How do I prevent windows from passing through the current authentication?

From: Greg Dunbar (dunbargr_at_hotmail.com)
Date: 05/29/03


Date: Thu, 29 May 2003 11:02:58 -0700


When you attempt to connect to a Windows 2000/XP machine from another, which
are not in the same domain, windows attempts to pass the current
authentication before prompting you with the "Enter network password" box.
This is helpful if you have two machines, and create the same account name
and password on each of them.

However... if the account name doesn't exist on the other machine, or the
password is different, windows will still try the current name and password
TEN TIMES before prompting you. (Turn on auditing and check for yourself)
This is causing a problem where users bring in their personal machines, and
use the same account name as the domain here at work but a different
password. This triggers our account lockout policy! So even if they type
the correct password when prompted, they are still locked out.

How can I limit the number of times windows tries to use the current
authentication before prompting?? Or preferably stop windows from trying
the current authentication at all.

TIA
Greg



Relevant Pages

  • Re: Login failed for ServerGuest
    ... | guest and the use of the same account/password does not ... |>I think it is not a limitation in Windows 2000. ... |>use same password for Administrator account on both Win2000 and WinXP ... although Windows Authentication is more secure than ...
    (microsoft.public.sqlserver.connect)
  • Re: User authentication
    ... With Windows authentication, ... an account is a member of Domain Admins. ... Windows account instead to run backup jobs. ...
    (microsoft.public.sqlserver.clients)
  • Re: User authentication
    ... Server Agent service account. ... What I want to do is configure scheduled backup. ... However, if possible, I would like to use Windows authentication as opposed ...
    (microsoft.public.sqlserver.clients)
  • RE: Adding a virtual FTP folder to IIS
    ... I think we can follow the Form Authentication modal. ... application will use the ASPNET account. ... If we change the username ... Windows identity different from that of the default process identity. ...
    (microsoft.public.dotnet.framework)
  • RE: Integrated Authentication (Kerberos) Problem
    ... Verify the SPN for the SQL service account is registered such as the ... >Thread-Topic: Integrated Authentication Problem ... A Windows XP SP1 with IE6 client machine ...
    (microsoft.public.inetserver.iis.security)