What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

This error usually means Windows cannot complete the domain authentication needed for the Remote Desktop connection—not that Network Level Authentication (NLA) should be permanently turned off. First restore the client or remote PC’s connection to Active Directory, checking VPN access, internal DNS, domain-controller reachability, time synchronization, and the computer’s domain trust. Microsoft recommends keeping NLA enabled because it authenticates users before a full remote session is established. Microsoft’s Remote Desktop guidance explains the security role of NLA.

What the error means

Remote Desktop first contacts the host. If that host requires NLA, CredSSP attempts to authenticate the user before Windows creates the usual graphical logon session. The message—“The remote computer that you are trying to connect to requires Network Level Authentication (NLA), but your Windows domain controller cannot be contacted to perform NLA”—says Windows could not contact or use the domain services needed for that authentication attempt.

That does not prove NLA itself is faulty, nor that every NLA connection requires a domain controller in every configuration. Account type and identity setup matter. But this specific wording makes domain connectivity the first thing to investigate. Disabling NLA can reduce protection and is an emergency access workaround, not a lasting repair.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start with the safe checks

  1. Confirm the remote PC or server is powered on and connected to the expected network.
  2. If the target or domain controller is reachable only over the organization’s network, connect the corporate VPN. The VPN must carry internal DNS and the required domain traffic, not just reach the RDP host.
  3. Check whether other domain-joined computers or users have the same problem. A broader failure may point to a domain controller, VPN, DNS, or routing issue.
  4. Note what changed immediately beforehand: a restart, network or VPN change, domain migration, VM snapshot restore, policy update, or Windows security update.
  5. Confirm the host supports incoming Remote Desktop and that the user is permitted to connect. On Windows client editions, the current path is Settings → System → Remote Desktop; labels may vary by release or management policy. Windows Home can connect to other PCs but cannot act as a standard incoming RDP host. See Microsoft’s edition and setup guidance.

Run checks from the computer you are connecting from

Open PowerShell and check the network configuration:

ipconfig /all

On the active network or VPN adapter, look for DNS servers that belong to the organization’s Active Directory DNS infrastructure and the expected connection details. A public DNS resolver may resolve internet sites while failing to find internal domain records.

Replace example.com and dc01.example.com below with your actual AD domain and a known domain controller. Test domain-controller discovery and DNS:

nslookup dc01.example.com
nslookup -type=SRV _ldap._tcp.dc._msdcs.example.com
nltest /dsgetdc:example.com

A successful SRV lookup and nltest result should identify domain-controller records and a controller. Failure points toward DNS configuration, VPN routing, firewall rules, or controller availability. Do not switch a domain-joined computer to public DNS as a generic fix; correct its path to internal DNS instead.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check whether common domain services are reachable:

Test-NetConnection dc01.example.com -Port 53
Test-NetConnection dc01.example.com -Port 88
Test-NetConnection dc01.example.com -Port 389
Test-NetConnection dc01.example.com -Port 445
  • 53: DNS
  • 88: Kerberos
  • 389: LDAP
  • 445: SMB and related domain operations

A passing test confirms only that a connection to that host and port succeeded. It does not establish that Active Directory is fully healthy; domain operations can depend on other services, including RPC and dynamic ports. Do not treat any single port as a complete NLA test.

Rank #2
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

Separately test the RDP path to the target:

Test-NetConnection target-hostname -Port 3389

If port 3389 fails, investigate the target’s address, routing, firewall, and RDP listener. If it succeeds while NLA still fails, the RDP host is reachable but the authentication path may not be.

Check time and the computer’s domain trust

Kerberos is time-sensitive. On the affected computer, inspect the time source and status:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
w32tm /query /status
w32tm /query /source
w32tm /resync

If resynchronization fails, check the configured time source and whether the machine can reach it. A manual clock adjustment may mask the symptom but is not a durable substitute for a healthy domain time hierarchy.

Check the local machine’s secure channel with the domain:

nltest /sc_verify:example.com

If this fails, the computer may not be able to validate its domain trust. Repair may require domain credentials and console or administrative access. A restored VM snapshot, stale machine password, duplicated image, or computer-account change can break trust even when ordinary network access looks normal.

Rank #3

Inspect the remote computer

If you have console access, a hypervisor or cloud serial console, or another authorized administrative route, run these checks on the target:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
systeminfo
nltest /dsgetdc:example.com
nltest /sc_verify:example.com

Confirm that the host is joined to the expected domain rather than a workgroup, can locate a domain controller, and has a working secure channel. A domain migration, deleted or reset computer account, or old VM snapshot may need administrator attention. Do not assume an Entra-joined device is interchangeable with a traditional AD domain-joined PC; the destination, account type, and authentication configuration affect what credentials can work.

Check relevant services:

Get-Service TermService,Netlogon,Dnscache,LanmanWorkstation,NlaSvc

Investigate any stopped or unhealthy service in context before changing it. Restarting Remote Desktop Services disconnects active RDP sessions; on a production server, do so only when that impact is acceptable and you have another way to recover access:

Restart-Service TermService

Review Remote Desktop firewall rules and policy as a separate check. Enabling an RDP firewall rule does not repair a domain-controller authentication failure:

Get-NetFirewallRule -DisplayGroup "Remote Desktop" |
    Select-Object DisplayName, Enabled, Profile, Direction, Action

Only if permitted by your organization’s security policy, you can enable the built-in group:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
Enable-NetFirewallRule -DisplayGroup "Remote Desktop"

For event evidence, check Event Viewer → Windows Logs → System and Security, plus Applications and Services Logs → Microsoft → Windows for TerminalServices-LocalSessionManager, TerminalServices-RemoteConnectionManager, Kerberos-Key-Distribution-Center, and GroupPolicy. Record the timestamp and time zone, client and target names and IP addresses, VPN status, DNS servers, command output, and whether another client or a local account changes the result.

Temporarily turn off NLA only if you have another trusted way in

Use this only when immediate access is necessary and you have console or authorized administrative access to the remote computer. Disabling NLA removes authentication before the full RDP session is created, so it can increase exposure. Restrict network access to the host, use the shortest possible window, and restore NLA after repairing domain connectivity.

Option 1: Settings dialog

  1. At the remote computer, press Win+R, enter SystemPropertiesRemote, and press Enter.
  2. On the Remote tab, clear Allow connections only from computers running Remote Desktop with Network Level Authentication.
  3. Select Apply and OK, then test the connection.

The exact wording can vary across Windows client and Server releases. This change does not fix DNS, VPN, or domain trust.

Option 2: Registry or PowerShell

On the remote machine, with administrative rights, record the original value or export the key before changing it. Set UserAuthentication to 0 to temporarily disable NLA:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
reg export "HKLMSYSTEMCurrentControlSetControlTerminal ServerWinStationsRDP-Tcp" "%USERPROFILE%DesktopRDP-Tcp-backup.reg"
reg add "HKLMSYSTEMCurrentControlSetControlTerminal ServerWinStationsRDP-Tcp" /v UserAuthentication /t REG_DWORD /d 0 /f

The same change in PowerShell is:

Set-ItemProperty `
  -Path 'HKLM:SYSTEMCurrentControlSetControlTerminal ServerWinStationsRDP-Tcp' `
  -Name UserAuthentication `
  -Type DWord `
  -Value 0

Apply the change with an appropriate service restart or reboot. A service restart drops active RDP sessions, so plan accordingly. If Group Policy or device management controls this value, a local change may be overwritten.

Best Value
Windows 11 Laptop with i3 Processor 15.6" Work Laptop for College Students
  • 【Efficient Performance】 Powered by Intel Core i3 processor (2 cores, 4 threads, up to 3.4GHz) with 12GB RAM and 256GB SSD. Handles multitasking, office software, online classes, and HD video streaming smoothly. Integrated Intel UHD Graphics 620
  • Backlit Keyboard & Complete Package】Comes with a cool backlit keyboard. Comes with awebcam, dual stereo speakers (8Ω/1.0W each), DC charger, and user manual – ready for late-night studying, online classes, video conferencing, and daily productivity
  • 【Vibrant Display】 15.6-inch Full HD (1920x1080) anti-glare screen with 16:9 aspect ratio delivers crisp images and vivid colors – perfect for studying, watching lectures, or entertainment. Thin-bezel design maximizes viewing area
  • 【Fast Connectivity & Expansion】 Equipped with WiFi 6 (802.11ax) and Bluetooth 5.2 for stable, high-speed wireless. Features 3 x USB 3.0, HDMI 2.1, Type-C (supports PD3.0 fast charging), and a TF card slot expandable up to 2TB – easily connect external monitors, mice, drives, or expand storage for all your files
  • 【Long Battery Life & Portable】 Built-in 11.55V 5000mAh/57.75Wh high-capacity battery delivers approximately 7 hours of mixed-use battery life – enough for a full day of classes and assignments. Lightweight at just 1.63kg (3.6 lbs) and 19.5mm thin, plus a compact packing size – easily slips into a backpack for campus, library, or coffee shop

Option 3: Group Policy

In the applicable policy editor, open Computer Configuration → Administrative Templates → Windows Components → Remote Desktop Services → Remote Desktop Session Host → Security. The policy is commonly named Require user authentication for remote connections by using Network Level Authentication. Setting it to Disabled permits a temporary non-NLA connection. Domain policy, Intune, or a security baseline may set it back; coordinate with the administrator rather than fighting managed policy.

Refresh and inspect policy when appropriate:

gpupdate /force
gpresult /h "%USERPROFILE%Desktopgpresult.html"
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Repair the cause, then restore NLA

  • VPN or routing: Connect the correct VPN and confirm it routes internal DNS and domain traffic to the relevant site. For a hosted VM, use the provider’s console or recovery path if RDP is unavailable; do not assume it can reach an on-premises domain controller without a working private route or site-to-site VPN. See Google Cloud’s RDP troubleshooting guidance for its VM context.
  • DNS: Set the machine to use the organization’s AD DNS service as directed by its administrator. Confirm the domain’s SRV records and controller names resolve through the connected network.
  • Domain controller: Ask the domain administrator to verify controller health and network paths if discovery or authentication fails for multiple machines.
  • Trust: Have an administrator repair the secure channel using appropriate domain credentials and access. Removing and rejoining a machine to the domain is a possible repair, but should not be an unplanned first step.
  • CredSSP or security update mismatch: If the failure followed an update or produces a CredSSP-specific message, update both client and server and review the organization’s security policy. This is distinct from basic controller reachability; do not weaken CredSSP settings as a generic NLA fix.

Once the underlying issue is fixed, restore the original NLA setting. In the Remote settings dialog, select the NLA-only option again. Or set the registry value back to 1:

reg add "HKLMSYSTEMCurrentControlSetControlTerminal ServerWinStationsRDP-Tcp" /v UserAuthentication /t REG_DWORD /d 1 /f

PowerShell equivalent:

Set-ItemProperty `
  -Path 'HKLM:SYSTEMCurrentControlSetControlTerminal ServerWinStationsRDP-Tcp' `
  -Name UserAuthentication `
  -Type DWord `
  -Value 1

If policy manages the setting, restore it through the authoritative policy rather than relying on a local registry edit. Then test port 3389 and make a normal RDP connection using the intended account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick symptom guide

Symptom Likely area Next check
Connection works after VPN connects Controller or internal DNS is reachable only on the corporate network ipconfig /all, SRV lookup, and nltest /dsgetdc
Target responds on 3389, but NLA fails Authentication path, DNS, Kerberos, or trust Controller discovery, time, secure-channel test, and service reachability
A local account works but a domain account does not Domain authentication or identity configuration Check VPN, DNS, time, and domain trust; local-account success does not prove domain health
NLA turns back on after a policy refresh or reboot Group Policy, Intune, or another management baseline Generate and inspect gpresult; check with the policy administrator
Failure began after a VM snapshot restore Stale computer password or broken secure channel nltest /sc_verify:example.com
Turning off NLA does not help RDP listener, firewall, routing, permissions, or service issue Test port 3389, inspect firewall and services, and review Terminal Services logs

A local account can sometimes help distinguish a domain-authentication problem, using .localuser or COMPUTERNAMElocaluser as the username. It is not guaranteed to work: RDP rights, host policy, and configuration still apply. For Remote Desktop Services deployments, RD Gateway connections, and direct RDP, the network path and authentication flow differ; diagnose the actual topology before changing firewall rules.

Quick Recap

Bestseller No. 1
Bestseller No. 2
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$309.00
Bestseller No. 3
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$249.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.