Re: user rights

From: Steven L Umbach (n9rou@attbi.com)
Date: 03/15/03


From: "Steven L Umbach" <n9rou@attbi.com>
Date: Sat, 15 Mar 2003 01:34:06 GMT


      My guess this is due to supporting backward compatability for W98/95
machines. There are still millions of them used as workstations. W98/95 were
not designed as robust security operating systems and machines running them
can not be joined to a domain. A W98/95 machine can only be configured to
prompt a user to enter a username/password to log onto a domain. If you have
a real need to secure W2K computers against this kind of access you can
implement a ipsec "require" policy on them within a forest using ipsec, and
a ipsec "client" policy on those W2K/XP computers to be allowed access.
However I (an others) have not had good luck implementing ipsec require
policy on domain controllers and that would cause problems joining computers
to a domain. However I have seen recent posts here from MS (thanks for the
help guys/ladies) explaining that may be due need to modify policy to
accomodate icmp traffic. -- Steve

"Nathan" <n.kemble@empunity.com> wrote in message
news:046901c2ea52$9a1e2580$2f01280a@phx.gbl...
> I have expirenced this as well at the workstation level. I
> was working on it for a bit and let it go. I am not sure
> but am interested in what you find out. I have noticed too
> as a local admin on a machine that it has prompted me for
> the Network password and have used the local admin
> password for that machine and let me browse the network
> shares.. This is not good for security purposes. There
> must be some kind of cache on a DC that could allow this.
> Anyway Could you let me know what you find out.
> Thanks,
> Nate
>
> >-----Original Message-----
> >I just built a standalone windows 2000 server that is on
> >our lan but not in our domain. If I login as
> Administrator
> >and then go to the run command and type \\192.168.x.x,
> it
> >will bring up the shares on our domain. It does not
> prompt
> >me for domain/user name. If I logon as a local user that
> >does not have administrator rights to that server, it
> will
> >prompt me for domain/username to logon. How can a
> >administrator of a local machine get access to a domain
> >controller's shares if it does not have access to the
> >domain? I want to try and prevent this. Any ideas? Thanks.
> >
> >Mitch
> >.
> >



Relevant Pages

  • Re: p Security GPO Setup
    ... Workstations to Their Own OU with Client Respond. ... > Your require/request ipsec policy would need to exempt domain controllers by ... > their static IP address which would include then within a permit filter ...
    (microsoft.public.windows.server.security)
  • IPSec help
    ... I tried to setup IPSec on the network. ... All our workstations are running XP. ... controller to use Request Security ... and through global policy, apply Client IPSec policy onto the ...
    (microsoft.public.security)
  • Re: Workstations are going offline! Help!
    ... This is what I would do: keep an eye on those workstations to make sure ... Settings -> Security Settings and click Password Policy. ... won't start, or if you're seeing any symptoms, please check your event logs ... When offline files are in use and you are offline (but still ...
    (microsoft.public.windows.server.sbs)
  • Re: Workstations are going offline! Help!
    ... This is what I would do: keep an eye on those workstations to make sure ... Settings -> Security Settings and click Password Policy. ... won't start, or if you're seeing any symptoms, please check your event logs ... When offline files are in use and you are offline (but still ...
    (microsoft.public.windows.server.sbs)
  • Re: Configured IPSec Policy is not working.
    ... As for the RRAS filters themselves, they're fairly basic, requiring ipsec ... and encryption will depend on the security settings of the connection. ... why exactly do you want to use l2tp without any ipsec protection rather ... > What is the default filter rule and filter policy ...
    (microsoft.public.win2000.ras_routing)