Consider the following scenario:
- You work on a Windows Vista-based computer that is a member of a workgroup.
- From this computer, you try to access an administrative share that is located on another Windows Vista-based computer.
- The computer that you try to access is a member of a workgroup or a member of a domain. For example, you try to access the C$ administrative share.
- When you are prompted for your user credentials, you provide the user credentials of an administrative user account on the destination computer.
In this scenario, you receive the following error message:
Windows is unable to log you on.
Make sure that your user name and password are correct.
If you try to map a network drive to the administrative share by using the Net Use
command, you receive the following error message after you provide the correct credentials:
System error 5
Access is denied.
By default, Windows Vista and newer versions of Windows prevent local accounts from accessing administrative shares through the network.
To let users have access, we recommend that you create shares on the Windows Vista-based computer by using the appropriate permissions. If, for some reason, you cannot apply this resolution, you might want to try the workaround
To share a folder on a Windows Vista-based computer that has file sharing enabled, follow these steps:
- Click Start
, and then click Computer.
Collapse this imageExpand this image
- Locate the folder that you want to share.
- Right-click the folder that you want to share, and then click Share.
- If you have password protected sharing enabled, select which users can access the shared folder and their permission level. To let all users have access, select Everyone in the list of users. By default, the permission level is "Reader." Users who have this permission level cannot change files or create new files in the share. To let a user change files, change folders, create new files, and create new folders, use the "Co-owner" permission level.
If you have password protected sharing disabled, select the Guest account or the Everyone account. This is the same as simple sharing in Windows XP.
- Click Share, and then click Done.
To allow administrative share access in a workgroup for Windows, use the following workaround. To have us perform this workaround for you, go to the "Fix it for me"
section. If you would rather do this yourself, go to the "Let me fix it myself"
Fix it for me
To perform this workaround automatically, click the Fix this problem
link. Next, click Run
in the File Download
dialog box, and then follow the steps in this wizard.
this wizard may be in English only; however, the automatic fix also works for other language versions of Windows.
If you are not using the computer that has the problem, you can save the automatic fix to a flash drive or to a CD, and then you can run it on the computer that has the problem.
Now go to the "Did this fix the problem?"
Let me fix it myselfImportant
This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:
How to back up and restore the registry in Windows
- Click Start
, type regedit in the Start Search box, and then press ENTER.
Collapse this imageExpand this image
If you are prompted for an administrator password or for confirmation, type the password or provide confirmation.
- Locate and then click the following registry subkey:
- On the Edit menu, point to New, and then click DWORD (32-bit) Value.
- Type LocalAccountTokenFilterPolicy to name the new entry, and then press ENTER.
- Right-click LocalAccountTokenFilterPolicy, and then click Modify.
- In the Value data box, type 1, and then click OK.
- Exit Registry Editor.
The LocalAccountTokenFilterPolicy entry in the registry can have a value of 0 or 1. These values set the behavior of the entry as follows:
- 0 = build a filtered token
This is the default value. The administrator credentials are removed. These credentials are required for remote administration of the print drivers.
- 1 = build an elevated token
This value enables the remote administration of the print drivers on a server within a workgroup.
Check whether the problem is fixed. If it is fixed, you are finished with this article. If it is not fixed, you can contact support.
This behavior is by design.
When the destination Windows Vista-based computer and the computer from which you want to access the administrative share are on the same domain, you can access the share by using domain administrator credentials.
You cannot access this administrative share if the destination Windows Vista-based computer is joined to a domain and you try to connect to it by using a computer that is joined to a workgroup. This is true even if you supply correct domain administrator credentials for the domain where the destination computer is located.
For more information about how to share folders or printers in Windows Vista, visit the following Microsoft Web site:
Article ID: 947232 - Last Review: September 23, 2011 - Revision: 4.0
- Windows Vista Enterprise 64-bit Edition
- Windows Vista Ultimate 64-bit Edition
- Windows Vista Enterprise
- Windows Vista Ultimate
- Windows Vista Home Basic 64-bit Edition
- Windows Vista Home Premium 64-bit Edition
- Windows Vista Business
- Windows Vista Business 64-bit Edition
- Windows Vista Home Basic
- Windows Vista Home Premium
|kbmsifixme kbfixme kbexpertiseadvanced kbtshoot kbprb KB947232|