Re: Active Directory Security Migration Questions:

From: Greg Francis (francis@gonzaga.edu)
Date: 05/15/02


From: "Greg Francis" <francis@gonzaga.edu>
To: "Dozal, Tim" <tdozal@cisco.com>, "leon" <leon.inyc@verizon.net>, <security-basics@securityfocus.com>
Date: Tue, 14 May 2002 21:26:46 -0700


----- Original Message -----
From: "Dozal, Tim" <tdozal@cisco.com>
To: "leon" <leon.inyc@verizon.net>; <security-basics@securityfocus.com>
Sent: Tuesday, May 14, 2002 11:10 AM
Subject: RE: Active Directory Security Migration Questions:

> I am no AD expert but my experience is that in Mixed mode you will use
NTLM (i.e NT 4) authentication (plain test transmission)) when connecting
between hosts on the network. If your infrastructure has any non-windows
2000/XP machines then you must use mixed mode. If you are building a whole
new environment and have no need to connect to legacy OS's then you can run
in native mode and take advantage of the higher level security of the
Kerberos authentication model (I think MD5 crypto on the transmissions).
Most migrations will not be able to do this because they are not replacing
every host with a windows 2000 or newer OS.
>
> I welcome people to expand on this for my own knowledge also.
>
> -Tim

This isn't quite correct. Mixed-mode is only required if you want to have
NT4 backup domain controllers in your domain. Once all of the DCs in a
domain are W2K, you can convert to native mode. You can have NT4 member
servers and workstations in a native mode domain. You can also have Win9x
machines in a native mode domain but they never really join the domain
anyway.

Greg

Greg Francis, Sr. System Administrator
Central Computing and Network Support Services
Gonzaga University -- Spokane, Washington
509-323-6896 francis@gonzaga.edu



Relevant Pages

  • Re: How to transfter deligates when migrating 5.5 to 2003
    ... Native mode? ... Are the users using that for authentication to ... >> When you say delegates, you're referring to folder delegates correct? ... >> Delegated rights configured via the client vs. the ADMIN tool. ...
    (microsoft.public.exchange.setup)
  • Re: Does windows xp use a gc in native mode?
    ... 2003 native mode, it strictly used a GC for authentication for a domain. ... when I have a user with Windows XP sp1 connecting to a windows 2003 native ... The user uses that DC for authentication, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Using Exchange Server 2000 to Authenticate
    ... Why use Exchange 2k for authentication? ... which is exactly what Exchange 2k does (in native mode)? ... > Corporate now want it to validate the user by using MS Exchange Server ...
    (microsoft.public.dotnet.framework.aspnet.security)

Quantcast