Fix it now
0x6BA is Windows error 1722, RPC_S_SERVER_UNAVAILABLE, “The RPC server is unavailable”. The client found a domain controller, so DNS worked, and then could not open the remote procedure call conversation the join runs over. Credentials are never evaluated, which is why nothing tells you whether the password was right.
Test-NetConnection dc01.corp.example.com -Port 135
Test-NetConnection dc01.corp.example.com -Port 445
Test-NetConnection dc01.corp.example.com -Port 389
portqry -n dc01.corp.example.com -e 135
- If 135 does not answer, the endpoint mapper is filtered or the domain controller is unreachable. Stop there and take it to the network team.
- If 135 answers and the join still fails, the RPC dynamic range is the usual reason. Microsoft documents the default range on Windows Server 2008 and later as 49152 to 65535, and that whole range has to be reachable from the client subnet.
- On the domain controller, confirm it is serving:
dcdiag /test:Advertising. Microsoft notes this fails if Netlogon has stopped. - Retry with
Add-Computer -DomainName corp.example.com -Credential (Get-Credential) -Restart, and if it fails again readC:\Windows\debug\NetSetup.LOG, which names the operation rather than just the code.
Microsoft’s own note on the advertising test is worth knowing: with TCP and UDP 88 blocked, the test still passes even though the domain controller cannot answer Kerberos requests. A pass is not proof the path is clear.
If the join completes, you are done. If not, the next section explains what a join needs beyond port 389 and which of the four codes you have.
Why it happens
A domain join is not one conversation but several. The client locates a domain controller over DNS, binds to LDAP to read the naming information, then does the real work over remote procedure calls: creating or claiming the computer object and setting its password. Those calls travel either over named pipes on SMB or directly over TCP, and the TCP path begins by asking the endpoint mapper on port 135 which port a given interface is listening on.
That second port is allocated dynamically. Microsoft documents the default dynamic range on Windows Server 2008 and later as 49152 to 65535. A firewall configured with the obvious ports – 88, 135, 389 and 445 – but not that range gets the client as far as the endpoint mapper and no further. It is the commonest reason for 1722 on networks where somebody has already opened what they believe are the Active Directory ports.
Microsoft’s dedicated page for 1722 is blunt about what it means: a lower-layer protocol reported a connectivity failure, and the common case is that the abstract TCP connect operation failed. The causes it lists are link-local failure, DHCP failure, DNS failure, WINS failure, routing failure including blocked ports on firewalls, IPSec or network authentication failure, resource limitations, and the higher-layer protocol not running. Every one of those is a network or service condition. None of them is a credential.
The neighbouring codes say what answered. 1753, EPT_S_NOT_REGISTERED, is published as “There are no more endpoints available from the endpoint mapper”: something answered on 135 and had nothing to offer, which points at a service that is not running or a domain controller that has not finished promoting. 1723 is the server reporting it is too busy. 1460 is a plain timeout, and on a wide area link that usually means packets are being dropped silently rather than actively refused.
The RPC dynamic port range is blocked
You have this one if Port 135 is reachable, the error persists, and the same join succeeds from a machine on the domain controller’s own subnet.
- Have TCP 49152 through 65535 opened from the client subnets to the domain controllers.
- If that is unacceptable, narrow the range on the domain controllers first with
netsh int ipv4 set dynamicport tcp start=<number> num=<range>. - Read back what is actually configured with
netsh int ipv4 show dynamicport tcpon each DC before anyone writes a firewall rule. - Restart the domain controllers so the new range takes effect, then retry.
The dynamic range is shared by every RPC service on the machine, not only Active Directory. Narrow it too far and something unrelated stops working weeks later, with no obvious connection to this change.
A host firewall on one end
You have this one if The join succeeds during a controlled test with the local firewall profile relaxed and fails again as soon as it is restored.
- On the domain controller, enable the inbound rules that cover the documented Active Directory port set and SMB on the Domain profile.
- Check for a third-party endpoint protection product with its own firewall on either machine.
- Confirm which network profile the client is applying before the join, since a machine that has classified the network as public may be filtering outbound RPC.
An access list that permits only the well-known ports
You have this one if Joins work on the corporate LAN and fail from a DMZ, a branch office or a segmented build VLAN.
- Give the network team Microsoft’s full port list rather than the three or four they will otherwise assume.
- If the segment cannot be opened, provision the computer account in advance and complete the join offline.
- For build networks, consider staging on a VLAN that does have the path and moving the machine afterwards.
The domain controller is not serving
You have this one if Error 1753 from the endpoint mapper, or the DC answers a ping and never an Active Directory request.
- Run
dcdiag /test:Advertisingon the DC. Microsoft documents it as checking whether the server advertises itself in the roles it should perform, and notes it fails if Netlogon has stopped. - Run
dcdiag /test:NetLogonsto confirm the SYSVOL and NETLOGON shares are actually readable. - Confirm the RPC, Net Logon and directory services are running.
- Point the client at a different domain controller to establish whether the fault is local to that server.
Full reference
What the four codes mean
| Code | Decimal | Symbolic name | Microsoft’s published text |
|---|---|---|---|
0x6BA |
1722 | RPC_S_SERVER_UNAVAILABLE | The RPC server is unavailable |
0x6D9 |
1753 | EPT_S_NOT_REGISTERED | There are no more endpoints available from the endpoint mapper |
0x5B4 |
1460 | ERROR_TIMEOUT | This operation returned because the timeout period expired |
0x6BB |
1723 | RPC_S_SERVER_TOO_BUSY | The RPC server is too busy to complete this operation |
The port set, from Microsoft’s own table
| Port | Protocol | Service |
|---|---|---|
| 53 | TCP and UDP | DNS |
| 88 | TCP and UDP | Kerberos |
| 135 | TCP | RPC endpoint mapper |
| 389 | TCP and UDP | LDAP |
| 445 | TCP | SMB |
| 464 | TCP and UDP | Kerberos password change |
| 3268 and 3269 | TCP | Global catalog, plain and over TLS |
| 49152 to 65535 | TCP | RPC randomly allocated high ports |
Microsoft’s own diagnostic sequence for 1722
- Check name resolution first:
dcdiag /test:DNS /v /e /f:<filename.log>andnltest /dsgetdc:<domain>. - Prove the endpoint mapper is reachable:
portqry -n <server> -e 135. - Prove the allocated port is reachable. Microsoft’s older guidance queried 1024-5000; on current Windows Server the equivalent question is about 49152 to 65535.
- Check replication and directory health with
repadmin /replsummary,repadmin /showreplanddcdiag. - Only then start changing firewall configuration, because a change made before the sequence is a guess.
Narrowing the dynamic range without breaking something else
| Command | What it does |
|---|---|
netsh int ipv4 show dynamicport tcp |
Reports the range in force on this machine |
netsh int ipv4 set dynamicport tcp start=<number> num=<range> |
Sets the start port and the size of the range |
Apply the same range to every domain controller and restart them, because a client that reaches one DC on a permitted port and another on a blocked one produces failures that look random. Leave room: the range serves every RPC service on the server, not only the directory, and the symptoms of running out are not obviously related to the change that caused them.
When the join has to happen and the path will not open
Offline provisioning exists for this exact case. The computer account is created in advance from a machine that does have the path, the resulting provisioning data is carried to the client, and the client completes the join without ever contacting a domain controller. It is the supported answer for a segmented build network, and it removes both DNS and RPC from the problem rather than working around them.
Reading the join log
C:\Windows\debug\NetSetup.LOG records each step of a join with its status. It is the difference between knowing that the join failed with 1722 and knowing which call failed with 1722, and it costs nothing to read. If the log shows the failure at the point of creating or renaming the computer object rather than at the locator stage, you are looking at RPC and not at DNS, which is what this article is about.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0x6BA |
Windows error 1722, RPC_S_SERVER_UNAVAILABLE: the RPC server is unavailable. Microsoft attributes it to a lower-layer connectivity failure, typically a failed TCP connect | Microsoft Learn |
0x6D9 |
Windows error 1753, EPT_S_NOT_REGISTERED: there are no more endpoints available from the endpoint mapper | Microsoft Learn |
0x5B4 |
Windows error 1460, ERROR_TIMEOUT: the operation returned because the timeout period expired | Microsoft Learn |
0x6BB |
Windows error 1723, RPC_S_SERVER_TOO_BUSY: the RPC server is too busy to complete this operation | Microsoft Learn |
Confirm the fix worked
Test-NetConnection <dc> -Port 135returns true from the client’s own subnet.- A test to a port inside the dynamic range on the same domain controller also succeeds.
- The join completes and the computer object appears in the organisational unit you targeted.
dcdiag /test:Advertisingpasses on the domain controller the client used.gpupdate /forceon the newly joined machine completes without errors.
Questions people ask about this
Can I get away with opening only 445?
Some join traffic travels over SMB named pipes, which is why a partial port set occasionally appears to work and then fails at the next step. It is not a configuration to rely on. Open the documented set, or provision the machine offline.
Can I narrow the RPC dynamic range?
Yes, with netsh int ipv4 set dynamicport tcp start=<number> num=<range> on each domain controller. Apply the same range everywhere, restart the servers, and leave headroom, because the range serves every RPC service on the machine.
Does this error mean my credentials are wrong?
No. The join failed before credentials were evaluated. A credential rejection produces a different code entirely.
dcdiag says the DC is advertising, so why does the join fail?
Microsoft notes that the advertising test still passes when TCP and UDP 88 are blocked on a firewall, even though the domain controller cannot then answer Kerberos ticket requests. Advertising tells you the server believes it is serving; it does not tell you the client can reach it.
What does it cost to fix?
Nothing. Every diagnostic here ships with Windows or the remote administration tools, and the remedy is a firewall rule or a service that needs starting.
