This can occur if the Everyone group was removed from 'Access this computer from the network' User Rights Assignment setting in the Default Domain Controllers Group Policy or if the 'Deny Access to this computer from the network' setting has been defined.
Modify the Default Domain Controllers Group Policy by adding the Everyone group, or the DSRM account you specify in the FR project, to the 'Access this computer from the network' setting:
- Open gpmc.msc
- Right click the Default Domain Controllers Policy and click Edit
- Expand Policies | Windows Settings | Security Settings | Local Policy
- Click User Rights Assignment
- In the right hand pane confirm that 'Access this computer from the network' contains the Everyone group (or the DSRM account) and that 'Deny Access to this computer from the network' is not defined
To test that the DSRM account can access the DC from the network:
- Reboot the DC into DSRM
- From the FR Console server, open the Windows Event Viewer
- Right click the top Event Viewer node and select Connect to Another Computer
- Enter the name of the DC that was booted into DSRM
- Check Connect as another user
- Click Set User
- Enter the DSRM account as servername\administrator and provide the password
- If the DSRM account can access the DC from the network the event viewer should load the events from the DC