Click here to get back home

Authenicated Users Query

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Authenicated Users Query gmickelsen 06-02-2005
Posted by gmickelsen on June 2, 2005, 6:14 am
Please log in for more thread options
Simplified Scenario of our configuration:

We have a W2K3 DC which hosts a share (share permissions:
Authenticated Users = Read Access;
NTFS permission :Administrators = Full Control)

We have a PC (not part of the domain, but in its own workgroup). This PC can
open the share on the server when logged in as a local administrator and see
the contents.

Firstly, shouldn't the fact that no users (apart from Administrators)
prevent the local user on this PC from being able to open the share?
Or are the permissions combined?

Secondly, shouldn't Authenticated Users only allow users who are logged on
to the domain to access the resource?

I'm sure this is quite a simple query for many of you.
Many thanks in advance.





Posted by Roger Abell on June 2, 2005, 8:31 am
Please log in for more thread options
Have you tried your test at a time when the test non-domain PC is
freshly booted and has in no way whatsoever been yet used to
connect to anything on that server ? If you connect to a remote
machine for one thing, authenticating to do so, and then later
try to connect to something else on that server the one connection
is recycled for the other session.

--
Roger Abell
Microsoft MVP (Windows Security)
MCSE (W2k3,W2k,Nt4) MCDBA
> Simplified Scenario of our configuration:
>
> We have a W2K3 DC which hosts a share (share permissions:
> Authenticated Users = Read Access;
> NTFS permission :Administrators = Full Control)
>
> We have a PC (not part of the domain, but in its own workgroup). This PC
can
> open the share on the server when logged in as a local administrator and
see
> the contents.
>
> Firstly, shouldn't the fact that no users (apart from Administrators)
> prevent the local user on this PC from being able to open the share?
> Or are the permissions combined?
>
> Secondly, shouldn't Authenticated Users only allow users who are logged on
> to the domain to access the resource?
>
> I'm sure this is quite a simple query for many of you.
> Many thanks in advance.
>
>
>




Posted by Steven L Umbach on June 2, 2005, 2:25 pm
Please log in for more thread options
If the account that the user is logged onto on the non domain computer has
the same logon name password as a user account in the domain then that user
can gain access to the share. If you have auditing of logon events enabled
for that server you will see a type 3 logon events recorded at the time that
computer user was able to access the share. If you want to restrict access
to only from domain computers you would have to enable an ipsec require
policy for that computer with the exception that domain controllers can not
use ipsec AH/ESP for communications with domain computers but otherwise it
would work because ipsec negotiation policy requires by default kerberos
authentication for computer accounts before the ipsec policy can be
sed. --- Steve


> Simplified Scenario of our configuration:
>
> We have a W2K3 DC which hosts a share (share permissions:
> Authenticated Users = Read Access;
> NTFS permission :Administrators = Full Control)
>
> We have a PC (not part of the domain, but in its own workgroup). This PC
> can
> open the share on the server when logged in as a local administrator and
> see
> the contents.
>
> Firstly, shouldn't the fact that no users (apart from Administrators)
> prevent the local user on this PC from being able to open the share?
> Or are the permissions combined?
>
> Secondly, shouldn't Authenticated Users only allow users who are logged on
> to the domain to access the resource?
>
> I'm sure this is quite a simple query for many of you.
> Many thanks in advance.
>
>
>




Similar ThreadsPosted
Query Process not showing users when not Admin July 1, 2005, 4:11 pm
Query LsaEnumerateAccountRights with C# June 13, 2005, 2:05 pm
Remotely query local policies January 10, 2008, 4:42 pm
Certificate Authority Newbie Installation query July 10, 2006, 10:54 am
Allow power users to "Show Processes From All Users" in Task Manager May 25, 2007, 6:38 pm
Can I delete 'Athenticated Users' group form local 'Users' group January 29, 2008, 11:52 am
S-x-x-xx Users November 19, 2005, 11:36 am
Cannot Add Users November 1, 2007, 9:00 am
Hidden Users November 25, 2005, 8:26 am
Everyone vs Authenticated Users April 10, 2006, 4:09 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap