Click here to get back home

Normal user logging onto Win2003 Domain Controller?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Normal user logging onto Win2003 Domain Controller? Zaheer Jassat 12-03-2007
Posted by Zaheer Jassat on December 3, 2007, 11:08 am
Please log in for more thread options
Thank you for this information. I tested this, created an encrypted folder
on shared space belonging to the server, and it created the directory and
profile. I'm assuming that it creates the folder to store the user's private
key (so that they can access the file from any machine)?

I've also found a method to disable users from using EFS via group policy.
Before I put this into effect, I would really like to know what exactly was
encrypted (assuming that it still is). Do you know of a way to search
specifically for encrypted files?

> On Mon, 3 Dec 2007 13:25:45 -0000, Zaheer Jassat wrote:
>
>> Its the DC, file & print server, runs SQL for a couple of (lightweight)
>> database applications. We also store userprofiles on this server. However
>> the server isn't a DHCP server.
>
> Check to see if the user in question has stored any EFS encrypted files on
> the domain controller. That will cause a user profile to be created.
>
> --
> Paul Adare
> MVP - Virtual Machines
> http://www.identit.ca
> Megahertz: A very large car rental company.


Posted by huhuiyu on December 3, 2007, 8:37 pm
Please log in for more thread options
you can use the comand line "efsinfo" which is belongs to the support
tools.
> Thank you for this information. I tested this, created an encrypted folder
> on shared space belonging to the server, and it created the directory and
> profile. I'm assuming that it creates the folder to store the user's
> private key (so that they can access the file from any machine)?
>
> I've also found a method to disable users from using EFS via group policy.
> Before I put this into effect, I would really like to know what exactly
> was encrypted (assuming that it still is). Do you know of a way to search
> specifically for encrypted files?
>
>> On Mon, 3 Dec 2007 13:25:45 -0000, Zaheer Jassat wrote:
>>
>>> Its the DC, file & print server, runs SQL for a couple of (lightweight)
>>> database applications. We also store userprofiles on this server.
>>> However
>>> the server isn't a DHCP server.
>>
>> Check to see if the user in question has stored any EFS encrypted files
>> on
>> the domain controller. That will cause a user profile to be created.
>>
>> --
>> Paul Adare
>> MVP - Virtual Machines
>> http://www.identit.ca
>> Megahertz: A very large car rental company.
>


Posted by Zaheer Jassat on December 4, 2007, 4:14 am
Please log in for more thread options
Thank you

> you can use the comand line "efsinfo" which is belongs to the support
> tools.
>> Thank you for this information. I tested this, created an encrypted
>> folder on shared space belonging to the server, and it created the
>> directory and profile. I'm assuming that it creates the folder to store
>> the user's private key (so that they can access the file from any
>> machine)?
>>
>> I've also found a method to disable users from using EFS via group
>> policy. Before I put this into effect, I would really like to know what
>> exactly was encrypted (assuming that it still is). Do you know of a way
>> to search specifically for encrypted files?
>>
>>> On Mon, 3 Dec 2007 13:25:45 -0000, Zaheer Jassat wrote:
>>>
>>>> Its the DC, file & print server, runs SQL for a couple of (lightweight)
>>>> database applications. We also store userprofiles on this server.
>>>> However
>>>> the server isn't a DHCP server.
>>>
>>> Check to see if the user in question has stored any EFS encrypted files
>>> on
>>> the domain controller. That will cause a user profile to be created.
>>>
>>> --
>>> Paul Adare
>>> MVP - Virtual Machines
>>> http://www.identit.ca
>>> Megahertz: A very large car rental company.
>>
>


Similar ThreadsPosted
PKI User certificate auto-enrollment for XP clients not logging onto domain computer May 18, 2007, 11:02 am
How to Create Restricted User at the Win2K3 DOMAIN Controller August 14, 2007, 2:00 am
prevent user from logging on to servers March 31, 2006, 8:22 am
What is the difference between logging into an AD Domain versus connecting to network resource? January 26, 2006, 4:32 pm
Domain Controller That Service a DMZ October 29, 2005, 9:58 pm
Domain Controller Security January 13, 2006, 4:43 pm
Domain Controller Security Policy August 12, 2005, 4:31 pm
Want to make an Admin for only one Domain Controller April 7, 2006, 4:42 pm
Client and Domain controller across a firewall March 31, 2008, 5:32 am
2003 Domain Controller not requesting certificate May 31, 2006, 2:53 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap