22 thoughts on “SQL SERVER – Fix : Error : Error 15401: Windows NT user or group ‘username’ not found. Check the name again.

  1. Hi,

    I have one suggestion, now that it works for me.
    I was unable to add a new login for a local windows user on a local sql server just because of case.
    The Sql Server management studio process would always give my user login like this : AMITY\Dave.
    In fact, the right case is Amity\Dave.

    By executing sp_grantlogin “Amity\Dave” it worked fine.

    Bad GUI tools don’t ease the use at all.



  2. Hi Pinal,

    I got this err when I tried to manually change the Window group name after the physical server got renamed.

    After renaming the server, I use sp_dropserver and sp_addserver to bring SQL in sync with the new server name. Then I restart SQL Server. Everything seems to work fine. However, under Security -> Logins there are 3 groups that are prefixed by the old server name and also contain the old server name within their name (for example: oldservername\SQLServer2005SQLAgentUser$oldservername$MSSQLSERVER)

    Can you please advise how to fix it?

    I found out lots of useful information from your website.
    Thank you very much for your help!



  3. Hi, I am a new SQL server 2008 user. I like to add another user to existing window user service account in sql server 2008. as example I have a account on my name and want another account with different name. Please help.




  4. hi its mike , a c# programmer . i tried to make a software that uses a data base . and i wan to apply a user management .every user see’s his data .but the table which stores data is the same for all users .one thing i hav done is to hav 1 column,in the table which stores the username .and when data is retrieved …select * from table where username =something ……. is there any method in sql server .row level sequrity .or any user management method

    thanks in advance


  5. Hello Mike,

    SQL Server 2008 introduced encryption methods to encript or decrypt specific data, but incorporating that feature needs changes in data store and fetch procedurs.

    Pinal Dave


  6. Just got hit by this error and the KB above fails to help me out. I just installed SS2K8 Developer on W2K8 (64-bit) and am in the process of configuring/setting up. I can fire up Management Studio locally on the server and log in as domain admin via Windows Authentication.

    When I try to create a new login for a domain user, either through the GUI by typing it in or searching for the user via the search button, or via DDL, I get a 15401 error: “Windows NT user or group ‘\’ not found.” This is a fresh install; no logins exist except the \administrator one I added during install and the builtin ones. I was able to enumerate the domain user accounts via the Search box. I can ping the DC, the collation is CI and DNS is okay.

    Additionally, all services are running as NT AUTHORITY\NETWORK SERVICE.

    Where’s the issue? Any ideas?


  7. I have also found that the GUI will deny the ability to create a user and throws this error when attempting to create a user with a space after the username.

    Liked by 1 person

  8. …”This is quite a famous error” … “The reason I was not writing about this as the solution of this error is very well explained in Book On Line. ” …aha

    Still a “famous error”!

    Try to install an application via WebMatrix. Doesn’t work… lost hours (maybe I’m to stupid). But… I’m sure… somehow it would/should work…?!?!

    Would be very nice, if all(!) such “errors” or “babels” would be damned finally!

    Please begin to think from the “newbie” an not from you as a DB-expert because I don’t want/can’t “fight” to make a DB (SQL-Express) working.


  9. Also had this problem when using TFS labs (HYperV). The SQL server 2008 VM simply would not add any domain users, despite deleting the computer account and readding to the domain, however I noticed some other unusual behaviour such as logging in with another domain admin created the user profile, but the user did not have any admin permissions on the server, yet on another server in the environment it all worked as expected. In the end I found the problem to be computer SID duplication and therefore required a Sysprep (WITH GENERALIZE OPTION) and then it all worked fine after readding the computer back to the domain (with its new SID). Windows requires activation again but not a big deal.


  10. The fix I found for my case, was that the Login was in a different domain that the server, i ran ipconfig /all , noticed the DNS primary suffix and the DNS Suffix search list, and found that the domain to which the account belongs was not listed, so I added those domains to the windows IP config, and afterwards SQL server was able to find the login.


  11. Dear sir,

    I am using 2008 std edition, i have live my server with SQl 2000 .
    After a 3 to 4 hrs its show an error” WIndows Nt services stop” .
    Can any body tell me why we are facing these issue.


  12. It would be nice if there was some explanation as to how SQL server determine whether the user specified in “CREATE LOGIN” is a Windows user or not. We just had a subset of users’ names changed. I have tried using “Alter Login with name = ” That works for some users, but does not work for others. I search for users in activie directory and their account names have all been changed there. Previous versions of SQL server allowed you to search the sys procs to determine how it was deciding if a user was a Windows user or not – i.e. functions like Is_wintuser or something like that. At this point, since all of that is hidden, I’m at a lost to debug this.


    • Forgot to add that this is only a problem on one server. For the names that fail with error 15401 (Windows NT User or Group not found) on this one server, those names were able to be changed on 3 other servers without a problem. The only difference is that this server is part of a cluster. What doesn’t make sense in this case though is that some of the names on this cluster were able to be changed without a problem.


  13. Hi Pinal, I am trying to understand this specific problem:

    – I was having users from multiple regions to be added to my Windows AD Group and add them in SQLServer as a login and grant access to the group.

    – My windows admin created a domain group and 3 sub groups as local group
    and added the 3 subgroups under the domain group – he called them the members of the domain group.

    – When I tried to grant access to the Domain group, I was expecting the privileges to get cascaded to the local groups under Domain group

    – I saw that none of the users were having access.

    Hence we stared adding each of the subscribers under the SQLServer as a separate login.

    Can you please explain how this works exactly ? – Should granting access / role to a domain group be sufficed for giving access to users ?


Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s