For workgroup shares without passthrough authentication, that *is* what I do
and then I am done with it.


Are you thinking 'anonymous' as in web server access ?


Erik Goldoff
IT  Consultant
Systems, Networks, & Security 

'  Security is an ongoing process, not a one time event ! '



-----Original Message-----
From: Jim McAtee [mailto:[email protected]] 
Sent: Monday, September 13, 2010 1:17 PM
To: NT System Admin Issues
Subject: Re: Anonymous Share Access

----- Original Message ----- 
From: "Erik Goldoff" <[email protected]>
To: "NT System Admin Issues" <[email protected]>
Sent: Monday, September 13, 2010 4:25 AM
Subject: RE: Anonymous Share Access


> Remember that a workgroup does NOT have a central user database like a
> domain does.  So unless you create a local login on the server with the 
> same
> name and password as each user has on their own workstation, when it 
> hits
> the server it fails, as the account does not exist on the server with 
> the
> requested resource.  The GUEST account serves as a default generic
> 'anonymous' credential

Right.  That makes sense, but I thought ANONYMOUS LOGON had its own SID. 
If an anonymous user becomes GUEST then why wouldn't you just set share 
and file permissions for the GUEST account and be done with it? 


~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

---
To manage subscriptions click here:
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to [email protected]
with the body: unsubscribe ntsysadmin


~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

---
To manage subscriptions click here: 
http://lyris.sunbelt-software.com/read/my_forums/
or send an email to [email protected]
with the body: unsubscribe ntsysadmin

Reply via email to