Domain users are unable to login to K2 sites using Windows Authentication. After three attempts, it leads to a 401 error.


Domain users who do not have administrator rights on the web server where the K2 site is hosted get this issue.

Troubleshooting Steps

Please check the following items:
  1. A single provider is enabled.
  2. The application pool account is not a system account.
  3. The application pool account is a member of the IIS_IUSRS Group. 
  4. The IIS_IUSRS group has Modify rights to the Windows\Temp directory.
  5. The following policies are granted to the Authenticated and Domain users on the web server:
    Access this computer from the network
    Log on as a batch
  6. The K2 Site URL is added in either Local Intranet or Trusted Sites under the Internet Options in IE.