anonymous restricitons block user logon

From: Ahmed Aldoseri (vitara666@hotmail.com)
Date: 04/16/03


From: "Ahmed Aldoseri" <vitara666@hotmail.com>
Date: Wed, 16 Apr 2003 00:46:19 -0700


On the default domain controller's group policy, by
setting the value of "Additional restricitons for
anonymous connections" to 1, 'do not allow enumeration of
SAM accounts and shares', users cannot logon to Windows XP
Professional computers with a message that says "Your
account is configured to prevent you for using this
computer, please try another computer". When viewing the
security log on the concerned computer, event number 533
is logged.

I've not had this problem with windows 2000 professional
computers.

Unless the domain user was a member of the administrators
group (whether local, or domain), the user's logon will
fail.



Relevant Pages


Loading