windows authentication

From: Colin Bondi (cmbondi_at_hotmail.com)
Date: 10/27/05


Date: Thu, 27 Oct 2005 10:47:21 -0700

I have a question about IIS securty. If you disable anonymous access and
choose only integrated windows authentication, should you be prompted for a
username and password when accessing that site from a domain computer
running IIS? Or should IIS pass the credentials of the currently logged on
user to IIS? We have an intranet site which we only want to be accessible to
domain users but I just wasn't sure if it should be necessary for them to
enter their username and password to log onto the site if they are logged
into the machine with valid domain credentials.
thanks



Relevant Pages

  • Re: [PHP] Authentication
    ... If memory doesn't fail me, if you work with IIS and protect the source pages of the application so that IUSR_xxxxx doesn't have access to those files and instead grant access to the NT users or groups which you want, the IIS when working with IE clients will take care of that as long as they are all in the same domain. ... I did it with IIS 3 and IE4 and it worked, I am not completely sure about the details, but it is something you do in the server administration and you don't need to do any programming at all, if the person reaches the page it is because it is who he says it is. ... Otherwise, no browser will give you access to any sensitive information on the client machine, nothing that someone, anyone, might pick on the server side just by receiving a page request. ... If you can find a JavaScript function to snoop the username, ...
    (php.general)
  • RE: IIS 4 Security
    ... > Subject: IIS 4 Security ... > password protected web site is hosted using IIS 4 w/o ... > username and password. ... I would probably exploit 'Malformed HTR Request', ...
    (Focus-Microsoft)
  • Re: identify disabled users and bad bad passwords
    ... which probably related to dynamic scripting, etc, hence IIS only ... >> the w3c extended iis log format. ... >> Bernard Cheah ... >>> The system takes both disabled accounts and bad username and password ...
    (microsoft.public.inetserver.iis.security)
  • Re: Integrated Windows Authentication
    ... > Yes the IIS is part of a domain... ... > The error is just access denied in the browser after 3 attempts at putting ... > in the username and password. ... >> Rgds. ...
    (microsoft.public.inetserver.iis.security)
  • Re: security between serving files from a fileshare
    ... Microsoft MVP - Windows Security ... Any other ideas, as I can browse to the file in iis manager, yet I ... When entering username ...
    (microsoft.public.inetserver.iis.security)