Can't access ADMIN$ share using a local user or LAPS account
When supplying the appropriate user credentials that have local administrator access, you attempt to access a supported device and receive one of the following errors:
- Access Denied - Failed to connect to ADMIN$ share
- Access to the path '\\TARGET\ADMIN$' is denied
Before you start
Verify the following:
- Device meets requirements: System Requirements
- Firewall Exceptions are set up correctly: Firewall Ports and External Exceptions.
- File and Printer Sharing is enabled
- Group Policy, endpoint security software, or antivirus software is not restricting remote administrative access to the ADMIN$ share
- Appropriate credentials of local administrative users have been set (and tested)
- If using a LAPS account, you should be able to retrieve the password and use these credentials to log in and open an elevated CMD prompt
Troubleshooting steps
The most likely cause is that Remote UAC is enabled on the target computer. Remote UAC blocks local administrator accounts, including LAPS accounts, from accessing the ADMIN$ share over the network. Disable Remote UAC to allow access.
Disabling Remote UAC does not impact regular GUI-based (userland) UAC.
Back up the registry before making this change. An incorrect registry edit can cause serious system problems.
To disable Remote UAC, an entry will need to be made in the registry of the affected target computer. Navigate to:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
Create a DWORD value called LocalAccountTokenFilterPolicy and assign it a value of 1.
A reboot is recommended but not required, however, restarting the Server service is necessary.
Additional Troubleshooting
Remote Repair Tool
You can also use the Remote Repair tool to troubleshoot ADMIN$ (and other) issues. To use the tool, select the troublesome machine, click Help on the main console menu and select Open Remote Repair (or press Ctrl+~).
GPO and Scripts
Check to make sure a GPO or a logon/logoff script is not specifically denying access to the ADMIN$.
Administrative Shares Are Missing
In rare cases, the administrative shares are missing on the target machine(s). You can check to see if this is the case by running the following from a command prompt and reading the results.
net share
If those shares are missing, see Microsoft's support article for additional troubleshooting of administrative shares: Overview of problems that may occur when administrative shares are missing | Microsoft
Multiple Administrators
In cases where more than one administrator is listed in PDQ's credentials, both administrators must have explicit administrative rights on the target machine as well as the PDQ console.
Malware or Virus
In some cases, a virus or malware could cause administrative share issues.