AD and WinXP

From: John Singler (singler@vet.upenn.edu)
Date: 06/20/02


From: "John Singler" <singler@vet.upenn.edu>
Date: Thu, 20 Jun 2002 06:25:55 -0700


Greetings,

We have an Active Directory environment with mixed clients
(win98, 2k, XP).

Our security model is such that we have set
RestrictAnonymous to 2 on our Domain Controllers (for more
info. please see MSKB Q246261):

<http://support.microsoft.com/directory/article.asp?
ID=KB;EN-US;Q246261&>

I know this breaks some functionality for DOWN-LEVEL
clients (ie. when a user on a win98 box is forced to
change their password they are no longer able to do so).
I can live with problematic down-level clients but I am
seeing similar behavior from WinXP boxes (ie. when forced
to change their password users are not able to, resulting
in the error message "You Do Not Have Permission to Change
your Password" - though if you are already logged in to a
WinXP box and choose to change your password you can do
so).

I thought this
<http://support.microsoft.com/directory/article.asp?
ID=kb;en-us;Q258788> might be the answer but it isn't.

So, finally, here is my question: Does anyone have an
environment configured like ours (restrictanonymous = 2),
with winXP members, whose users can/cannot change their
passwords when they are FORCED to?

TIA.



Relevant Pages

  • Re: Windows XP and VFP 8.0
    ... WinXP are not server operating systems. ... > and clients running WinXP. ... > The app is served in a shared folver by a Win98 pc. ...
    (microsoft.public.fox.helpwanted)
  • AD and WinXP
    ... Just WinXP. ... >(win98, 2k, XP). ... >clients (ie. when a user on a win98 box is forced to ... >I can live with problematic down-level clients but I am ...
    (microsoft.public.win2000.security)
  • RE: Migrating Win98 ws from NT4 to Win 2K3
    ... All the clients are win98. ... you can either upgrade the NT domain to win2k3 ... domain, or set up a win2k3 domain, and then migrate from NT to win2k3 ...
    (microsoft.public.windows.server.migration)
  • RE: Migrating Win98 workstations from NT4 to W2K3
    ... All the clients are win98. ... you can either upgrade the NT domain to win2k3 ... domain, or set up a win2k3 domain, and then migrate from NT to win2k3 ...
    (microsoft.public.windows.server.migration)
  • Re: slow or failed user logon authorization
    ... Here is the link for the WIN98 ADClient: ... it is available on the WIN2000 Server CD. ... The WIN98 clients to not have a computer account like the WINNT, ... > My DHCP servers have option 006 set to my internal DNS ...
    (microsoft.public.win2000.active_directory)