Re: Share is denied and user is locked out

From: Ed (ebabin_at_yahoo.com)
Date: 05/13/03


Date: 13 May 2003 03:39:57 -0700


A 'small' detail I've seemed to have left out (there are no issues to
which you've described below). We are constantly testing our software
in various test environments in where we would replace a workstation
with another using a manual switch box utilizing the same IP address
(it is much easier to do it this way instead due to our unique
environment). At first we noticed the other workstations would not
connect because the arp table associated the IP with the previous
workstation's MAC address. So we would gracefully shutdown all the
workstations (including the server) and reboot with the temporary test
WS. This seemed to go well for a while until the authentication would
not work properly as described.

thanks for your thoughts,
ed

"Steven L Umbach" <n9rou@attbi.com> wrote in message news:<U7Vva.818825$3D1.460965@sccrnsc01>...
> Hi Ed. Have you changed any security options/user rights settings on
> the server or workstations of late? If so, that may be causing a problem.
> Possibly someone has obtained administrator access to your server and
> changed some settings/ntfs permissions without your knowledge. Double check
> that share and ntfs permissions are correct with the proper users/groups
> shown. I would recommend checking the membership of the local administrator
> and power users group on the server, to see if it looks correct. Also change
> the passwords for any administrator or power users on that computer. Enable
> auditing account log on and log on events for success and failure to see
> what reason users are being denied access and if someone is trying to access
> administrator account. I would also suggest enabling auditing of account
> management and policy change. Run netdiag /v on the server while logged in
> as administrator to check for network configuration. Also run Security and
> Configuration Analysis against the set up security template to see what if
> any security settings have been changed from default paying particular
> attention to "additional restrictions fro anonymous users" and "lan man
> authentication level". --- Steve
>
> http://www.lokboxsoftware.com/SecureWin2K/secAnalysis.asp
>
> "Ed" <ebabin@yahoo.com> wrote in message
> news:2e0a15f6.0305121205.5ddb40a6@posting.google.com...
> > We have a workgroup only configuration with our storage device
> > (Windows 2000 Server) providing a network share accessible by all
> > users. Our user accounts are named the same on each workstation and
> > server. We had no problems for an extended amount of time but lately
> > after rebooting the workstations, we were prompted with a
> > user/password dialogue which fails and locks out the user account on
> > the server. This occurs regardless of which user attempts to access
> > the share.
> >
> > After a frustrating day and investigation put off until the next day,
> > the user accesses the share without difficulty. This continues
> > intermittently until we think it is narrowed down to a server problem,
> > in that we rebuilt the workstations without luck but in restoring the
> > server we were able to overcome this problem (temporarily). It's our
> > guess the server's authentication of the users connection request is
> > not be handled properly (but why only sometimes).
> >
> > Anyone ever see this before?
> >
> > ed



Relevant Pages

  • Re: FIRED IT ADMIN HAS LOCKED US OUT OF SBS
    ... you have risen to an Administrator this would be a given. ... server and run all LOB apps on these. ... If there are no encrypted files, just reset the DSRM account ...
    (microsoft.public.windows.server.sbs)
  • Re: FIRED IT ADMIN HAS LOCKED US OUT OF SBS
    ... Teneo> Interesting post and Im now gonna be a party pooper... ... connections) before cutting power to the server and to the Internet ... If there are no encrypted files, just reset the DSRM account ... and try old domain Administrator account's passwords. ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote desktop: cannot copy files why still not working
    ... I created a new user on the XP box, set as an administrator ... this new user account is local to the XP system, ... In my environment, when I do an RDP connection to a server, I first log ... member of the local administrators group on the server. ...
    (microsoft.public.windows.server.security)
  • Re: Remote desktop: cannot copy files why still not working
    ... this new user account is local to the XP system, and a member of the local administrator's group on that workstation. ... In my environment, when I do an RDP connection to a server, I first log on to the xp workstation using my regular, non-privileged domain account, run mstsc, and then logon to the server using a domain account that is a member of the local administrators group on the server. ... In addition, I frequently use runas to run privileged applications on the workstation using my "administrator" account, and have found that files cannot be copied between those applications and anything running under the credentials of my regular account - even though my administrator account actually does have full access to everything on the workstation - just not through my regular account's view of that workstation. ...
    (microsoft.public.windows.server.security)
  • Re: Shared Fax device not available anymore after reboot server!?!
    ... the error message one by one to the Newsgroup for accurate research. ... You can send fax by using Administrator account. ... after the reboot of the server no account is able to fax anaymore. ...
    (microsoft.public.windows.server.sbs)