I get the same problem even when trying to connect via netbios from a
DC to member server though I'm using the domain admin account, which
cannot be prevented (in the dsa.msc>accounts>Log on to.. user config)
from logging onto to all machines in the domain.
I've also checked and the administrators and domain administrators are
both in the allow and not in the deny log of from network.
Also worth noting in this instance that there are two other machines
with an identical setup, neither of these two machines are
experiencingt he same issue when I try to connect from the DC to them.
All are part of the same domain and so get the same policy progpogated
to them.
There seems to be many reason why this might occurs with a handful of
solutions all with mixed results.
It would be nice for MS to assist in coming up with a fix for this.