Troubleshooting / symptôme

Could not, open a session on Windows domain

A user can no longer log in with his domain account.

⌚ About 3 min read
View my favorites
Real-world problem · V2

Quick troubleshooting view

What you are seeing

A user can no longer log in with his domain account.

Likely causes
  1. Invalid or expired password
  2. Locked or deactivated account
  3. Inaccessible domain controller
First checks
  1. Test another account
  2. Control Domain Connectivity
  3. Check the account status
Recommended actions
  1. Unlock or re-open account if justified
  2. Correct the DNS of the post
  3. Restoring communication with a domain controller
Start Symptom → Cause →
Active DirectoryIntermediate.

A user can no longer log in with his domain account.

Important: relevez toujours le message d’erreur exact et l’heure du problème avant de modifier la configuration. Les actions proposées doivent être adaptées à votre environnement.

Causes probables

  • Invalid or expired password
  • Locked or deactivated account
  • Inaccessible domain controller
  • Invalid DNS
  • Relationship problem of approval

Diagnostic étape par étape

  1. 1

    Test another account

    Determine if the problem is with the user or the position.

  2. 2

    Control Domain Connectivity

    Check DNS and access to the domain controller.

  3. 3

    Check the account status

    Check lock, deactivate and expire.

  4. 4

    Read the exact message

    Distinguish incorrect password, domain unavailable or relationship of approval.

Commands utiles

nltest /dsgetdc:example.local
The new and updated version of the document is available on the website of the European Commission.
arami /fqdn

Solutions possibles

  • Unlock or re-open account if justified
  • Correct the DNS of the post
  • Restoring communication with a domain controller
  • Treat the relationship of approval without withdrawing the position from the domain as a first-line
Quand escalader ?

Climb if multiple positions no longer find a domain controller.

♡ 0