Re: integrated Windows authentication failure

From: Tom Kaminski [MVP] ((A_at_T))
Date: 03/22/04


Date: Mon, 22 Mar 2004 14:51:12 -0500


"Barry" <anonymous@discussions.microsoft.com> wrote in message
news:589AC6DD-B2D1-4976-A561-4C033781E898@microsoft.com...
> I am trying to use Internet Explorer (IE) 6 on a Windows XP Home client to
access a virtual directory in the default Web site on a Windows XP Pro Web
server. Both client and server are linked to a single router. In the
virtual directory, the account used for anonymous access is set to the
Internet guest account. Anonymous access works, but I want to use
integrated Windows authentication (IWA) instead. In IE on the client, I
enabled IWA. In the virtual directory, I turned IWA on and turned anonymous
access off. When I tried to access the directory from the client, I was
prompted for a username and password. I entered the name of the server's
Internet guest account (or that of another account that I added to the
server's Guests group) and the corresponding password, but access was
denied; after 3 tries, I got an HTTP 401.1 error message ("You are not
authorized to view this page"). How do I get integrated Windows
authentication working?

First of all, Windows Integrated authentication is best suited for an
intranet environment where everyone is on a windows domain - IE/IIS will use
the domain account that the user has logged on to the client computer with.
Basic authentication is probably a better choice in your case. In addition
to setting the authentication method, you need to restrict access by setting
NTFS permissions on your content. You would then logon with an account that
you have given permissions to the content.

IIS 5.1 on WXP is essentially the same as IIS 5 on W2K:

IIS 5 Documentation
http://www.microsoft.com/windows2000/en/server/iis/
Microsoft Internet Information Server
     Administration
         Server Administration
             Security
                 Authentication
                 Access Control

HOW TO: Configure IIS 5.0 Web Site Authentication in Windows 2000
http://support.microsoft.com/?id=310344
HOW TO: Configure User and Group Access on an Intranet in Windows 2000 or
Windows NT 4.0
http://support.microsoft.com/?id=325358

Make sure you disable simple file sharing in XP
http://support.microsoft.com/default.aspx?scid=kb;en-us;304040

-- 
Tom Kaminski IIS MVP
http://www.iistoolshed.com/ - tools, scripts, and utilities for running IIS
http://mvp.support.microsoft.com/
http://www.microsoft.com/windowsserver2003/community/centers/iis/


Relevant Pages

  • RE: How to start/stop windows service on a remote machine?
    ... impersonate the client user(authenticated via integrated windows ... authentication in IIS) and access some remote protected resource(windows ... the problem you meet is a typical windows ... want to continue access other remote machine, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: SP1 und Netzwerkauthentifizierung 802.1x
    ... Es gab mal ein Problem wenn das Client Certificat ... 953650 You cannot connect to an 802.1X wired network after you upgrade to Windows XP Service Pack 3 ... 838502 802.1x client authentication fails when you connect to a Windows Server ... IAS Best Practices: ...
    (microsoft.public.de.windows.vista.installation)
  • RE: 802.1x, Computers, Wired Security
    ... client to use EAP-TLS. ... Authentication-Provider = Windows ... Wired 802.1X Authentication failed. ... Network Adapter: Broadcom NetXtreme Gigabit Ethernet - Packet Scheduler ...
    (microsoft.public.windows.server.active_directory)
  • RE: IEEE 802.1x & dynamic vlan assignment
    ... You must configure the 802.1X client to send an EAP-logoff ... user authentication behavior of Windows XP and Windows Server 2003. ... - Computer authentication mode. ...
    (Focus-Microsoft)
  • RE: Sharepoint prompts for login credentials when not necessary
    ... \par Based on my experience, if this issue occurs on all the client, you need to check the Authentication Settings: ... \par Also, add the SharePoint site to your IE trusted zone, and make sure the "Automatic logon with current user name and password" is selected under User Authentication section in the Trusted Sites Security Settings. ... \par You are prompted to enter your credentials when you access an FQDN site by using a Windows Vista-based client computer that has no proxy configured ... \par login prompt and I can get in/open the document or do whatever I was doing. ...
    (microsoft.public.sharepoint.windowsservices)

Quantcast