Windows 2000 native and NTLM

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Jesse (jesseghere_at_yahoo.com)
Date: 02/18/04


Date: 18 Feb 2004 10:12:47 -0800

Hi-

We currently have a Windows 2000 domain running in native mode. All
of our workstations are Windows 2000. On the domain controller that
has the role of PDC I am seeing NTLM event 540's:

Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 2/16/2004
Time: 12:28:48 PM
User: Domain\username - edited for security
Computer: ServerName
Description:
Successful Network Logon:
         User Name: username
         Domain: Domain
         Logon ID: (0x0,0x16114BCF)
         Logon Type: 3
         Logon Process: NtLmSsp
         Authentication Package: NTLM
         Workstation Name: WorkstationName

All of my other domain controllers are using only Kerberos.
My question is why is NTLM still being used when I am running Windows
2000 native? Is this something I should be concerned with? I am
required to use Kerberos for all authenication on our network. Why is
NTLM being used on the PDC when Windows 2000 machines are
authenicating?

Thank you in advance,
Jesse



Relevant Pages

  • Re: trying to install exchange 2003
    ... The domain controller is windows 2000. ... native mode. ... need to upgrade to Active Directory before upgrading to Exchange 2003. ... Active Directory Connector agreement b/n the 2003 "domain controller" ...
    (microsoft.public.exchange.setup)
  • Re: AD sites and services
    ... A search for "Active Directory Sites" yeilds the following: ... After an Unsuccessful Domain Controller Demotion" ... http://support.microsoft.com?kbid=220140 "FRS Replication Protocol and Topology ... Windows 2000 Domain Controllers" ...
    (microsoft.public.win2000.active_directory)
  • RE: Internet Connection Wizard failing at Firewall Config and Secu
    ... You can use the Dcdiag.exe (Domain Controller Diagnostic Tool) included ... in Windows Support Tools to verify the AD status. ... Windows Server 2003 Active Directory Diagnostics, ...
    (microsoft.public.windows.server.sbs)
  • Site-tosite VPN Issue
    ... Windows Server 2003 domain controller ... Mixture of PCs running Windows 2000 Profressional with SP3 and Windows XP ... the VPN to the Windows Server 2003 domain controller. ... 12.7MB file from the server to the client PC. ...
    (microsoft.public.windows.server.networking)
  • RE: join server 2003
    ... Cannot Promote a Windows Server 2003 Domain Controller into a Windows 2000 ... Make a backup of the schema master. ...
    (microsoft.public.win2000.networking)