NDES Service Account Installation Failure – Interactive Logon Policy Conflict

Sreeram Raju 40 Reputation points
2026-09-22T07:12:18.9+00:00

We are encountering an installation failure while deploying the NDES role using a dedicated service account. The configuration fails with the error: "Logon Failure: the user has not been granted the requested logon type at this computer"

Our security standards mandate that service accounts belong to PG-Deny logon locally SVC, which blocks interactive logon. We verified that removing the service account from this deny group allows the setup to succeed. However, our security team cannot approve permanent interactive logon permissions for service accounts due to compliance risks.

Could you please clarify:

  • The exact logon rights required by the NDES service account both during installation and at runtime ?
  • Supported hardening workarounds or procedural steps to install NDES without granting permanent interactive logon rights to the service account?
Microsoft Security | Intune | Configuration
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.