Windows / Intune error

0X80070569

The user has not been granted the requested logon type.

Symbol / family
ERROR_LOGON_TYPE_NOT_GRANTED
Signed decimal
-2147023511
Unsigned decimal
2147943785

What it means here

Local or domain user-rights policy does not allow this identity to use the requested interactive, service, batch, or network logon type.

Technical reference: Microsoft documentation or Microsoft-hosted support material

Resolution playbook

From symptom to verified fix

Start with evidence, change one variable at a time, and confirm the result before closing the incident.

1

Likely causes

  • The caller lacks the required local, tenant, share, or service permission.
  • The credential is invalid, expired, or being used in the wrong authentication context.
  • A policy denies the requested logon type or operation even though authentication succeeded.
2

Recommended fix

  1. Identify the logon type requested by the service or task.
  2. Review effective User Rights Assignment and deny rights from Group Policy.
  3. Grant only the required logon right to the intended managed identity or group.
3

Verify

  1. Repeat the smallest operation that originally failed.
  2. Confirm the same HRESULT does not recur at the matching timestamp.
  3. Check the management console or service report for a fresh successful state, not only a client-side message.
4

Escalate when

  • The error persists after the relevant checks and a clean retry.
  • Multiple devices, users, or networks show the same failure, suggesting service or policy scope.
  • You can provide the exact UTC time, operation, device/build, correlation identifiers, and the relevant event or service logs.
Capture the current Windows identity
whoami /all

Read-only. Review group membership and privileges; redact account identifiers before sharing.

← Search another error