Re: Smart Card Logon



That can't be done since computer configuration Group Policy apples to all
users on that domain computer. You can configure user accounts in Active
Directory to require that they use smart card logon but that will apply to
any domain computer that they logon to. To me it seems to defeat the
security advantage of smart cards [multifactor authentication] by exempting
an account for smart card logon where there is an apparent need to otherwise
require smart card logon. Instead make sure that there is a user/group in
the local administrators group that has smart cards that can logon if need
be. Also you can simply undo the security option via Local Security Policy
or at the domain/OU level if that is where it is applied to not require
smart card logon to a domain computer when the need arises.

Steve


"JayW" <JayW@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:A816C391-F797-4941-A0C0-35A8E91322F0@xxxxxxxxxxxxxxxx
I am trying to implement smart card required logon on my Win XP and Win2K
PC's on the network through the local computer security policy. I need to
restrict all users logging onto those PCs to use a smart card to logon
instead of the normal User ID and password. However, I need to exempt the
administrator account on the local machine from this policy. The security
template options are enabled and disabled but I need to add the local
administrator account as an exception from the smart card requirement. Is
there a way that the template can be edited so that exceptions can be
added
or is there a predefined template available from Microsoft? Bottom
line...can this be done?


.



Relevant Pages

  • Re: Smart Card Logon
    ... You can simply make sure those domain users are local administrators on the ... domain computer they need to manage - they do not need to be using a domain ... enfoce the Smart Card Logon on the local machine. ... Directory to require that they use smart card logon but that will apply to ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Offline Smart Card Logon
    ... So smart card logon would only work as long the notebooks have a vaild, ... If the CRL has expired, ... > For successful smart card logon, a valid CRL (certificate revocation list) ...
    (microsoft.public.windows.server.security)
  • Re: how can an administrator login as a user to a domain w/o user
    ... >>> Is there any way to logon to a domain computer with a users domain ... how can the admin impersonate ... If you use a user's account then that ...
    (microsoft.public.windows.server.general)
  • RE: Duplicating Certificate Templates
    ... smart card logon in SBS network. ... we do not need to duplicate certificate template when we just want ... | Thread-Topic: Duplicating Certificate Templates ...
    (microsoft.public.windows.server.sbs)
  • LSALogonUser and smart cards....
    ... I have the following question concerning smart card logon on windows station. ... we query from a smart card (or any other certificate store). ...
    (microsoft.public.win32.programmer.networks)