You are attempting to log in as a user who is not a member of the “Administrators” or “Remote Management Users” groups. Generally speaking, only members of these groups will be able to login via WS-Management.
The target machine is configured to disallow the “Negotiate” authenticate method. To view permitted authentication methods on the target, run the command:
winrm get winrm/config/Client/Auth
In certain situations, when the target machine is joined to a domain, logging in using a local machine account is disabled. This problem has been observed after upgrading from Windows Management Framework 1.0 to 2.0, for example, on a Windows 2008 Server machine (not R2). To enable local account logins in this situation, you must create the LocalAccountTokenFilterPolicy registry value:
Key Path: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
Value Name: LocalAccountTokenFilterPolicy