Advertisement

05.16.2008 at 09:20AM PDT, ID: 23408841 | Points: 500
[x]
Attachment Details

Access Denied When Connecting to Network Resource - Credentials Issue

Tags: Microsoft, Windows, 2003/XP, Access Denied Error Message
I have a Windows domain and a workstation in a workgroup on the same network. For security reasons, the workstation is locked down behind a firewall and unidirectional access is not possible, unless the firewall deems it to be, so it can't be on the domain.

There is a network share on the workstation that needs to be accessed. In Windows 2000, when accessing a network share not in the domain, it would prompt for user credentials. In Windows 2003, it always tries to authenticate with the currently logged on user.

Does anyone know of a way to force the Windows 2003 machine to use the Windows 2000 behaviour of prompting for a user name and password?
Start your free trial to view this solution
Question Stats
Zone: Security
Question Asked By: troutbm
Question Asked On: 05.16.2008
Participating Experts: 3
Points: 500
Views: 0
Translate:
Loading Advertisement...
05.16.2008 at 05:03PM PDT, ID: 21587375

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.17.2008 at 02:00AM PDT, ID: 21588501

Rank: Wizard

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.17.2008 at 08:02AM PDT, ID: 21589591

Rank: Guru

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.21.2008 at 06:44AM PDT, ID: 21614935

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.21.2008 at 04:35PM PDT, ID: 21619873

Rank: Wizard

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
06.05.2008 at 06:15AM PDT, ID: 21718970

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
06.11.2008 at 11:27AM PDT, ID: 21762808

Rank: Wizard

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
07.10.2008 at 07:48AM PDT, ID: 21973935

All comments and solutions are available to Premium Service Members only.

Start your 7-day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
Loading Advertisement...
Microsoft
  • Internet Protocols
  • Applications
  • Development
  • OS
  • Hardware
  • Windows Security
Apple
  • Operating Systems
  • Hardware
  • Programming
  • Networking
  • Software
Internet
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Spy / Ad Blockers
  • Web Browsers
  • New Net Users
  • Web Development
  • Chat / IM
  • Anti Spam
  • Web Servers
  • Anti-Virus
  • Email Clients
Gamers
  • Tips
  • Online / MMORPG
  • Puzzle
  • Emulators
  • Action / Adventure
  • Role Playing
  • Consoles
  • Game Programming
  • Strategy
  • Sports
  • Misc
  • Computer Games
Digital Living
  • Hardware
  • Automotive
  • New Net Users
  • New Users
  • Software
  • Digital Music
  • Gaming World
  • Home Security
  • Apple
  • Networking Hardware
Virus & Spyware
  • Vulnerabilities
  • IDS
  • Encryption
  • Anti-Virus
  • Operating Systems Security
  • Software Firewalls
  • WebApplications
  • Cell Phones
  • Operating Systems
  • Internet
  • Hardware Firewalls
Hardware
  • Displays / Monitors
  • Handhelds / PDAs
  • Components
  • Peripherals
  • Laptops/Notebooks
  • Servers
  • Misc
  • Apple
  • Embedded Hardware
  • Networking Hardware
  • Storage
  • Desktops
  • New Users
Software
  • System Utilities
  • Industry Specific
  • Network Management
  • Photos / Graphics
  • Page Layout
  • VMware
  • Misc
  • Web Development
  • OS
  • CYGWIN
  • Voice Recognition
  • Virtualization
  • Message Queue
  • Quality Assurance
  • Security
  • Firewalls
  • MultiMedia Applications
  • Development
  • Database
  • Office / Productivity
  • Business Management
  • OS/2 Apps
  • Server Software
  • Internet / Email
ITPro
  • OS
  • Storage
  • Encryption
  • Operating Systems Security
  • Apple Hardware
  • Laptops & Notebooks
  • Servers
  • Networking Hardware
  • Peripherals
  • Devices
  • Displays / Monitors
  • WebTrends / Stats
  • Search Engines
  • Firewalls
  • Web Computing
  • WebApplications
  • IDS
  • Vulnerabilities
  • Email Clients
  • File Sharing
  • Spy / Ad Blockers
  • Web Browsers
  • Web Servers
  • Networking
  • Anti-Virus
  • Consulting
  • Chat / IM
  • Anti Spam
Developer
  • Web Servers
  • Web Browsers
  • Game Programming
  • Dev Tools
  • Industry Specific
  • Office / Productivity
  • Database
  • CYGWIN
  • Web Development
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Programming
  • Content Management
  • Application Servers
  • Protocols
Storage
  • Removable Backup Media
  • Storage Technology
  • Servers
  • Grid
  • Remote Access
  • Backup / Restore
  • Misc
  • Hard Drives
OS
  • Miscellaneous
  • Security
  • Development
  • Linux
  • VMware
  • MainFrame OS
  • Unix
  • Apple
  • OS / 2
  • AS / 400
  • BeOS
  • Microsoft
  • VMS / OpenVMS
Database
  • Oracle
  • Miscellaneous
  • MySQL
  • Software
  • Sybase
  • Contact Management
  • PostgreSQL
  • Data Manipulation
  • Clarion
  • InterSystems Cache
  • Siebel
  • MUMPS
  • OLAP
  • SQLBase
  • SAS
  • GIS & GPS
  • 4GL
  • Berkeley DB
  • DB2
  • Informix
  • Interbase / Firebird
  • FoxPro
  • Reporting
  • LDAP
  • Filemaker Pro
  • MS SQL Server
  • dBase
  • MS Access
Security
  • Misc
  • Web Browsers
  • Software Firewalls
  • Operating Systems Security
  • File Sharing
  • Spy / Ad Blockers
  • Vulnerabilities
  • WebApplications
  • IDS
  • Anti-Virus
  • Encryption
  • Anti Spam
  • Email Clients
  • VPN
  • Chat / IM
Programming
  • Editors IDEs
  • Installation
  • Handhelds / PDAs
  • Multimedia Programming
  • System / Kernel
  • Automation
  • Algorithms
  • Game
  • Signal Processing
  • Project Management
  • Open Source
  • Database
  • Misc
  • Languages
  • Processor Platforms
  • Theory
Web Development
  • Scripting
  • Blogs
  • Web Servers
  • Software
  • Search Engines
  • Web Graphics
  • Web Services
  • Images
  • Internet Marketing
  • Images and Photos
  • Components
  • Document Imaging
  • Web Languages/Standards
  • Illustration
  • WebApplications
  • Fonts
  • WebTrends / Stats
  • Authoring
  • Digital Camera Software
  • Miscellaneous
Networking
  • Protocols
  • Apple Networking
  • Network Management
  • Message Queue
  • Application Servers
  • Content Management
  • File Servers
  • Email Servers
  • Misc
  • Java Editors & IDEs
  • Wireless
  • Networking Hardware
  • Backup / Restore
  • System Utilities
  • ISPs & Hosting
  • Web Servers
  • Storage Technology
  • Removable Backup Media
  • Servers
  • Web Computing
  • Broadband
  • Grid
  • OS / 2
  • Novell Netware
  • Unix Networking
  • Windows Networking
  • Security
  • Telecommunications
  • Operating Systems
  • Linux Networking
Other
  • Lounge
  • Business Travel
  • Community Support
  • New Net Users
  • Philosophy / Religion
  • Math / Science
  • Miscellaneous
  • URLs
  • Expert Lounge
  • Politics
  • Puzzles / Riddles
  • Automotive
Community Support
  • Suggestions
  • New to EE
  • New Topics
  • CleanUp
  • Announcements
  • General
  • Feedback
  • Input
  • EE Bugs
 
05.16.2008 at 05:03PM PDT, ID: 21587375
A trick I've employed in the past w/ occasional success (which may or may NOT work for you) is as follows:

instead of connecting to the share via \\server\sharename try \\serverip\sharename

I realize this doesn't answer your question; however, if you're unable to find a better one, I could offer some additional suggestions that may make this a viable "next best" solution.
 
05.17.2008 at 02:00AM PDT, ID: 21588501

Rank: Wizard

This may seem odd, but give this a shot:

This is a test:
Go to a single client computer, using Internet Explorer7, and open your IE browser:
Go to Tools->Internet Options->Security->Custom Level
Scroll to the very botoom that says Netlogon, and select prompt for "username and password".

The fix, if this works, is to apply it to a GPO:
 
05.17.2008 at 08:02AM PDT, ID: 21589591

Rank: Guru

Even if the computer you want to reach is behind a firewall, you can add it to add it to the domain. To let the firewalled computer authenticate with AD, the following outgoing ports are involved:

88 (kerberos)
389 (ldap)
53 (dns)
3268 (gc)
445 (smb)

Also see http://support.microsoft.com/kb/555381 for more information about how to get domain controllers to talk through firewall.
 
05.21.2008 at 06:44AM PDT, ID: 21614935
Connecting with IP or server name brings the same result.

All computers use IE6. I tried your suggestion but it didn't work.

Adding the workstation to the domain is not possible. This machine is going to be reset on a regular basis and I can't really get into why it can't be on the domain.

I am looking to find out how or why this changed from Windows 2000 to Windows 2003/XP.

 
05.21.2008 at 04:35PM PDT, ID: 21619873

Rank: Wizard

On the workstation, it should request user authentication, UNLESS you already have a set of credentials saved on the workstation that permits access. Let's say you log on as Domain administrator. If these sets of credentials are saved on the work station, then you can authenticate through without being prompted to. Also, if you have a mapped network drive to this workstation, and selected log on every time to this drive upon logging in, you have a set of credentials that are used for that share and are cached on your 2003 server.

Check the workstation's list of users and remove the domain credentials saved on the workstation computer. Then check the domain controller for "Managed Passwords". Managed passwords are what I call cached credentials. The can be found in Control pannel>>Users>>Advanced Tab>>Managed passwords. If you have a set of credentials for the workstation saved in managed passwords, your 2003 server will breeze right through the authentication process without being prompted.

Even though it is not requesting a username and password, it doesn't mean it's not authenticating.
 
06.05.2008 at 06:15AM PDT, ID: 21718970
This workstation is not on the domain. There are no domain credentials cached on it.
 
06.11.2008 at 11:27AM PDT, ID: 21762808

Rank: Wizard

Try this on your domain controller:

If using IE6 on the domain controller, I don't know if this is the same as IE7:

This may seem odd, but give this a shot:

This is a test:
Go to the domain controller, and open your IE browser:
Go to Tools->Internet Options->Security->Custom Level
Scroll to the very botoom that says Netlogon, and select prompt for "username and password".

The fix, if this works, is to apply it to a GPO:
 
07.10.2008 at 07:48AM PDT, ID: 21973935
I think this sort of resolved itself on its own.
 
 
20080236-EE-VQP-29 / EE_QW_2_20070628