Authentication for non-domain computers



We are in the process of allowing contractors into our network via a Cisco
VPN solution. The contractors will access a "SecureNet" area only, which is
separate from our production network. The SecureNet will also contain
development servers upon which the contractors will work. The SecureNet will
also contain an LDAP proxy, which will allow authentication to our production
AD environment without direct access to any domain controllers.

The contractors will be using their own computers, which will not be
"joined" to our domain - thus, the computers will have no Kerberos password.
The contractors will, however, have AD user accounts. In this scenario, how
can we authenticate these users? Keep in mind that this is not a web/browser
scenario. Their computers will need to directly access NTFS partitions.

We have considered a separate forest for the SecureNet, but prefer the proxy
approach to reduce administrative overhead, assuming we can resolve this
issue.

Thanks in advance.
--
Hugh
.



Relevant Pages

  • Re: Authentication for non-domain computers
    ... When trying to access a resource the contractors should be prompted for ... but least secure solution is to have them ... connect to the resource once and save their username and password. ... The SecureNet will also contain ...
    (microsoft.public.windows.server.active_directory)
  • Re: Authentication for non-domain computers
    ... In this scenario, how would they be able to change ... > connect to the resource once and save their username and password. ... > domain, most likely in Group Policy (won't apply to the contractors, but ... The SecureNet will also contain ...
    (microsoft.public.windows.server.active_directory)
  • RE: SSL VPNs from LAN to WAN
    ... First I would have a meeting with the manager of the contractors, ... the remote site will be terminated. ... your production network. ... SSL VPN's from LAN to WAN ...
    (Security-Basics)
  • Group Policy Help
    ... I Currently Work for a High School as the computer tech (No network ... admin, just contractors and there's no money for this years budget)and ...
    (microsoft.public.windows.group_policy)
  • Re: Port Security on switches?
    ... Sounds like you're looking for 802.1x enabled networking gear: ... My concern is people connecting non authorized laptops to the network ... vendors, contractors, etc come often and its basically left up to ...
    (Security-Basics)