RE: UF_PASSWD_NOTREQD user account flag

From: Brady McClenon (mcclenon_at_albany.edu)
Date: 03/16/05

  • Next message: Petr Merta: "Re: UF_PASSWD_NOTREQD user account flag"
    To: "'Matt'" <smp.repicky@gmail.com>, "'Petr Merta'" <pmerta@lynguent.com>
    Date: Wed, 16 Mar 2005 16:25:50 -0500
    
    

    Petr,

    What error is logged on the server/workstation and/or the DC when the logon
    fails? Is it Security event ID 534 ("The user has not been granted the
    requested logon type at this machine") or something else?

    -----Original Message-----
    From: Matt [mailto:smp.repicky@gmail.com]
    Sent: Wednesday, March 16, 2005 3:53 PM
    To: Petr Merta
    Cc: focus-ms@securityfocus.com
    Subject: Re: UF_PASSWD_NOTREQD user account flag

    Not saying i've done any lookup on the flag or anything, but i know of a
    local security policy setting that exists that says that user accounts
    without passwords can only have console logon (log on locally). Doesn't
    explain why you can't access the machine without a password via SM. I
    believe network logon is controlled through the user rights assignment in
    the local security settings (or domain if you're networked) on a per user
    basis that can be set to allow/deny remote access to the machine to specific
    users. It also can be controlled through network access in the security
    options tab. There is one setting that is turned on by default with simple
    file sharing that says all network access is performed as user guest.

    Hope that gives you some hints.

    --
    On Wed, 16 Mar 2005 00:23:36 +0100, Petr Merta <pmerta@lynguent.com> wrote:
    > Hi all,
    > 
    > can anybody here explain the real meaning of UF_PASSWD_NOTREQD flag of 
    > Windows user account? I've found bunch of user accounts in W2K domain 
    > with this flag set; when I've tried to perform interactive or network 
    > logon with them, it failed. I've found no descriptive documentation 
    > besides of vague "password not required" statement. My questions are:
    > -- what's the actual meaning of this flag?
    > -- are there some circumstances under which it is possible to logon to 
    > account with this flag set (without password)?
    > 
    > Thanks for any info and/or reference.
    > 
    > Petr
    > 
    > ----------------------------------------------------------------------
    > -----
    > ----------------------------------------------------------------------
    > -----
    > 
    >
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Petr Merta: "Re: UF_PASSWD_NOTREQD user account flag"

    Relevant Pages

    • RE: Offer Remote Assistance - "Permission denied" - Windows XP SP2
      ... I am on a Novell network. ... > being made from and under the security context of a Local AND Domain ... > Allow logon through Terminal Services Administrators,Remote Desktop Users ... > Back up files and directories Administrators ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Help, Ive been hacked
      ... ID: 540 Source: Security ... > Event Type: Failure Audit ... > Event Category: Account Logon ... Your computer was not able to renew its address from the network ...
      (microsoft.public.windowsxp.security_admin)
    • Re: ATTN : Microsoft - Security Event 529....Second Request for help....
      ... According to the events, the logon ... failure is from the local machine account. ... disconnected from the network. ... Security Event ID 529 is a failure audit for logon/logoff. ...
      (microsoft.public.windows.server.sbs)
    • Re: No Shut Down or Restart for Domain Admins
      ... run rsop.msc from your DC and check which policy is responsible to this. ... I have created a group policy in a development network and imported it ... NT AUTHORITY\Authenticated Users Read (from Security Filtering) No ... Enforce user logon restrictions Enabled ...
      (microsoft.public.windows.server.active_directory)
    • Re: Unknown Domain user - domain authentication appears limited
      ... It sounds as if security policy changes were implemented without testing ... first in a test network or Organizational Unit which probably was not your ... Also keep in mind that deny logon locally and deny access to this ... > requested logon type at this computer. ...
      (microsoft.public.windows.server.security)