> Source: [sk120137](https://support.checkpoint.com/results/sk/sk120137)

# sk120137 - "this account has been disabled" error message when logging into preboot

| Property | Value |
|----------|-------|
| Solution ID | sk120137 |
| Date Created | 2017-08-25 |
| Last Modified | 2017-08-28 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X, R82.20, R82.10, R82, R81.20 |
| OS | Windows |

## Symptoms

- "this account has been disabled" error message when logging into preboot.

## Cause

An attempt was made to sign into preboot with a user that is not in AD, for example an admin account that is not in AD, but is listed in the preboot authorized users.

## Solution

1. In the FDE policy, go to the fourth action: 'Enable lock screen authentication (OneCheck)'.
2. Under this action, you will see the 'Require that only an authorized preboot user is allowed to log into the operating system' checkbox. If this checkbox is selected, then you will **not be able**to login to preboot unless the profile is in AD.
3. Uncheck this checkbox to use a profile not in AD.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
