Re: administrative shares



John already gave some good advice. I just want to add if there is a need to
not allow non domain computers to access domain computers [other then domain
controllers] you can use ipsec require policy. Ipsec by default in an AD
domain uses Kerberos authentication between computers to set up a security
association. Non domain computers can not use Kerberos. Ipsec however takes
planning and testing so do not implement without first reading up on
Microsoft documentation on how to deploy it and never assign ipsec
require/request default ipsec policy in Domain Security Policy.

Steve


"Auddog" <will_k@xxxxxxxxxxx> wrote in message
news:Ovs1ipY3GHA.3508@xxxxxxxxxxxxxxxxxxxxxxx
I was checking over our network when I started to discover a potential
problem that I have. I have a new laptop that has not been added into our
domain. I'm logging into the laptop as the administrator and I'm
connecting to my network via the wireless connection. I have been able to
connect to several (but not all) of our desktops administrative shares (C$)
without having to enter any credentials. Does anyone know how to fix this
problem? Any help that you may be able to provide is greatly appreciated.

A



.



Relevant Pages

  • Re: Group policy to restrict who Recieves an IP from DHCP???
    ... DHCP is not a good security mechanism though you can use reservations that ... capable switches, compatible operating systems, PKI, and IAS server on the ... Ipsec may be something to look at. ... While you can use ipsec to protect domain computers, ...
    (microsoft.public.win2000.group_policy)
  • Re: I need a method a way to ONLY allow computers in domain to login
    ... log onto a domain from a domain computer configured with the request policy if the dc ... information with a non ipsec capable computer while the require policy will, ... >> have problems with domain computers accessing domain controllers. ...
    (microsoft.public.win2000.security)
  • Re: DHCP ENCRYPTED TO DOMAIN MEMBERS
    ... That can not be done with ipsec. ... Windows 2000/2003 or XP Pro you can use ipsec in the domain to prevent non ... domain computers from accessing any domain computer with a ipsec "require" ... that use negotiation security by adding their static IP addresses to a rule ...
    (microsoft.public.win2000.security)
  • Re: prevent access to shared folder when not on a domain computer
    ... One solution would be to use ipsec with an ipsec server require policy on ... controllers from ipsec ESP/AH with other domain computers for at least ...
    (microsoft.public.windows.server.security)
  • Re: I need a method a way to ONLY allow computers in domain to login
    ... have problems with domain computers accessing domain controllers. ... able to use ipsec and access resources. ... > You must authenticate TO logon. ...
    (microsoft.public.win2000.security)