Fix it now
0x52E is Windows error 1326, which Microsoft publishes as “The user name or password is incorrect”. On a domain join it is often exactly that, and three near misses produce the same refusal: an unqualified account name, an account with no right to create an object in the organisational unit you named, and a clock too far out for Kerberos.
w32tm /query /status
nltest /dsgetdc:corp.example.com
Add-Computer -DomainName corp.example.com -OUPath "OU=Workstations,DC=corp,DC=example,DC=com" -Credential (Get-Credential) -Restart
- Enter the account in a qualified form:
admin@corp.example.comorCORP\admin. On a machine that is not yet a member, an unqualified name is looked up locally first. - Check the clock. Microsoft’s own domain controller security test treats a skew of 300 seconds or more between two machines as fatal to Kerberos, so an offset near that is enough to produce an instant rejection.
- If the credentials are good, the problem is rights on the destination container. Delegate the right to create computer objects on that organisational unit and retry with
-OUPathnaming it. - If the failure follows one account rather than one machine, read the next article along: the machine account quota produces a different code but the same shape of complaint.
Add-Computer is a Windows PowerShell 5.1 cmdlet. In PowerShell 7 it will not be recognised, which reads like a different failure than it is.
If the object appears in the organisational unit you targeted and a domain user signs in, you are done. If not, the next section separates the failures that share this code.
Why it happens
The join API authenticates the credentials you supply against a domain controller, then uses that identity to create or take over a computer object. A wrong password fails at the first stage and produces 1326. On the domain controller’s Security log the same failure appears as event 4625 with a Status or Sub Status of 0xC000006A, which Microsoft’s own monitoring guidance reads as a user logon with a misspelled or bad password. If you can see that pair, the password really is wrong and nothing else in this article applies.
The second case is an account that authenticates perfectly and is not permitted to create an object where you asked. Because that happens inside the same call, the failure can surface as a credential rejection rather than as an access denial. The distinguishing test is whether the same credentials work against the domain controller for something else. If they do, the password is right and the problem is delegation.
The third is time. Kerberos rejects a ticket whose timestamp falls outside the tolerance, and the symptom is a rejection that arrives instantly however carefully you retype the password. Microsoft’s dcdiag /test:CheckSecurityError check, run with /ReplSource, tests exactly this: it verifies that the time skew between servers is less than 300 seconds for Kerberos, along with naming context permissions, SYSVOL and NETLOGON connectivity, and the “Access this computer from the network” privilege.
Two neighbouring codes are worth telling apart. 1385, ERROR_LOGON_TYPE_NOT_GRANTED, is published as “Logon failure: the user has not been granted the requested logon type at this computer” – the account is valid and is being refused a particular kind of logon. 1332, ERROR_NONE_MAPPED, is “No mapping between account names and security IDs was done”, which means the name could not be resolved to a security identifier at all: a deleted account, an untrusted domain, or a stale entry in an access control list.
The account name is not qualified
You have this one if You typed a bare user name with no domain part, on a machine still in a workgroup.
- Retype it as
admin@corp.example.comorCORP\admin. - Retry the join.
This is why the same string works after the join and not before it. Until the machine is a member, an unqualified name has nowhere to go but the local account database.
The account authenticates and has no rights on the destination organisational unit
You have this one if The same credentials work against the domain controller for other things, and the join fails only when a specific OU is targeted.
- In Active Directory Users and Computers, delegate control on the destination OU and grant the right to create computer objects there.
- Add the right to delete them too if the same account has to handle rebuilds.
- Retry the join with
-OUPathnaming that OU.
Microsoft states that users who have delegated permissions on containers to create and delete computer accounts are not restricted by the machine account quota either, so this one change fixes two different refusals at once.
Clock skew between the client and the domain
You have this one if The rejection appears instantly every time, and w32tm /query /status shows a large offset or a source of Local CMOS Clock.
- Run
w32tm /resyncon the client and recheck the status. - If the client is a virtual machine, stop it taking time from the hypervisor host so the domain hierarchy owns its clock.
- On a domain controller, run
dcdiag /test:CheckSecurityError /ReplSource:<dc>, which checks the skew against the 300-second Kerberos limit directly.
/force is not a parameter of w32tm /resync. The documented parameters are /computer, /nowait, /rediscover and /soft; anything else makes the command print its usage and exit without resynchronising.
The account is locked, disabled, or denied the logon type it needs
You have this one if The directory reports the account locked or disabled, or you see 1385 shortly after a security baseline was applied.
- Unlock or re-enable the account, and find what keeps locking it before you retry.
- For 1385, check the “Access this computer from the network” privilege on the domain controllers. Microsoft’s
dcdiag /test:NetLogonsverifies that Administrators, Authenticated Users and Everyone hold it. - Confirm no enforced domain-level policy is overriding the domain controllers policy.
Full reference
The codes, as Microsoft publishes them
| Code | Decimal | Symbolic name | Published text |
|---|---|---|---|
0x52E |
1326 | ERROR_LOGON_FAILURE | The user name or password is incorrect |
0x569 |
1385 | ERROR_LOGON_TYPE_NOT_GRANTED | Logon failure: the user has not been granted the requested logon type at this computer |
0x534 |
1332 | ERROR_NONE_MAPPED | No mapping between account names and security IDs was done |
0xC000006A |
– | STATUS_WRONG_PASSWORD | Read on event 4625 as a user logon with a misspelled or bad password |
Telling the three failures apart in two minutes
| What you see | What it means |
|---|---|
| Event 4625 on the DC with Sub Status 0xC000006A | The password really is wrong |
| Credentials work elsewhere, join fails only into one OU | Rights on that container |
Instant rejection, large offset in w32tm /query /status |
Clock skew; Kerberos is refusing before anything else happens |
| Error 1332 | The name cannot be resolved to a security identifier at all |
| Error 1385 | The account is valid and is denied that logon type at that computer |
Delegation rather than Domain Admin
The right answer to “this account cannot create the object” is almost never to make the account more powerful. Microsoft documents that members of Administrators and Domain Administrators, and users with delegated permissions on containers to create and delete computer accounts, are exempt from the machine account quota. Delegating on the specific organisational unit where machines land gets you the same practical result as Domain Admin for joins, without giving a deployment account rights over everything else in the directory.
- Open Active Directory Users and Computers and find the OU machines are built into.
- Delegate control to the deployment account or group.
- Grant the right to create computer objects in that folder, and to delete them if rebuilds are part of the job.
- Test with one machine, joined with
-OUPathnaming that OU. - Document which accounts hold the delegation, so that the next person does not raise the machine account quota to work around a rights problem.
Time, and why it is worth checking early
| Command | What it reports |
|---|---|
w32tm /query /status |
The client’s time source and current offset |
w32tm /query /source |
The source alone |
w32tm /resync |
Resynchronises. Documented parameters: /computer, /nowait, /rediscover, /soft |
w32tm /monitor |
Compares clocks across a domain; /domain and /computers select what to look at |
dcdiag /test:CheckSecurityError /ReplSource:<dc> |
Checks skew against the 300-second Kerberos limit, plus permissions and share connectivity |
Do not correct a domain-wide drift by setting the clock on a domain controller by hand. Time flows down the domain hierarchy, so a manually set DC ends up fighting it. Correct the source the hierarchy uses and let the rest follow.
Codes that arrive at the same dialog from somewhere else
- 8557 is the machine account quota refusal: the account has created as many computer objects as it is allowed. Different code, same complaint from the user.
- 8305 means an object with that name already exists in the directory, which is what a rebuild under an old name looks like.
- 1355 means the domain could not be contacted at all, which is a locator problem and not a credential one.
- 1722 means the RPC conversation never opened, so credentials were never evaluated.
Before you conclude the password is wrong
Read the failure on the domain controller rather than on the client. A Security log entry with a Status or Sub Status of 0xC000006A settles the question in one line, and Microsoft’s own guidance is to watch for a run of them against critical or service accounts. If there is no such entry, the domain controller never rejected a password, and whatever failed on the client happened before or after the authentication rather than during it.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x52E |
Windows error 1326, ERROR_LOGON_FAILURE: the user name or password is incorrect | Microsoft Learn |
0x569 |
Windows error 1385, ERROR_LOGON_TYPE_NOT_GRANTED: the user has not been granted the requested logon type at this computer | Microsoft Learn |
0x534 |
Windows error 1332, ERROR_NONE_MAPPED: no mapping between account names and security IDs was done | Microsoft Learn |
0xC000006A |
STATUS_WRONG_PASSWORD. On Security log event 4625 Microsoft reads this Status or Sub Status value as a user logon with a misspelled or bad password | Microsoft Learn |
Confirm the fix worked
- The computer object appears in the organisational unit you targeted, not the default container.
- A domain user signs in at the console of a machine with no cached credentials for them.
w32tm /query /statuson the client shows a small offset against a domain time source.- No new event 4625 with Sub Status 0xC000006A appears on the domain controller for that account.
gpupdate /forcecompletes on the joined machine.
Questions people ask about this
Do I need Domain Admin rights to join a computer?
No, and you should not use them. An account with the right to create computer objects delegated on the destination organisational unit is enough, and Microsoft notes that such accounts are also exempt from the machine account quota.
Why does the join work into one OU and fail into another?
Delegation is applied per container and inherits downward, not sideways. An account delegated on one organisational unit has no rights in its sibling, so the same credentials succeed or fail purely on the container you name.
The password works for logging in but not for joining. Why?
An interactive logon can be served from cached credentials, so it proves nothing about whether a domain controller accepts that password now. It can also be that the password is fine and the real failure is rights.
How far out does the clock have to be?
Microsoft’s own domain controller security check tests that the skew between servers is less than 300 seconds for Kerberos. Treat anything approaching that as the cause and correct it before spending time on anything else.
Does any of this cost anything?
No. Delegation, time synchronisation and account management are all built in, and no licence or edition changes how credentials are evaluated.
