Forcing authentication with a specific DC

From: Hindy (h_at_1.com)
Date: 07/01/03


Date: Tue, 1 Jul 2003 07:31:07 -0700


I don't think you need to worry about the DC's at site
not having an up to date password. I take it your PDC
emulator DC is at the main site?

Read this, and see if it resolves your problem:

"In Windows 2000, when a user password is changed at a
specific domain controller, that domain controller
attempts to update the respective replica at the domain
controller that holds the PDC emulator role. Update of
the PDC emulator occurs immediately, without respect to
schedules between sites on site links. The updated
password is propagated to other domain controllers by
normal replication within a site. When the user logs on
to a domain and is authenticated by a domain controller
that does not have the updated password, the domain
controller refers to the PDC emulator to check the
credentials of the user name and password rather than
denying authentication based on a nonvalid password.
Therefore, the user can log on successfully even when the
authenticating domain controller has not yet received the
updated password."

from:
ms-
help://MS.TechNet.2003JUN.1033/win2ksrv/tnoffline/prodtech
nol/win2ksrv/reskit/distsys/part1/dsgch06.htm

>-----Original Message-----
>Hi,
>
>I have 5 remotes sites, and my main site here. Each
remote
>site has a DC that users at that site authenticate to
when
>they log onto the domain.
>
>Due to a password policy change, I need to force all my
>users to change their password, a site at a time, at the
>next logon. However, I don't want them authenticating
with
>their local DC, I want them to authenticate at the main
>site, due to replication latency, citrix servers and a
>firewall that uses account credentials from the main
site
>here.
>
>If I disable the netlogon service, on their local DC's,
I
>am assuming their authentication request will go
>elsewhere. In the past, I have noticed that when a
certain
>site's server is down, users authenticate with whichever
>DC nabs their request first.
>
>I don't want this happening. I want to ensure that they
do
>not authenticate with their local DC AND they *do* auth
>with my DC here.
>
>Is this possible?
>
>If it is, how do I accomplish this?
>
>Thanks,
>Sharyn
>
>.
>



Relevant Pages

  • Re: AD 2003 Replication Failure/Authentication Failure
    ... >Verify time is synchronized on all DCs. ... users can authenticate to the Seidler-root domain controller, ... users can authenticate to the enterprise domain controller. ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to down grade server 2003 from pdc to file server
    ... "While you have a mixed environment of nt4 and 2k3 domain ... the 2K3 dc will hold the PDC role via the FSMO PDCe role." ... domain controller, you'll likely have to nominate a NT4 dc as the PDC ... after you demote the 2K3 server. ...
    (microsoft.public.windows.server.active_directory)
  • dcpromo fails on 2nd server after in-place upgrade of NT to W2K3
    ... After completing an in-place upgrade of our NT 4 PDC to Windows 2003 Server, ... I cannot run dcpromo to create a second domain controller on a server running ... The Active Directory name (and DNS zone) is MyDomain.com and the NetBIOS ...
    (microsoft.public.windows.server.active_directory)
  • Re: User profiles
    ... >Scenario One: Install a new domain controller in the same ... Perform full backup for the current PDC. ... >The user profiles will transfer to the new server ...
    (microsoft.public.windows.server.migration)
  • Re: adc error 5719
    ... It is the same server/domain or not? ... This posting is provided "AS IS" with no warranties, ... ADDITIONAL INFO If this computer is a domain controller for the ... does it mean that pdc is logging from pdc and clients are logging ...
    (microsoft.public.windows.server.active_directory)