to log on to all computers on the domain.
[Window Title]
Remote Desktop Connection
[Content]
The system administrator has restricted the types of logon (network or interactive) that you may use. For assistance, contact your system administrator or technical support.
[^] Hide details [OK]
[Expanded Information]
Error code: 0x1307
Extended error code: 0x0
Timestamp (UTC): 03/26/24 03:01:36 PM
2 answers
Sort by: Most helpful
-
-
Daisy Zhou 18,701 Reputation points Microsoft Vendor
2024-03-27T06:57:15.09+00:00 Hello John McCleskey,
Thank you for posting in Q&A forum.
1.How many Domain Controllers are there in this domain?
2.Do you mean when non-Administrator logs on this Domain Controller, there will be such error message?
3.Or when non-Administrator logs Windows 11 OS on the client, there will be such error message?
4.Did you log on the machine locally or remotely?
If you cannot log on to Windows 11 OS client, please check:
Go to Local Security PolicyNavigate to Security Settings -> Local Policies -> User Rights Assignment
Access this computer from Network (has this user or user group)
Allow log on locally (has this user or user group if you are talking about local logon)
Allow log on through Remote Desktop Services (has this user or user group if you are talking about remote logon)
Deny access this computer from Network (there is no this user or user group)
Deny log on locally (there is no this user or user group)
Deny log on through Remote Desktop Services (there is no this user or user group)
And check this user or user group is in Remote desktop users group (open lusrmgr.msc on this client to check).
If you cannot log on to Domain Controller, please check: Edit Default Domain Controller Policy,
Navigate to Security Settings -> Local Policies -> User Rights Assignment
Access this computer from Network (has this user or user group)
Allow log on locally (has this user or user group if you are talking about local logon)
Allow log on through Remote Desktop Services (has this user or user group if you are talking about remote logon)
Deny access this computer from Network (there is no this user or user group)
Deny log on locally (there is no this user or user group)
Deny log on through Remote Desktop Services (there is no this user or user group)
And check this user or user group in in Remote desktop users group.
And check this user or user group is in Remote desktop users group (open AD users and computers on Domain Controller to check).
References:
https://bobcares.com/blog/the-system-administrator-has-restricted-the-type-of-logon/
I hope the information above is helpful.
If you have any questions or concerns, please feel free to let us know.
Best Regards,
Daisy Zhou
============================================
If the Answer is helpful, please click "Accept Answer" and upvote it.