Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Free Fix 0x6BA

Error 0x6BA during domain join: RPC and the endpoint mapper are blocked

10 min read Updated October 4, 2026 Windows Server: AD, DNS & Group Policy

Fix it now

0x6BA is Windows error 1722, RPC_S_SERVER_UNAVAILABLE, “The RPC server is unavailable”. The client found a domain controller, so DNS worked, and then could not open the remote procedure call conversation the join runs over. Credentials are never evaluated, which is why nothing tells you whether the password was right.

Run these from the failing client’s own subnet

Test-NetConnection dc01.corp.example.com -Port 135
Test-NetConnection dc01.corp.example.com -Port 445
Test-NetConnection dc01.corp.example.com -Port 389
portqry -n dc01.corp.example.com -e 135
  1. If 135 does not answer, the endpoint mapper is filtered or the domain controller is unreachable. Stop there and take it to the network team.
  2. If 135 answers and the join still fails, the RPC dynamic range is the usual reason. Microsoft documents the default range on Windows Server 2008 and later as 49152 to 65535, and that whole range has to be reachable from the client subnet.
  3. On the domain controller, confirm it is serving: dcdiag /test:Advertising. Microsoft notes this fails if Netlogon has stopped.
  4. Retry with Add-Computer -DomainName corp.example.com -Credential (Get-Credential) -Restart, and if it fails again read C:\Windows\debug\NetSetup.LOG, which names the operation rather than just the code.

Microsoft’s own note on the advertising test is worth knowing: with TCP and UDP 88 blocked, the test still passes even though the domain controller cannot answer Kerberos requests. A pass is not proof the path is clear.

If the join completes, you are done. If not, the next section explains what a join needs beyond port 389 and which of the four codes you have.

Why it happens

A domain join is not one conversation but several. The client locates a domain controller over DNS, binds to LDAP to read the naming information, then does the real work over remote procedure calls: creating or claiming the computer object and setting its password. Those calls travel either over named pipes on SMB or directly over TCP, and the TCP path begins by asking the endpoint mapper on port 135 which port a given interface is listening on.

That second port is allocated dynamically. Microsoft documents the default dynamic range on Windows Server 2008 and later as 49152 to 65535. A firewall configured with the obvious ports – 88, 135, 389 and 445 – but not that range gets the client as far as the endpoint mapper and no further. It is the commonest reason for 1722 on networks where somebody has already opened what they believe are the Active Directory ports.

Microsoft’s dedicated page for 1722 is blunt about what it means: a lower-layer protocol reported a connectivity failure, and the common case is that the abstract TCP connect operation failed. The causes it lists are link-local failure, DHCP failure, DNS failure, WINS failure, routing failure including blocked ports on firewalls, IPSec or network authentication failure, resource limitations, and the higher-layer protocol not running. Every one of those is a network or service condition. None of them is a credential.

The neighbouring codes say what answered. 1753, EPT_S_NOT_REGISTERED, is published as “There are no more endpoints available from the endpoint mapper”: something answered on 135 and had nothing to offer, which points at a service that is not running or a domain controller that has not finished promoting. 1723 is the server reporting it is too busy. 1460 is a plain timeout, and on a wide area link that usually means packets are being dropped silently rather than actively refused.

The RPC dynamic port range is blocked

You have this one if Port 135 is reachable, the error persists, and the same join succeeds from a machine on the domain controller’s own subnet.

  1. Have TCP 49152 through 65535 opened from the client subnets to the domain controllers.
  2. If that is unacceptable, narrow the range on the domain controllers first with netsh int ipv4 set dynamicport tcp start=<number> num=<range>.
  3. Read back what is actually configured with netsh int ipv4 show dynamicport tcp on each DC before anyone writes a firewall rule.
  4. Restart the domain controllers so the new range takes effect, then retry.

The dynamic range is shared by every RPC service on the machine, not only Active Directory. Narrow it too far and something unrelated stops working weeks later, with no obvious connection to this change.

A host firewall on one end

You have this one if The join succeeds during a controlled test with the local firewall profile relaxed and fails again as soon as it is restored.

  1. On the domain controller, enable the inbound rules that cover the documented Active Directory port set and SMB on the Domain profile.
  2. Check for a third-party endpoint protection product with its own firewall on either machine.
  3. Confirm which network profile the client is applying before the join, since a machine that has classified the network as public may be filtering outbound RPC.

An access list that permits only the well-known ports

You have this one if Joins work on the corporate LAN and fail from a DMZ, a branch office or a segmented build VLAN.

  1. Give the network team Microsoft’s full port list rather than the three or four they will otherwise assume.
  2. If the segment cannot be opened, provision the computer account in advance and complete the join offline.
  3. For build networks, consider staging on a VLAN that does have the path and moving the machine afterwards.

The domain controller is not serving

You have this one if Error 1753 from the endpoint mapper, or the DC answers a ping and never an Active Directory request.

  1. Run dcdiag /test:Advertising on the DC. Microsoft documents it as checking whether the server advertises itself in the roles it should perform, and notes it fails if Netlogon has stopped.
  2. Run dcdiag /test:NetLogons to confirm the SYSVOL and NETLOGON shares are actually readable.
  3. Confirm the RPC, Net Logon and directory services are running.
  4. Point the client at a different domain controller to establish whether the fault is local to that server.

Full reference

What the four codes mean

Code Decimal Symbolic name Microsoft’s published text
0x6BA 1722 RPC_S_SERVER_UNAVAILABLE The RPC server is unavailable
0x6D9 1753 EPT_S_NOT_REGISTERED There are no more endpoints available from the endpoint mapper
0x5B4 1460 ERROR_TIMEOUT This operation returned because the timeout period expired
0x6BB 1723 RPC_S_SERVER_TOO_BUSY The RPC server is too busy to complete this operation

The port set, from Microsoft’s own table

Port Protocol Service
53 TCP and UDP DNS
88 TCP and UDP Kerberos
135 TCP RPC endpoint mapper
389 TCP and UDP LDAP
445 TCP SMB
464 TCP and UDP Kerberos password change
3268 and 3269 TCP Global catalog, plain and over TLS
49152 to 65535 TCP RPC randomly allocated high ports

Microsoft’s own diagnostic sequence for 1722

  1. Check name resolution first: dcdiag /test:DNS /v /e /f:<filename.log> and nltest /dsgetdc:<domain>.
  2. Prove the endpoint mapper is reachable: portqry -n <server> -e 135.
  3. Prove the allocated port is reachable. Microsoft’s older guidance queried 1024-5000; on current Windows Server the equivalent question is about 49152 to 65535.
  4. Check replication and directory health with repadmin /replsummary, repadmin /showrepl and dcdiag.
  5. Only then start changing firewall configuration, because a change made before the sequence is a guess.

Narrowing the dynamic range without breaking something else

Command What it does
netsh int ipv4 show dynamicport tcp Reports the range in force on this machine
netsh int ipv4 set dynamicport tcp start=<number> num=<range> Sets the start port and the size of the range

Apply the same range to every domain controller and restart them, because a client that reaches one DC on a permitted port and another on a blocked one produces failures that look random. Leave room: the range serves every RPC service on the server, not only the directory, and the symptoms of running out are not obviously related to the change that caused them.

When the join has to happen and the path will not open

Offline provisioning exists for this exact case. The computer account is created in advance from a machine that does have the path, the resulting provisioning data is carried to the client, and the client completes the join without ever contacting a domain controller. It is the supported answer for a segmented build network, and it removes both DNS and RPC from the problem rather than working around them.

Reading the join log

C:\Windows\debug\NetSetup.LOG records each step of a join with its status. It is the difference between knowing that the join failed with 1722 and knowing which call failed with 1722, and it costs nothing to read. If the log shows the failure at the point of creating or renaming the computer object rather than at the locator stage, you are looking at RPC and not at DNS, which is what this article is about.

Every code this article covers

Code What it points at Source
0x6BA Windows error 1722, RPC_S_SERVER_UNAVAILABLE: the RPC server is unavailable. Microsoft attributes it to a lower-layer connectivity failure, typically a failed TCP connect Microsoft Learn
0x6D9 Windows error 1753, EPT_S_NOT_REGISTERED: there are no more endpoints available from the endpoint mapper Microsoft Learn
0x5B4 Windows error 1460, ERROR_TIMEOUT: the operation returned because the timeout period expired Microsoft Learn
0x6BB Windows error 1723, RPC_S_SERVER_TOO_BUSY: the RPC server is too busy to complete this operation Microsoft Learn

Confirm the fix worked

  1. Test-NetConnection <dc> -Port 135 returns true from the client’s own subnet.
  2. A test to a port inside the dynamic range on the same domain controller also succeeds.
  3. The join completes and the computer object appears in the organisational unit you targeted.
  4. dcdiag /test:Advertising passes on the domain controller the client used.
  5. gpupdate /force on the newly joined machine completes without errors.

Questions people ask about this

Can I get away with opening only 445?

Some join traffic travels over SMB named pipes, which is why a partial port set occasionally appears to work and then fails at the next step. It is not a configuration to rely on. Open the documented set, or provision the machine offline.

Can I narrow the RPC dynamic range?

Yes, with netsh int ipv4 set dynamicport tcp start=<number> num=<range> on each domain controller. Apply the same range everywhere, restart the servers, and leave headroom, because the range serves every RPC service on the machine.

Does this error mean my credentials are wrong?

No. The join failed before credentials were evaluated. A credential rejection produces a different code entirely.

dcdiag says the DC is advertising, so why does the join fail?

Microsoft notes that the advertising test still passes when TCP and UDP 88 are blocked on a firewall, even though the domain controller cannot then answer Kerberos ticket requests. Advertising tells you the server believes it is serving; it does not tell you the client can reach it.

What does it cost to fix?

Nothing. Every diagnostic here ships with Windows or the remote administration tools, and the remedy is a firewall rule or a service that needs starting.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix Event ID 1058: Windows cannot access gpt.ini for a Group Policy object Free Fix Event ID 7016: a Group Policy client-side extension never finishes processing Free Fix Event ID 4013: the DNS server is waiting for Active Directory to synchronise License Error Error 8606 lingering objects: clearing stale AD data that blocks replication
โ† Back to Knowledge Base