Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Windows error 1240—ERROR_LOGIN_WKSTA_RESTRICTION, or 0x4D8—means a network logon was refused because of a workstation, security-policy, authentication, or protocol restriction. It does not automatically mean the password is wrong. For a documented domain-join failure, Microsoft identifies incompatible SMB-signing requirements between the client and domain controller as a key cause; share access and other network logons can also be blocked by effective user-rights policy or legacy protocol settings.

Start by identifying exactly what fails and whether it affects one account, one computer, or one server. Then check the policy and protocol on the relevant endpoints before changing security settings.

What error 1240 means

The message “The account is not authorized to log in from this station” corresponds to Windows error 1240, ERROR_LOGIN_WKSTA_RESTRICTION (0x4D8). “Station” refers broadly to the computer or network endpoint from which the account is trying to authenticate. A valid username and password can still be rejected if the endpoint’s policy or the negotiated authentication protocol does not meet the target’s requirements. Microsoft’s system error code list gives the code and message.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not confuse it with nearby errors:

  • Error 1239 is a logon-time restriction.
  • Logon failure commonly indicates an invalid username or password, though context matters.
  • “The user has not been granted the requested logon type at this computer” points directly to a logon-right assignment.
  • Access denied is broader and can reflect share or file permissions.
  • A broken domain trust or unavailable domain controller can prevent domain authentication, but is not the same diagnosis as error 1240.

The number and the operation that produced it are more useful clues than the message alone.

First identify where it fails

Note whether the error occurs while joining a domain, opening a share such as \servershare, accessing SYSVOL or Group Policy, or performing another network logon. Also record whether it affects one account, every account on one workstation, or connections to one particular server. These patterns narrow the cause; they do not prove it.

Observed pattern Areas to investigate first
During domain join, with error 1240 SMB-signing compatibility and restrictive security policy; then DNS, domain-controller discovery, join rights, SPNs, and the computer account.
One user fails from multiple computers Account restrictions, group membership, and effective network-logon allow/deny policy.
Several users fail from one workstation That computer’s applied policy, SMB client configuration, cached SMB sessions, or domain connectivity.
Only one file server or NAS fails That target’s SMB-signing and authentication capabilities, configuration, and compatibility with the client.
SYSVOL or Group Policy access fails SMB negotiation as well as Netlogon, domain-controller, SYSVOL, and replication health.
A share works by IP address but not by name DNS, name resolution, SPNs, and the Kerberos authentication path.
An existing domain member suddenly cannot authenticate Check DNS, time, domain-controller availability, and the secure channel rather than assuming an SMB-signing issue.

Run low-risk checks before changing policy

On the affected workstation, open Command Prompt and note the signed-in identity and existing SMB connections:

whoami
net use

Windows can retain an SMB connection using different credentials. If you are sure it is safe to disconnect current mapped drives and share sessions, clear them before testing:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
net use * /delete
net use \servershare /user:DOMAINusername

Replace the server, share, domain, and username with the actual values. The delete command disconnects all current network connections made with net use; save work and check for dependencies first. A successful test with a different account, computer, or server helps isolate the scope, but is not proof of a specific cause.

Rank #2
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

If the error occurs during a domain join

  1. Read the join log. Check C:WindowsdebugNetSetup.log around the failure time for the target domain controller and the failed stage.
  2. Verify DNS and controller discovery. The joining computer should use the domain’s DNS service, not an unrelated public resolver. Replace example.com with your AD DNS domain:
ipconfig /all
nslookup -type=SRV _ldap._tcp.dc._msdcs.example.com
nltest /dsgetdc:example.com

Failed SRV lookup or discovery warrants fixing DNS or domain-controller availability before retrying the join.

  1. Check SMB-signing compatibility. Microsoft documents a domain-join authentication case in which client and domain-controller SMB-signing requirements do not match. Compare the effective policies on both systems; do not assume that re-entering credentials will resolve a negotiation failure. See Microsoft’s domain-join authentication troubleshooting guidance.
  2. Verify join permissions and the computer account. The account may need permission to create a computer object or reuse the existing object, depending on how the domain is configured. Check for a stale or conflicting computer account rather than granting broad administrative rights as a shortcut.
  3. Check SPNs and domain health where indicated. Microsoft’s guidance includes checking controller registration in DNS and relevant SPNs in Active Directory. These checks are typically for a domain administrator.
  4. Refresh policy and retry only after correcting the cause. Run gpupdate /force if policy was changed, then repeat the original join attempt and review the new log entries.

A domain rejoin is not a first diagnostic step. It will not fix incompatible signing policy, incorrect DNS, missing join permission, or a misconfigured domain controller.

If a network share, SYSVOL, or Group Policy fails

Compare the SMB-signing requirements of the client and target server. Relevant settings are under secpol.msc → Local Policies → Security Options; domain policy may set the effective values instead. The exact display names can vary by Windows version and administrative-template language:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Microsoft network client: Digitally sign communications (always)
  • Microsoft network client: Digitally sign communications (if server agrees)
  • Microsoft network server: Digitally sign communications (always)
  • Microsoft network server: Digitally sign communications (if client agrees)

In the documented legacy file-share scenario, a mismatch between signing required by the Workstation service and signing disabled by the Server service—or the reverse—can prevent SMB connection and produce error 1240. Microsoft’s article also describes affected access to SYSVOL, Group Policy snap-ins, administrative shares, and dcdiag checks: Cannot open file shares and Group Policy snap-ins.

Rank #3

If SYSVOL or a domain controller is involved, an administrator can run these checks on the relevant controller:

dcdiag /test:netlogons
dcdiag /test:machineaccount

Interpret results alongside Netlogon, DNS, replication, and SYSVOL health; a failed share test alone does not establish that SMB signing is the cause.

Check network-logon user rights

On the destination computer, open secpol.msc and go to Local Policies → User Rights Assignment. Inspect:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Access this computer from the network
  • Deny access to this computer from the network

For a network share, the network-logon rights are the relevant ones. Allow log on locally concerns console sign-in; Allow log on through Remote Desktop Services concerns Remote Desktop. Check corresponding deny rights when investigating those logon types.

Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.

A deny assignment generally takes precedence over an allow assignment. Check the user’s group memberships, including nested or domain groups, and the policy applied to the destination. Being an administrator does not automatically override an explicit deny or fix an SMB or authentication mismatch. Microsoft also documents network-logon failures caused by user-right assignments in its network login troubleshooting guidance.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Find the effective policy, not just the local setting

A local policy setting marked “Not Configured” may still be controlled by a domain Group Policy Object (GPO). Export the effective security policy and generate a Group Policy report for review:

secedit /export /cfg C:Tempeffective-security-policy.inf
gpresult /h C:Tempgpresult.html

Create C:Temp first if it does not exist. In the report, identify which GPO applies the relevant settings and to which computer. A local edit may be overwritten at policy refresh, startup, or sign-in. If the policy is domain-managed, change it through the responsible GPO—not an isolated local override.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Other settings worth reviewing for older or mixed environments include Network security: LAN Manager authentication level, Domain member: Digitally encrypt or sign secure channel data (always), and Domain member: Require strong (Windows 2000 or later) session key. Do not lower authentication requirements or alter secure-channel policies speculatively: first establish the endpoint’s requirements and the security effect of a proposed change.

Best Value
Windows 11 Laptop with i3 Processor 15.6" Work Laptop for College Students
  • 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
  • Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
  • 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
  • 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
  • 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop

Choose an SMB-signing fix without weakening the network unnecessarily

  1. Identify which endpoint is requiring signing and which endpoint is refusing, not supporting, or negotiating it differently.
  2. Confirm the SMB and signing capabilities of both endpoints, especially if the target is an old Windows server, NAS, Samba system, or other SMB appliance.
  3. Prefer updating or correctly configuring the older endpoint so it supports the required signing mode.
  4. Align the effective client and server policies in the authoritative GPO or documented device configuration.
  5. Refresh policy with gpupdate /force. Restart a service or computer only if the policy change requires it, and follow the platform’s change procedure.
  6. Retest the exact original action from the original computer using the intended account.

Requiring SMB signing helps protect communications against tampering and session-hijacking risks, but can prevent connections to older systems that cannot negotiate it. Disabling signing may restore compatibility while reducing protection. Microsoft describes these compatibility and security trade-offs in its security-settings and user-rights guidance. Avoid disabling signing everywhere as a blanket fix; if an exception is unavoidable, limit its scope, document the risk and owner, and set a removal plan.

Legacy registry workaround: only for the documented old scenario

Microsoft’s registry procedure for this class of share and SYSVOL problem describes Windows 2000 Server and Windows Server 2003-era behavior. It uses SMB-signing values in these service parameter keys:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServiceslanmanserverparameters
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServiceslanmanworkstationparameters

The values include EnableSecuritySignature and RequireSecuritySignature. Do not copy legacy value changes onto a current Windows client or server as a general-purpose repair: the applicable defaults and enforcement can differ, and Group Policy may override the registry. An incorrect edit can also make recovery harder.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If maintaining a system covered by that legacy procedure, use the applicable Microsoft instructions and change-control process. Before any edit, export or back up the relevant keys, record the original values, identify the GPO that controls them, and make sure you have a tested rollback path. Changes may require restarting the affected Server or Workstation service; follow the version-specific procedure, especially on a domain controller. A temporary compatibility exception should be narrowly scoped and removed once the incompatible endpoint is updated or replaced.

Verify the repair

After correcting the identified cause:

  1. Repeat the original action with the intended account from the original workstation.
  2. Confirm access to the required share, domain join, or SYSVOL resource—not merely that the error message disappeared.
  3. Run gpupdate /force where policy changes apply, then check that the intended settings remain effective.
  4. Review the System and Security event logs, Group Policy operational log, and Netlogon logs where appropriate. For a join, inspect the updated C:WindowsdebugNetSetup.log.
  5. Confirm the change is not a local override that a domain GPO will reverse, and record any temporary security exception for follow-up.

Involve a domain administrator if the enforcing GPO is unclear, multiple controllers or SYSVOL are affected, SPN or machine-account repair is needed, or resolving compatibility would require weakening domain-wide authentication.

Quick Recap

Bestseller No. 1
Bestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$309.00
Bestseller No. 3
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$247.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.