The Remote Computer requires network-level authentication

When Remote Desktop displays “The remote computer requires Network Level Authentication (NLA), but your domain controller cannot be contacted,” the problem is usually that the computer cannot complete domain authentication. NLA adds an important layer of protection by authenticating a user before a remote session is created. Keep NLA enabled while you troubleshoot whenever possible.

Check domain and network connectivity

First confirm that the affected computer can reach a healthy domain controller and resolve the domain correctly. Verify its DNS configuration, network or VPN connection, and system time. If the computer has lost its Active Directory secure channel, repair that relationship using your organization’s standard process. For an Azure VM, Microsoft also recommends checking the VM-to-domain-controller connection, the machine account password, and domain-controller health.

Verify the account is allowed to use Remote Desktop

Confirm that the user is a member of Remote Desktop Users or another authorized group, and that effective Group Policy grants the required Remote Desktop logon rights. Check for conflicting allow and deny policies. Microsoft documents a related sign-in failure when group membership or the “Access this computer from the network” user right is missing.

Use a controlled recovery path

If remote access is unavailable, use an approved console, hypervisor, cloud recovery, or local-administrator access path to diagnose the machine. Disabling NLA reduces protection and should not be the default fix. If an administrator must disable it temporarily as an emergency recovery workaround, restrict access to a trusted network, restore NLA as soon as the underlying issue is fixed, and verify the policy that caused the problem so it does not recur.

For Azure virtual machines, see Microsoft’s RDP authentication troubleshooting guide. For Windows Server, see Microsoft’s guidance on user authentication and Remote Desktop logon rights. Follow your organization’s change-control process before modifying domain policy or remote-access settings.

Windows Remote Desktop Network Level Authentication settings