Application or Desktops launch fail with the error message "Access Denied"
On the Domain Controllers, delete the registry string "RestrictRemoteSam" if exists
Registry Path : HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
The Group Policy setting "Network access: Restrict clients allowed to make remote calls to SAM" was applied to Domain Controller as part of server security hardening and removed. After removing the policy registry key was left over.