What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
This message usually appears when Configuration Manager client push cannot connect from the site server to a target computer’s administrative share, commonly \TARGET-COMPUTERAdmin$. It is not automatically a bad-password error. Read the hexadecimal code in ccm.log, then test name resolution, SMB, the ADMIN$ share, and the client-push account’s effective local-administrator rights.
What the message means
During client push, the Client Configuration Manager component on the site server attempts to establish a Windows network connection to the target computer. WNetAddConnection2 is the Windows API used to connect to a network resource such as an SMB share; its failure can mean an unavailable path, invalid name, authentication failure, access denial, or a conflicting existing connection. See the WNetAddConnection2A reference.
LOGON32_LOGON_INTERACTIVE is Windows logon type 2. It describes the token-creation method used for the supplied account, not proof that someone is physically logged on to the computer. The surrounding log lines and the error value are more diagnostic than this phrase alone. Microsoft documents the API and logon behavior in the LogonUser reference and Windows logon scenarios.
Historical Configuration Manager guidance describes this class of failure as an inability to connect to ADMIN$ or related remote-management resources. A matching Configuration Manager 2012 R2 case was resolved by making the client-push account a local administrator on the target machines, but that fix does not address DNS, routing, disabled shares, or firewall failures. See the reported case and archived Microsoft troubleshooting material.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors#1 Best Overall
- Phoossno USB cable is one of active USB 3.1 extension 10Gbps cable, it is optical cable extension solution, use advanced Optical-Electric Converting technology, extension USB 3.0 USB2.0 and USB1.1 signal to 15m max, cable is more Flexible & Light & Slim than traditional passive copper USB cable
- USB extension 3.1 cable,back forward compatible to USB 3.1 Gen 1 (5Gbps), also back forward compatible to USB 2.0 (Full Speed 480Mbps )and USB 1.1
- Usb cable extender Supprt USB 3.1 device under Windows , Mac, Unix Operation system, plug & play, no need install any driver software
- USB 3.1 Active Optical Cable dopt standard USB A male to USB A female solution, at USB A female side, end-user can exchange different USB converting interface, such as USB A to USB A, USB A to USB B, USB A to USB type C, USB A to USB Micro B, USB A to Mini B etc, this can apply to kinds of USB interface device, such as Hard Disk, Touch Screen, Web Camera, Game Controller, Mouse, Keyboard, Printer, Scanner, etc.
- male to female extension calbe Applications, USB is very important interface on computer, it communicate with all computer peripherals, to connect all Industrial Control, Digital Signage, Home integrating, Medical USB device , Video Meeting Conference, Machine Vision, KVM extension, Web Camera etc.
Start with the server-side log
Open <Configuration Manager installation directory>Logsccm.log on the site server. The exact installation path varies by release and setup. Look for entries from SMS_CLIENT_CONFIG_MANAGER, including the target name, account, hexadecimal code, and 20–30 lines before and after the failure.
Attempting to connect to administrative share 'HOSTAdmin$'
using account 'DOMAINAccount'
WNetAddConnection2 failed (...)
ERROR: Unable to access target machine ...
Use the target’s ccmsetup.log only after files have been copied and installation has started. A connection failure can occur before the target has a working Configuration Manager client.
Decode the hexadecimal error
Convert the value to decimal and map it to Microsoft’s system error codes 0–499 or codes 1300–1699. Common branches are:
| Log value | Decimal | Typical meaning | First checks |
|---|---|---|---|
00000035 |
53 | Network path not found | DNS, target availability, SMB and firewall |
00000005 |
5 | Access denied | Effective local-admin rights, policy and UAC filtering |
0000052e |
1326 | Username or password is incorrect | Account format, password, lockout, expiry and trust |
00000043 |
67 | Bad network name | Computer/share name and name resolution |
A code such as 00000035 should not be “fixed” by adding permissions; it normally indicates that the path cannot be found. Conversely, a valid password does not grant access to ADMIN$.
Run the connectivity checks from the site server
1. Confirm the name and host are reachable
Test-Connection TARGET-COMPUTER -Count 2
Resolve-DnsName TARGET-COMPUTER
Test-NetConnection TARGET-COMPUTER -Port 445
DNS failure points to stale records, suffixes or an incorrect computer name. A failed ping is inconclusive because ICMP may be blocked. A failed TCP 445 test strongly indicates an SMB, route or firewall problem. On older PowerShell versions, use:
net view \TARGET-COMPUTER
dir \TARGET-COMPUTERADMIN$
2. Test the exact share with the configured account
net use \TARGET-COMPUTERAdmin$ /user:DOMAINusername *
dir \TARGET-COMPUTERAdmin$
net use \TARGET-COMPUTERAdmin$ /delete
The asterisk prompts for a password; do not put passwords in command history or scripts. If Windows reports that multiple connections using different credentials are not allowed, inspect and remove only the conflicting session:
net use
net use \TARGET-COMPUTERIPC$ /delete
net use \TARGET-COMPUTERAdmin$ /delete
Verify the client-push account
- Use the correct scope, normally
DOMAINusernamefor a domain account. - Confirm the account is enabled, not expired or locked out, and that Configuration Manager has its current password.
- Ensure the account is an effective member of the target computer’s local Administrators group.
- Confirm policy grants network access and does not deny it.
- Check that the site server and target have a usable domain trust.
Nested group membership can be removed or replaced by Group Policy, Restricted Groups, Local Users and Groups policy, or endpoint-management software. Check effective membership rather than assuming that a domain group was applied.
Rank #2
- Phoossno USB cable is one of active USB 3.1 extension 10Gbps cable, it is optical cable extension solution, use advanced Optical-Electric Converting technology, extension USB 3.0 USB2.0 and USB1.1 signal to 15m max, cable is more Flexible & Light & Slim than traditional passive copper USB cable
- USB extension 3.1 cable,back forward compatible to USB 3.1 Gen 1 (5Gbps), also back forward compatible to USB 2.0 (Full Speed 480Mbps )and USB 1.1
- Usb cable extender Supprt USB 3.1 device under Windows , Mac, Unix Operation system, plug & play, no need install any driver software
- USB 3.1 Active Optical Cable dopt standard USB A male to USB A female solution, at USB A female side, end-user can exchange different USB converting interface, such as USB A to USB A, USB A to USB B, USB A to USB type C, USB A to USB Micro B, USB A to Mini B etc, this can apply to kinds of USB interface device, such as Hard Disk, Touch Screen, Web Camera, Game Controller, Mouse, Keyboard, Printer, Scanner, etc.
- male to female extension calbe Applications, USB is very important interface on computer, it communicate with all computer peripherals, to connect all Industrial Control, Digital Signage, Home integrating, Medical USB device , Video Meeting Conference, Machine Vision, KVM extension, Web Camera etc.
net localgroup administrators
For domain diagnostics, use the organization’s approved identity tools and, where applicable:
Recommended Free Tools
whoami /user
nltest /sc_verify:DOMAIN
If the target is in a workgroup, domain credentials do not have the same trust relationship as they do on a domain-joined computer. Use a supported Configuration Manager installation method for workgroup clients instead of repeatedly changing passwords.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Check administrative shares and services on the target
net share
sc query lanmanserver
A typical supported Windows workstation or server exposes ADMIN$ and IPC$, subject to edition and policy. If ADMIN$ is missing, investigate the Server service, administrative-share policy, registry or Group Policy changes, security software, and the target’s Windows edition. Do not recreate the share or edit the registry until you establish why automatic administrative shares were disabled.
Separate SMB, RPC, authentication and authorization
- SMB reachability: TCP 445 and the share path must be reachable.
- RPC and service control: remote installation operations require the relevant RPC and remote-service traffic permitted by your Configuration Manager and Windows versions.
- Authentication: the account must obtain a valid token.
- Authorization: that token must have effective local-admin and remote-management rights.
A successful port-445 test proves only basic SMB reachability. Check Windows Firewall rule sets, domain-profile policy, network segmentation, VPN routes and endpoint-security logs. Do not disable the firewall as a permanent remedy; if policy allows a brief controlled test, restore it and create narrowly scoped inbound rules for the required traffic.
Review local security policy and UAC restrictions
Even a domain account in local Administrators can be affected by UAC remote filtering, Deny access to this computer from the network, missing Access this computer from the network, NTLM restrictions, SMB-signing requirements, domain isolation or security software that blocks remote service creation.
- Verify account scope and effective group membership.
- Review Resultant Set of Policy and security logs on the target.
- Check endpoint-protection events for blocked administrative-share or remote-service activity.
- Change UAC or authentication policy only under an approved security change, preferably through domain policy, and record a rollback.
Broadly weakening UAC, NTLM or firewall protections can expose every managed computer and is not a default fix.
Retry and verify the installation
- Correct the specific cause identified by the code and tests.
- Trigger client push again from the Configuration Manager console.
- Watch the site server’s
ccm.logfor progress beyond the connection attempt. - On the target, confirm file transfer and review
ccmsetup.log. - Verify that the client registers and reports to its assigned site.
When client push is the wrong method
Client push depends on administrative shares, SMB/RPC reachability and a deployment account with meaningful rights on each target. Choose another supported installation approach when devices are internet-based, remote across blocked network zones, workgroup-joined, subject to strict local-admin restrictions, or already managed through provisioning, task sequences, software deployment or another management platform. A successful manual ADMIN$ test does not make client push appropriate for every security architecture.
Quick Recap
Common traps
- “It must be the password.” The code may instead indicate a missing path or access denial.
- Ping works, so client push should work. ICMP does not prove SMB, RPC or authorization.
- Add more permissions immediately. Permissions cannot repair DNS or routing failures.
- Rebuild WMI first. An archived HPE case associated
0000052ewith a separate suspected WMI problem; rebuilding WMI is not a first-line response to this connection error. See that archived support record. - Assume old SCCM behavior is universal. Log wording and supported methods vary by Configuration Manager and Windows release.
Final checklist
- The target name resolves to the intended computer.
- The target is online and TCP 445 is reachable.
ADMIN$exists and the Server service is running.- The configured account authenticates with the correct scope and current password.
- The account is an effective local administrator.
- Firewall, RPC and endpoint-security policies permit the operation.
- No conflicting SMB session is using another credential.
ccm.logprogresses beyond the connection attempt andccmsetup.logrecords installation.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




