Re: Does LsaLogonUser support local users?

From: Valery Pryamikov (Valery_at_nospam.harper.no)
Date: 04/29/04


Date: Thu, 29 Apr 2004 08:55:10 +0200

Hi,
KERB_S4U_LOGON is a special logon type that requires W2K3 AD (on W2K3
functional level) and therefore this type logon is not supported for users
that is not part of W2K3 AD. Other types of kerberos logon also require AD
(kerbInteractiveLogon, kerbSmartCardLogon, ...), however work with AD of W2K
functional level.

Non-kerberos logon types (interactive, network, batch, service...) could be
used with local users.

-Valery.

http://www.harper.no/valery

"paul yang" <pyang@rsasecurity.com> wrote in message
news:458f5504.0404281659.38ff1844@posting.google.com...
> Hi,
>
> I wonder if I can pass a local user instead of a domain to
> LsalogonUser and get a token back?
>
> I noticed that the KERB_S4U_LOGON structure requires a username in UPN
> format, but local users don't have UPN available. So LsaLogonUser
> might not be used for local users.
>
> Does anyone have a definite answer for this?
>
> Thanks.
>
> Paul



Relevant Pages

  • Re: Deny Logon Locally
    ... > would also like to add all together deny local users logon. ... > locally or on a DC under Domain Policy user rights? ...
    (microsoft.public.win2000.security)
  • Re: Deny Logon Locally
    ... would also like to add all together deny local users logon. ... locally or on a DC under Domain Policy user rights? ...
    (microsoft.public.win2000.security)
  • Re: system cannot log you on now because the domain PCname123 is not available
    ... Are you logging on as the local Administrator - are you sure you're not ... using a domain account to try to login locally. ... Log onto the Domain and check the local Users & Groups - check the local ... And all I want to do it's logon to local box NOT the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Deny Logon Locally
    ... Do you have another suggestion I could do use with Group Policy? ... >> would also like to add all together deny local users logon. ... >> in the Local Security Policy for each computer under User Rights Deny ...
    (microsoft.public.win2000.security)
  • error that my profile cant be loaded at logon
    ... File>Add/REmoveSnapIn> (you choose Local Users and Groups> ... then you douuble click your user name in your right panel ... (probably your account is set to load a profile from some ... >I get an error that my profile can't be loaded at logon. ...
    (microsoft.public.windowsxp.security_admin)