Remote Desktop Connection (RDP) is a great tool in Windows 11 and Windows 10 that lets you use a computer from another place. But sometimes, you might get a message saying “A user account restriction (for example, a time-of-day restriction) is preventing you from logging on. For assistance, contact your system administrator or technical support.” We’re here to help fix this issue, focusing first on making sure the user account has a password, turning off checks for blank passwords, and then looking at other ways to solve the problem.
Also see: Windows 11 Remote Desktop “An authentication error has occurred”
Page Contents
Fixing “A user account restriction” error in Remote Desktop
1. Setting a password for the user account
Not having a password on your account is a common reason for RDP errors about user account restrictions. RDP has a safety feature that usually stops remote access to accounts without passwords.
How to set a password for the user:
- Hit the Windows key or click the Start button.
- Search for “Computer Management” and open it from the results.
- In Computer Management, go to the System Tools section.
- Click on Local Users and Groups and then on Users.
- Right-click the user account you’re working on and pick Set Password.
- After reading the warning, click Proceed, then type and confirm the new password, and hit OK.
By giving all accounts a password, you not only fix the RDP issue but also make your system more secure.
Related resource: Disable Network Level Authentication in Windows 11 or 10
2. Allow blank passwords for Remote Desktop Connection
If you need to let RDP connections use accounts without passwords, you can turn off the blank password check. You can do this through the Local Group Policy Editor or the Registry Editor. Just know that this makes your system less secure.
Using local group policy editor:
- Press Windows + R, type
gpedit.msc
, and press Enter to open the Local Group Policy Editor. - Go to Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options.
- Find the policy “Accounts: Limit local account use of blank passwords to console logon only” and open it.
- Set it to Disabled.
- Hit OK and close the Local Group Policy Editor.
- To make the changes work right away, open Command Prompt and type
gpupdate /force
and press Enter.
Using registry editor:
- Press Windows + R, type
regedit
, and press Enter to open the Registry Editor. - Go to HKEY_LOCAL_MACHINE > SYSTEM > CurrentControlSet > Control > Lsa.
- Look for the DWORD LimitBlankPasswordUse. If it’s not there, right-click, choose New > DWORD (32-bit) Value, and name it LimitBlankPasswordUse.
- Double-click on LimitBlankPasswordUse and change its value to 0.
- Close the Registry Editor and restart your PC to see the changes.
Note: Always back up your registry before making changes. Wrong changes can cause problems or make your system unstable.
Pro tip: How to Open an RDP Connection via CMD in Windows 11
3. Time-of-day restrictions
Sometimes, admins limit when certain users can log in. If you’re trying to get in at a time you’re not allowed, you’ll see the “A user account restriction” RDP error. Setting login hours is usually done for domain user accounts with Active Directory.
How to check and modify login hours:
- Open Active Directory Users and Computers.
- Find the user’s account, right-click it, and go to Properties.
- Click on Logon Hours to see or change when they can log in.
4. Account is locked out
If someone tries and fails to log in too many times, the account gets locked for safety.
How to address account lockout:
- On the Remote Computer:
- Press Windows + R, type
lusrmgr.msc
, and press Enter to open Local Users and Groups. - Click on Users, then double-click the account in question.
- Make sure the Account is locked out option is not checked.
- Press Windows + R, type
- On a Domain Controller:
- Open Active Directory Users and Computers.
- Right-click the user’s account and go to Properties.
- Under the Account tab, ensure the Account is locked out option is not checked.
Related guide: How to Remote Desktop Over The Internet in Windows 11
5. Group policy restrictions
Group Policy settings might be stopping RDP access for the user or the computer.
How to check group policy settings:
- Open
gpedit.msc
for the Local Group Policy Editor. - Head to Computer Configuration > Windows Settings > Security Settings > Local Policies > User Rights Assignment.
- Look for policies like “Deny log on through Remote Desktop Services” and make sure the user isn’t listed.
- If you find the user listed, remove them to allow RDP access.
6. Password complexity requirements
Windows might need passwords to be really strong. If the account’s password isn’t tough enough, RDP might not work.
How to check password policies:
- Press Windows + R, type
gpedit.msc
, and hit Enter to open the Local Group Policy Editor. - Go to Computer Configuration > Windows Settings > Security Settings > Account Policies > Password Policy.
- Check out the policies, like “Password must meet complexity requirements.” If it’s on, passwords need to have uppercase and lowercase letters, numbers, and symbols.
In short
Getting the error “A user account restriction (for example, a time-of-day restriction) is preventing you from logging on. For assistance, contact your system administrator or technical support” usually means you need to set a password for the account or allow RDP logins without passwords. This often fixes the main problem, especially if you’re not using a domain.
But in a domain, the issue might be due to time-of-day limits, Group Policy settings, or specific user rights. Make sure to look into each possible cause.