"Authentication Failed or Access denied" message is shown, when trying to add the Server Monitor through WMI mode.

"Authentication Failed or Access denied" message is shown, when trying to add the Server Monitor through WMI mode.

Overview

This article provides troubleshooting steps for Authentication Failed, Access Denied, and related WMI authentication errors encountered while adding a Windows Server Monitor or during data collection through WMI mode in Applications Manager.
These errors are commonly caused by:
  • Incorrect credentials
  • Improper username format
  • Insufficient user privileges
  • DCOM or WMI permission issues
  • Firewall restrictions
  • WMI connectivity failures

Applicable WMI Error Codes

  • 0x80070005 — Access is denied.
  • 0x80041003 — Access denied.

Where to Perform These Steps

⚠️ CRITICAL: Each troubleshooting step must be performed on the correct server as indicated:
    • Applications Manager Server: Steps performed while configuring monitors or testing connectivity
    • Remote Windows Server: Steps performed on the server being monitored or to be monitored to verify configurations
      Each step below clearly indicates where it should be performed. Pay close attention to these indicators to avoid configuration errors.

Troubleshooting Steps

Step 1: Verify the Username Format

📍 Perform on: Applications Manager Server (while configuring or editing the Windows monitor credentials)

      Ensure that the monitoring credentials are specified in the correct format.

      Domain Environment

            If the target server is joined to a domain, specify the username in the following format:

      DOMAIN\Username

            Example:

      CORP\Administrator

            Where:

      • CORP is the domain name
      • Administrator is the username

      Workgroup Environment

          If the target server is part of a workgroup, specify the username in the following format:

      MachineName\Username

          Example:

      WIN-SERVER-01\Administrator
NotesNote: MachineName refers to the computer name of the target Windows server.

To identify the domain or computer name: Navigate toControl Panel  User Accounts  User Accounts

Step 2: Verify Required Windows Services

📍 Perform on: Remote Windows Server (the server being monitored or to be monitored)

      Ensure that the following services are running on the target server.      

InfoRecommendation: Configure their Startup Type as Automatic.

    • Remote Procedure Call (RPC)
    • Remote Procedure Call (RPC) Locator
    • Windows Management Instrumentation (WMI)
    • COM+ Event System
    • Remote Access Auto Connection Manager
    • Remote Access Connection Manager
    • Remote Registry
    • Server
    • Windows Management Instrumentation Driver Extensions
    • WMI Performance Adapter
    • Workstation

Step 3: Verify Firewall Configuration

📍 Perform on: Remote Windows Server

      Open an elevated Command Prompt on the target server and execute the following commands:

netsh advfirewall firewall set rule group="Windows Remote Management" new enable=yes

netsh advfirewall firewall set rule group="Windows Management Instrumentation (WMI)" new enable=yes

netsh advfirewall firewall set rule group="Remote Administration" new enable=yes
      If the following message is displayed:
No rules match the specified criteria
      Execute:
netsh firewall set service remoteadmin enable
      After executing the above command, re-execute the Remote Administration command and try the WMI connectivity test.

Step 4: Verify WMI Connectivity Using WBEMTEST

📍 Perform on: Applications Manager Server

This verifies that the Applications Manager server can establish a remote WMI connection to the target server.

    1. Open WBEMTEST
    2. Click Connect
    3. Enter the namespace:
      \\hostname\root\cimv2
    4. Enter the monitoring credentials
    5. Click Connect
      If the connection fails using the hostname:
    • Retry using: \\ipaddress\root\cimv2
      If the connection succeeds only with the IP address:
    • Verify DNS resolution
    • Remove incorrect entries from: C:\Windows\System32\drivers\etc\hosts
    • Retry using the hostname

Error-Specific Guidance

      Error Code: 0x80070005 (Access Denied)

      Error Code: 0x80041003 (Access Denied)


Step 5: Verify DCOM Configuration

    1. Open: dcomcnfg
    2. Navigate to: Component Services → Computers
    3. Right-click My Computer and select Properties

      Default Properties

            Verify that:
      • ✓ Enable Distributed COM on this computer is enabled
      • ✓ Default Authentication Level is set to Connect
      • ✓ Default Impersonation Level is set to Impersonate or Identify

      COM Security

      Under Access Permissions → Edit Limits:
            Verify that the monitoring user (or its grouphas:
      • ✓ Local Access
      • ✓ Remote Access
      Under Launch and Activation Permissions → Edit Limits:
            Verify that the monitoring user (or its grouphas:
      • ✓ Local Launch
      • ✓ Remote Launch
      • ✓ Local Activation
      • ✓ Remote Activation

Step 6: Verify WMI Permissions

    1. Open: wmimgmt.msc
    2. Navigate to: WMI Control → Properties → Security
    3. Click Security
    4. Click Advanced
    5. Select the monitoring user (or its group). Add it if it does not exist.
    6. Click Edit
            Configure:
      • Type: Allow
      • Applies to: This namespace and subnamespaces
            Verify that the following permissions are enabled:
      • ✓ Execute Methods
      • ✓ Enable Account
      • ✓ Remote Enable
      • ✓ Read Security

Step 7: Verify User Rights Assignment

    1. Open: gpedit.msc
    2. Navigate to:
      Computer Configuration → Windows Settings → Security Settings → Local Policies → User Rights Assignment
    3. Open: Impersonate a client after authentication
    4. Add the monitoring user if it is not already listed
    5. Apply the changes and retry monitoring

Important Note

Recommendation: For Windows monitoring through WMI mode, it is recommended to use an account with local Administrator privileges.

Non-Administrator Accounts: If using a non-administrator account, ensure that all the required DCOM permissions, WMI namespace permissions, and User Rights Assignment settings are configured correctly. Refer to the following KB articles for detailed configuration steps:


                    New to ADSelfService Plus?

                      • Related Articles

                      • I get the message "Authentication failed. Kindly verify the username and password provided" while adding server/Microsoft .NET/Exchange server through WMI.

                        Solution: Enter the username as <DomainName>\<UserName>. Also refer to: https://desk.zoho.com/portal/manageengine/kb/articles/authentication-failed-or-access-denied-message-is-shown-when-trying-to-add-the-server-monitor-through-wmi-mode
                      • Mail Server Monitor - Troubleshooting

                        Common Mail Server Monitor Errors and Troubleshooting Guide 1. Unknown Host Error Description: This error occurs when the mail client cannot resolve the hostname of the mail server to an IP address. The issue typically arises from DNS resolution ...
                      • Troubleshooting URL Monitor

                        When configuring a URL monitor in Applications Manager, you might encounter several errors related to accessibility, configuration, or server-side issues. Below are common errors along with step-by-step troubleshooting instructions to help you ...
                      • Troubleshooting Authentication Failed error

                        Authentication Failure Authentication failure occurs when the request to a resource is missing or has invalid credentials. Check if URL requires authentication Access the URL in an incognito/private window and check if any pop up asking for ...
                      • Real User Monitor (RUM) - Troubleshooting guide

                        If your Real User Monitor has not collected data for an extended period, follow the steps below to troubleshoot the issue. Step 1: Verify the RUM Agent configuration Real User Monitoring requires the RUM Agent to be installed and mapped to ...