RE: Changing user account authentication method in AD



I appreciate the information. What the problem appears to be is that these
users always authenticate using NTLM when they login to the domain. I
checked the security log and all other users authenticate using Kerberos. Is
there a reason that only these accounts would login using NTLM
authentication? All the client computers are running XP. We don't have any
NT or older machines on the domain. As I understand from some of the reading
I have done, Kerberos is the default authentication package and the only
reason that they would authenticate using another method would be if the
kerberos authentication failed or if it was not available. It does not show
any Kerberos failures, it only shows them attempting login using Microsoft
Authentication Package V1, and the next entry shows them successfully logging
in using the NTLM authentication package. I have tried to eliminate it being
a computer specific issue by having them login to another computer, but they
still use the same authentication. Any help would be a much appreciated.
.



Relevant Pages

  • Re: Integrated Windows Authentication Timeout?
    ... Is it possible that a different host name is being used for one of the subsequent requests that would break Kerberos auth? ... If you have "Negotiate" authentication set in the metabase, then this can still negotiate down to NTLM if for some reason the protocol thinks that Kerberos is unavailable. ... server. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Solaris 10 ssh logins + w2k3 AD native mode
    ... SEAM, Kerberos). ... Unix system to map from the AD user attributes ... a Unix login session. ... Does putty support GSSAPI authentication for SSH and can it ...
    (comp.protocols.kerberos)
  • Re: Event log shows NTLM not Kerberos
    ... it needs those SIDs, which is what authentication gives. ... Authentication Package: NTLM ... Authentication Package NTLM not Kerberos? ...
    (microsoft.public.security)
  • RE: Correct Domain User/Pass/Domain credentials rejected
    ... Authentication" checked vs. unchecked is that if it's unchecked, ... use NTLM or Kerberos, and Kerberos usually ends up being the winner. ... you can force IIS to only use NTLM: ...
    (microsoft.public.inetserver.iis.security)
  • Re: Unexplained Failed Logins
    ... if the DC is attempting a login via a delegation, ... and directly attempt Kerberos authN on network exposed ... authentication which would show IIS and use NTLM. ... Can you suggest any other places/logs to check for external activity? ...
    (microsoft.public.win2000.security)

Loading