Troubleshooting: Domain Account Logon Error (Security Policies / DisplayLastLogonInfo)

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All (setting introduced in SecureAuth version 6.4)
     
     

    Overview

    When a user attempts to log on to the SecureAuth appliance console, or via RDP, using a domain account, they see the error: "Security Policies on this computer are set to display information about the last interactive logon. Windows could not retrieve this information. Please contact your network administrator for assistance."

     

    Cause

    A Group Policy has been applied to the SecureAuth appliance that conflicts with a local security policy setting on the appliance. This setting, DisplayLastLogonInfo, was updated in SecureAuth version 6.4, but earlier versions could also be affected.

     

    Resolution:

    Disable the Local Security Policy setting so the Group Policy setting can take effect. Two approaches are available.

    Approach 1 (Recommended): Using the Local Group Policy Editor

    1. Open the Local Group Policy Editor on the SecureAuth appliance.
    2. In the left pane, click Computer Configuration, then Administrative Templates, then Windows Components, then Windows Logon Options.
    3. In the right pane, right-click Display information about previous logons during user logon and click Properties.
    4. Set the option to Disabled and click OK.
    5. Close the Local Group Policy Editor.

    Approach 2: Using the Registry Editor

    1. Open the Start menu, type regedit in the search box, and press Enter.
    2. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System.
    3. In the right pane, right-click in an empty area, then click New, then DWORD (32-bit) Value.
    4. Name it DisplayLastLogonInfo and press Enter.
    5. Right-click DisplayLastLogonInfo and click Modify.
    6. Set the value to 0 to stop displaying last logon information, or 1 to display it, and click OK.
    7. Close the Registry Editor.
    8. Restart the computer to apply the changes.




    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.