RestrictAnonymous=2 & WinXP Clients

From: John Singler (singler@vet.upenn.edu)
Date: 08/26/02


From: "John Singler" <singler@vet.upenn.edu>
Date: Mon, 26 Aug 2002 10:49:14 -0400


Folks,

I have a ticket open with MS on this and seeing that they are reluctant to
release this problem as a KB article I figured that I could save you some
headache by informing you of some unexpected behavior when using a Security
Policy that enables RA=2 on your DC(s).

For an explanation of RA, please see
http://support.microsoft.com/default.aspx?scid=kb;en-us;q246261

As you can see from the above article RA=2 breaks things for down-level
clients and Mac users (but if you want a secure environment you don't care
about them anyway...). Well it also breaks things for up-level (??)
clients, namely WinXP machines. When a user on a WinXP box is "FORCED" to
change his/her password s/he will receive an error message stating "You do
not have permission to change you password". If you are already logged on
and "CHOOSE" to change your password you WILL be able to do so. If your
password expires you will NOT be able to log in to the Domain...

Welcome to MS's new security initiative's.

-John



Relevant Pages

  • RE: Dhcp security
    ... Setting up a 802.1x wired network requires: ... vendors, including Cisco, provide solutions to ensure that only properly ... trust agent collects security state information from multiple security ... software clients, such as anti-virus clients, and then communicates this ...
    (Focus-Microsoft)
  • Re: [Full-Disclosure] SSH vs. TLS
    ... > frowned upon by network ops and security. ... > - There must be a secure means by which all server keys are distributed to ... > appropriate ssh clients. ... > servers from using expired keys. ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Question about Mac OS X 10.4 Security
    ... SANS or Cisco Networkers makes me question ... security realm use Macs, myself included. ... Still, the ignorance of Mac users, who believe their ... x86 laptops, so - on an advice from a friend of mine - ...
    (Full-Disclosure)
  • Re: Shared Win98 Printing in 2003 Mixed Domain
    ... are a lot of security settings - particularly security options in security ... network access:do not allow anonymous access to sam and sam and shares, ... manager authentication level to send ntlmv2 responses only, ... make sure that the W2003 servers are also wins clients. ...
    (microsoft.public.win2000.networking)
  • Re: Shared Win98 Printing in 2003 Mixed Domain
    ... are a lot of security settings - particularly security options in security ... network access:do not allow anonymous access to sam and sam and shares, ... manager authentication level to send ntlmv2 responses only, ... make sure that the W2003 servers are also wins clients. ...
    (microsoft.public.win2000.security)

Quantcast