Re: DCOM access from a different domain (yes another accessdenied question)
- From: "Graham Morris" <Graywing@xxxxxxxxxxxxxxxx>
- Date: Mon, 15 May 2006 11:34:09 +0100
I still can't get anonymous logon to work, even when I enable the guest
account. The security audit log continues to say "Unknown user name or bad
password" when I try to connect, rather than "ANONYMOUS LOGON".
Interestingly I do get successful anonymous logon messages from applications
accessing COM+ on this machine.
I am not sure where to disable "Restrict anonymous access" - is this the
policy "Network access:Restrict anonymous access to Named Pipes and Shares"?
I originally hoped that having an account in the domain with a matching
username and password to the out-of-domain account would work. Does this no
longer work on 2003 SP1?
""Jeffrey Tan[MSFT]"" <jetan@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:j%23qSeK%23dGHA.188@xxxxxxxxxxxxxxxxxxxxxxxx
Hi Graham,
Below is the feedback I got from internal consulting:
In Window Server 2003:
1. The guest account is disabled by default -- no anonymous logon.
2. Restrict Anonymous access is enabled.
Anonymous logon does not work unless you enable the Guest account in
Server
2003 -- A serious security RISK. Not recommended.
Disabling Restrict Anonymous access opens up the server to a higher
potential for compromise -- anyone can read the list of users accounts and
attempt a dictionary password attack.
An unprivileged user account with a password assigned on the required
permissions would be a better choice in this situation.
Hope this helps
Best regards,
Jeffrey Tan
Microsoft Online Community Support
==================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
==================================================
This posting is provided "AS IS" with no warranties, and confers no
rights.
.
- Follow-Ups:
- Re: DCOM access from a different domain (yes another accessdenied question)
- From: "Jeffrey Tan[MSFT]"
- Re: DCOM access from a different domain (yes another accessdenied question)
- References:
- Re: DCOM access from a different domain (yes another accessdenied question)
- From: Graham Morris
- Re: DCOM access from a different domain (yes another accessdenied question)
- From: "Jeffrey Tan[MSFT]"
- Re: DCOM access from a different domain (yes another accessdenied question)
- From: "Jeffrey Tan[MSFT]"
- Re: DCOM access from a different domain (yes another accessdenied question)
- From: Graham Morris
- Re: DCOM access from a different domain (yes another accessdenied question)
- From: "Jeffrey Tan[MSFT]"
- Re: DCOM access from a different domain (yes another accessdenied question)
- Prev by Date: Re: DCOM access from a different domain (yes another accessdenied question)
- Next by Date: Re:hwnd to activeX control
- Previous by thread: Re: DCOM access from a different domain (yes another accessdenied question)
- Next by thread: Re: DCOM access from a different domain (yes another accessdenied question)
- Index(es):
Relevant Pages
|