Re: RE: ADS Password Storage Protection



Rolando,

You can divide up the settings if you want, but the easiest method is to apply GPO's with these settings to both the DCs and the Workstations.

Establishing the settings for workstations is especially important in cases where they are laptops operated either in a local-authentication mode or disconnected from the domain.

In any case you'll want to disable the storage of LM Hash on both the workstations and the DCs and establish NTLMv2 as the communication protocol of choice on both sets of systems (otherwise you may not connect, or experience long authentication delays while the workstations and DCs negotiate the communication settings).

Sincerely,

Eric B.

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • RE: Install.INS - Proxy Enabled
    ... Yes, for those workstations have joined domain, if you want to change their ... IE settings you need manually reapply the install.ins file again on every ... I located the install.ins file on the server and workstations and was under ... >The Install.ins file contains the configuration settings for Internet ...
    (microsoft.public.windows.server.sbs)
  • Re: Questions About Windows Firewall and Domain Policy Enforcement (Updated Info)
    ... I have a Windows 2000 domain that has 200 workstations most of which are ... If we enable the firewall on the workstations then the domain ... SP2 settings on firewall activation). ... long as there is no Standard Profile configured. ...
    (microsoft.public.win2000.group_policy)
  • Re: Questions About Windows Firewall and Domain Policy Enforcement (Updated Info)
    ... I have a Windows 2000 domain that has 200 workstations most of which are ... If we enable the firewall on the workstations then the domain ... SP2 settings on firewall activation). ... long as there is no Standard Profile configured. ...
    (microsoft.public.windows.group_policy)
  • RE: RE: ADS Password Storage Protection
    ... You can divide up the settings if you want, but the easiest method is to ... apply GPO's with these settings to both the DCs and the Workstations. ... Norwich University ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE The NSA has ...
    (Security-Basics)
  • What does "No One" mean in a GPO Default setting?
    ... We recently implemented some User and Workstation GPO's that used settings ... Our tech who did ... A user who has this privilege can add up ... to 10 workstations to the domain. ...
    (microsoft.public.windows.group_policy)