Click here to get back home

Windows XPx64 does not require user authenication against Sharepoi

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Windows XPx64 does not require user authenication against Sharepoi StanP 02-20-2007
Posted by StanP on February 20, 2007, 6:42 am
Please log in for more thread options
I have a mixed environment with x86 and x64 XP systems. All have the updates
required and most access Sharepoint 2003 portals. Anonymous Access is not
allowed, Windows Authentication is required, however have found that none of
the x64 clients are prompted for user credentials (DOMAIN\username and
password) while all x86 clients are. All are required to login to the domain
to gain access, but after that the x64 clients do not need to re-validate to
gain access to the Sharepoint sites, even if they are not setup as vaild
users to those sites.

Any and all ideas as to how to prevent this would be very very much
appreciated.


Posted by Roger Abell [MVP] on February 20, 2007, 10:44 am
Please log in for more thread options
>I have a mixed environment with x86 and x64 XP systems. All have the
>updates
> required and most access Sharepoint 2003 portals. Anonymous Access is not
> allowed, Windows Authentication is required, however have found that none
> of
> the x64 clients are prompted for user credentials (DOMAIN\username and
> password) while all x86 clients are. All are required to login to the
> domain
> to gain access, but after that the x64 clients do not need to re-validate
> to
> gain access to the Sharepoint sites, even if they are not setup as vaild
> users to those sites.
>
> Any and all ideas as to how to prevent this would be very very much
> appreciated.
>

Well, I thought I had a likely cause, until I got to your statement
> even if they are not setup as vaild users to those sites
I was thinking to explain this by differences in the Internet options
security settings and/or zone recognition differences between the
machines, specifically as those impact whether Windows authentication
is allowed in the IE settings.

So, if a machine local account logs into an x64 XP it gets prompted
when attempting access to any of those Sharepoint webs, but if ANY
domain account logs in then it can access ANY of the Sharepoint webs
even though some of them are restricted so they should not allow that
domain account. Correct summary?

If only specific domain accounts show this, while logged in as one,
have you checked for cached network credentials ? in the properties
of the account in control panel ?

Roger



Posted by StanP on February 20, 2007, 1:16 pm
Please log in for more thread options
Roger, thanks for the reply. After much searching have found that it is in
the IE Security settings, at least the forcing of the logon prompt. However,
this has really become a bit disturbing in that it appears that if a user,
who is a member of the domain, on an XPx64 system, attempts to log onto a
Sharepoint site, without having the following changes made to the IE settings
they have full access to any and all Sharepoint sites and on top of thay
"Full Administrative" rights to all areas of those sites as well as the top
level portal.

Under the Advanced tab in Internet Options, if checked, remove the check on
"Enable Integrated Windows Authentication".

Under the Security tab, Internet/Custom Level/User Authentication/Logon the
option for Prompt for user name and password must be selected.

That will prevent anyone not authorized on the Sharepoint site to access it
on an XPx64 system.

"Roger Abell [MVP]" wrote:

> >I have a mixed environment with x86 and x64 XP systems. All have the
> >updates
> > required and most access Sharepoint 2003 portals. Anonymous Access is not
> > allowed, Windows Authentication is required, however have found that none
> > of
> > the x64 clients are prompted for user credentials (DOMAIN\username and
> > password) while all x86 clients are. All are required to login to the
> > domain
> > to gain access, but after that the x64 clients do not need to re-validate
> > to
> > gain access to the Sharepoint sites, even if they are not setup as vaild
> > users to those sites.
> >
> > Any and all ideas as to how to prevent this would be very very much
> > appreciated.
> >
>
> Well, I thought I had a likely cause, until I got to your statement
> > even if they are not setup as vaild users to those sites
> I was thinking to explain this by differences in the Internet options
> security settings and/or zone recognition differences between the
> machines, specifically as those impact whether Windows authentication
> is allowed in the IE settings.
>
> So, if a machine local account logs into an x64 XP it gets prompted
> when attempting access to any of those Sharepoint webs, but if ANY
> domain account logs in then it can access ANY of the Sharepoint webs
> even though some of them are restricted so they should not allow that
> domain account. Correct summary?
>
> If only specific domain accounts show this, while logged in as one,
> have you checked for cached network credentials ? in the properties
> of the account in control panel ?
>
> Roger
>
>
>

Posted by StanP on February 20, 2007, 1:25 pm
Please log in for more thread options
Roger,

Sorry I didn't answer your other points,

> So, if a machine local account logs into an x64 XP it gets prompted
> when attempting access to any of those Sharepoint webs, but if ANY
> domain account logs in then it can access ANY of the Sharepoint webs
> even though some of them are restricted so they should not allow that
> domain account. Correct summary?

>> Yes this is correct, however without changing the settings that I discribed
in my first reply, they don't get prompted, they have full access and that is
not a good thing at all. All they have to do is be a member of the Domain within
where the Sharepoint sites reside and they get access, period, to both Top level
portals and sub sites they are not setup in.<<


To prevent those who will never have a need to access these site I have gone
one step further, I have placed the Sharepoint URLS within a Restricted Zone,
and have set the User Authenication/Logon to "Anonymous logon". This thoughs
then into a You are not authorized page since the SS portals deny this type
of logon.


"Roger Abell [MVP]" wrote:

> >I have a mixed environment with x86 and x64 XP systems. All have the
> >updates
> > required and most access Sharepoint 2003 portals. Anonymous Access is not
> > allowed, Windows Authentication is required, however have found that none
> > of
> > the x64 clients are prompted for user credentials (DOMAIN\username and
> > password) while all x86 clients are. All are required to login to the
> > domain
> > to gain access, but after that the x64 clients do not need to re-validate
> > to
> > gain access to the Sharepoint sites, even if they are not setup as vaild
> > users to those sites.
> >
> > Any and all ideas as to how to prevent this would be very very much
> > appreciated.
> >
>
> Well, I thought I had a likely cause, until I got to your statement
> > even if they are not setup as vaild users to those sites
> I was thinking to explain this by differences in the Internet options
> security settings and/or zone recognition differences between the
> machines, specifically as those impact whether Windows authentication
> is allowed in the IE settings.
>
> So, if a machine local account logs into an x64 XP it gets prompted
> when attempting access to any of those Sharepoint webs, but if ANY
> domain account logs in then it can access ANY of the Sharepoint webs
> even though some of them are restricted so they should not allow that
> domain account. Correct summary?
>
> If only specific domain accounts show this, while logged in as one,
> have you checked for cached network credentials ? in the properties
> of the account in control panel ?
>
> Roger
>
>
>

Posted by Roger Abell [MVP] on February 20, 2007, 8:21 pm
Please log in for more thread options
I would suggest that you post to one of the Sharepoint newsgroups
as the granting of access to all sites on the Sharepoint server at the
site admin level must be due to some misconfig of the Sharepoint
roles. Just how that plays out with an account getting that level of
access when authentication is behind the scene with integrated
authentication, but is not the access level obtained when credentials
must be explicitly provided upon prompt is, frankly, rather hard to
fathom, at least assuming the same account is what ends up being
authenticated in both cases.

In the meantime you might consider using the IE adm template
settings via GPO to force the Internet options config on systems.

Roger
> Roger,
>
> Sorry I didn't answer your other points,
>
>> So, if a machine local account logs into an x64 XP it gets prompted
>> when attempting access to any of those Sharepoint webs, but if ANY
>> domain account logs in then it can access ANY of the Sharepoint webs
>> even though some of them are restricted so they should not allow that
>> domain account. Correct summary?
>
>>> Yes this is correct, however without changing the settings that I
>>> discribed in my first reply, they don't get prompted, they have full
>>> access and that is not a good thing at all. All they have to do is be a
>>> member of the Domain within where the Sharepoint sites reside and they
>>> get access, period, to both Top level portals and sub sites they are not
>>> setup in.<<
>
> To prevent those who will never have a need to access these site I have
> gone
> one step further, I have placed the Sharepoint URLS within a Restricted
> Zone,
> and have set the User Authenication/Logon to "Anonymous logon". This
> thoughs
> then into a You are not authorized page since the SS portals deny this
> type
> of logon.
>
>
> "Roger Abell [MVP]" wrote:
>
>> >I have a mixed environment with x86 and x64 XP systems. All have the
>> >updates
>> > required and most access Sharepoint 2003 portals. Anonymous Access is
>> > not
>> > allowed, Windows Authentication is required, however have found that
>> > none
>> > of
>> > the x64 clients are prompted for user credentials (DOMAIN\username and
>> > password) while all x86 clients are. All are required to login to the
>> > domain
>> > to gain access, but after that the x64 clients do not need to
>> > re-validate
>> > to
>> > gain access to the Sharepoint sites, even if they are not setup as
>> > vaild
>> > users to those sites.
>> >
>> > Any and all ideas as to how to prevent this would be very very much
>> > appreciated.
>> >
>>
>> Well, I thought I had a likely cause, until I got to your statement
>> > even if they are not setup as vaild users to those sites
>> I was thinking to explain this by differences in the Internet options
>> security settings and/or zone recognition differences between the
>> machines, specifically as those impact whether Windows authentication
>> is allowed in the IE settings.
>>
>> So, if a machine local account logs into an x64 XP it gets prompted
>> when attempting access to any of those Sharepoint webs, but if ANY
>> domain account logs in then it can access ANY of the Sharepoint webs
>> even though some of them are restricted so they should not allow that
>> domain account. Correct summary?
>>
>> If only specific domain accounts show this, while logged in as one,
>> have you checked for cached network credentials ? in the properties
>> of the account in control panel ?
>>
>> Roger
>>
>>
>>



Similar ThreadsPosted
Why Do So Many Windows EXEs Require Write Attribute File Permissions? December 23, 2006, 5:06 am
Failure to update domain policy Impersonate a client after authenication May 22, 2007, 3:43 am
Is it possible to use the Windows 2003 user names instead of pre-Windows 2000 user names in Windows Authentication? September 5, 2006, 9:27 am
Password Policy require server restart March 11, 2006, 9:37 am
Second Try: Any Anti Virus Applications That Do Not Require Install to Registry? July 4, 2008, 6:56 pm
windows user permissions April 3, 2007, 10:30 pm
windows 2003 user login failed locally October 16, 2005, 1:50 pm
sysadmin user in windows Active directory users and computers July 27, 2005, 12:31 pm
What has Windows 2003 Server security done to domain user profiles January 17, 2006, 11:49 pm
Windows Explorer changes user account during connection to share folder February 15, 2006, 5:49 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap