Native Mode and Win9x/NT Clients Authentication

From: Fred Yarbrough (fyarbrou@yahoo.com)
Date: 07/27/02


From: "Fred Yarbrough" <fyarbrou@yahoo.com>
Date: Fri, 26 Jul 2002 19:22:06 -0500


I have been searching all over the Internet and still have not found an
exact answer. I know that once all of your NT 4 DC's have been converted to
Windows 2000 you can then switch to Native mode. Windows 2000 Pro clients
will authenticate using Kerberos. How will Windows 9x/NT clients
authenticate? Will they use the NTLM and authenticate against the PDC
Emulator or do you have to load some piece of software on them to make them
Kerberos aware? I am finding bits and pieces of info but nothing that says
it all in one area. One document that I have seen at
http://www.giac.org/practical/Deirdre_Perkins-Moore_gcnt.doc states the
following:

Windows 2000 supports NTLM logon (same as NT4), Kerberos logon, smart card
logon, or certificate mapping such as LDAP. Keep in mind that NTLM is not
available in Native mode. There is Kerberos support for other clients such
as Win98, but this requires that you install the Directory Services client.

Is this correct about there not being NTLM in Native mode? I thought that
the PDC Emulator would have provided this for backward compatibility. I am
not too wild about going out to our 2500 clients to load a Directory
Services client unless I have to. What's your take on how clients
authenticate when switching to Native mode????

Thanks,
Fred



Relevant Pages

  • Re: Native Mode and Win9x/NT Clients Authentication
    ... "Keep in mind that NTLM is not available in Native mode. ... > will authenticate using Kerberos. ... How will Windows 9x/NT clients ...
    (microsoft.public.win2000.security)
  • Re: Adding a second site
    ... newDCname.existingdomain.com and my clients would authenticate to that DC ... Computer accounts do not join Sites, ... > the Subnets and associate each Subnet with the correct Site). ...
    (microsoft.public.win2000.active_directory)
  • Re: Adding a second site
    ... > newDCname.existingdomain.com and my clients would authenticate to that DC ... "Alex Anderson" wrote in message ... Computer accounts do not join Sites, ...
    (microsoft.public.win2000.active_directory)
  • Re: ntlm
    ... NTLM is still used for down level clients. ... means the DCs will no longer talk to NT4 DCs. ... > We are thinking about switching from Windows 2000 mixed to native mode. ... We still have some downlevel clients with those being Windows NT ...
    (microsoft.public.win2000.active_directory)
  • Re: IAS server and access points
    ... I use PEAP and passwords to authenticate wireless clients. ... I get an occassional message on my IAS server that says "A RADIUS ...
    (microsoft.public.internet.radius)