OK – so where it didn’t work someone was changing the default.

 

Suggestion:

1.       Figure out what regkey it is, set it via a custom ADM or use IEAK

2.       Don’t allow the users to change the security zones

 

MS GPOs work that way that you are defining a setting and making sure that users don’t have the rights to change them again.

 

Gruesse - Sincerely,

Ulf B. Simon-Weidner

  MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz
  Weblog: http://msmvps.org/UlfBSimonWeidner
  Website: http://www.windowsserverfaq.org
  Profile:   
http://mvp.support.microsoft.com/profile="">   


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kamlesh Parmar
Sent: Wednesday, January 04, 2006 11:05 PM
To: [email protected]
Subject: Re: [ActiveDir] Enable Windows Integrated Authentication through GPO

 

I was testing the integrated authentication with IIS, and even though site was is local intranet, IE prompted for username and password on some machines and on some it didn't.

I checked in "Local Intranet" security zone for user authentication option and sure it was enabled for intranet sites.

And on investigation, on all the machine where it didn't work, I found that the same "Windows integrated authentication" was not ticked in Advanced option.

I ticked it and it worked.

So just putting it in "local intranet" might not work for this case.

My Config : Desktops are XP SP2, IE 6 & IIS 6 on Win2k3 SP1

On 1/4/06, Ulf B. Simon-Weidner <[EMAIL PROTECTED]> wrote:

The IIS site must be set up to allow windows integrated authentication and not to allow anonymous access. By default the IE Security Zone "Local Intranet" is enabled to allow Integrated Authentication (while Trusted Sites does not), if you haven't changed that you can configure the systems in question to be within the local intranet zone.

 

I don't know if you are able to change IEs settings per GPO, propably only if you created an ADM yourself, but you may be able to change it with IEAK. But that shouldn't be necessary if you use the correct security zones, and I'd recommend not enabling it for "Trusted Sites" or other Zones which are outside your DMZ.

 

Gruesse - Sincerely,

Ulf B. Simon-Weidner

  MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz
  Weblog: http://msmvps.org/UlfBSimonWeidner
  Website: http://www.windowsserverfaq.org
  Profile:   
http://mvp.support.microsoft.com/profile="">   


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of Salandra, Justin A.
Sent: Tuesday, January 03, 2006 8:26 PM
To: [EMAIL PROTECTED]; [email protected]
Subject: [ActiveDir] Enable Windows Integrated Authentication through GPO

 

How does someone enable Windows Integrated Authentication  through a Group Policy.  You will find this on the Advanced tab of Internet Options.


 

 

Justin A. Salandra

MCSE Windows 2000 & 2003

Network and Technology Services Manager

Catholic Healthcare System

646.505.3681 - office

917.455.0110 - cell

[EMAIL PROTECTED]

 




--
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
"Be the change you want to see in the World"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Reply via email to