Need MBAM 2.5 Helpdesk and selfservice sites to open for authenticated users with no password prompt

I Need MBAM 2.5 Helpdesk and self service sites to open for authenticated users with no password prompt. I just cant seem to get this to work. The account used in the application pool has its SPN registered and delegation set. I can use that account to login
to the sites but am prompted for a password. That said anyone I add into the helpdesk users group cannot negotiate the sites. Only the account I have set in the application pool can. I want domain authenticated users that have been added to the MBAM Help Desk
Users group to negotiate the site with NO password challenge at all.
tconners

This generally means that your SPN is not set up correctly.  Let's say the web server you installed the SSP on is lance.contoso.com and your app pool creds are corp\lance.  You should set an SPN similar to setspn -s http/lance.contoso.com
corp\lance.  In your browser, you should now be able to access the SSP without prompts.  However, if you still get prompted, generally that means that your local intranet zone in IE does not have an entry for *.contoso.com.  Since you are entering
an FQDN in your browser, IE interprets the "." to mean "on the internet" which breaks Kerberos authentication.  By adding *.contoso.com to your local intranet zone, you are telling it that lance.contoso.com is on the intranet, so use
Kerberos.
I can confirm, that I have exact configuration and I always get the password promt for the very first time. We have 2 server (1xIIS and 1xSQL) infrastructure in production with SPN set like it should and I get the password prompt.

Similar Messages

  • Need to get the name and the Site ID of a specific user using SharePoint Webservices

    Hi,
    I need to get the User's name by passing the Login Name using SharePoint OOB Web Services.
    I need to pass DOMAIN\\Login ID and get the User's Info i.e. Name and the ID of a particular site.
    I'm trying to use GetuserInfo:
    $(document).ready(function () {
    var soapEnv = "<soap:Envelope xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" xmlns:xsd=\"http://www.w3.org/2001/XMLSchema\" xmlns:soap=\"http://schemas.xmlsoap.org/soap/envelope/\">"+
    "<soap:Body>"+
    "<GetUserInfo xmlns=\"http://schemas.microsoft.com/sharepoint/soap/directory/\">"+
    "<userLoginName>DOMAIN\\Login ID</userLoginName>"+
    "</GetUserInfo>"+
    "</soap:Body>"+
    "</soap:Envelope>";
    $.ajax({
    url: "<http://SiteURL>/_vti_bin/usergroup.asmx",
    beforeSend: function (xhr) {
    xhr.setRequestHeader("SOAPAction",
    "http://schemas.microsoft.com/sharepoint/soap/directory/GetUserInfo");
    type: "POST",
    dataType: "xml",
    data: soapEnv,
    complete: processResult,
    contentType: "text/xml; charset=\"utf-8\""
    function processResult(xData, status) {
    alert("Status : " + status);
    alert(xData.responseText);
    console.log(xData.responseText);
    But i get error stating that User does not exist.
    Appreciate all your help.
    Regards,
    Sachin

    Hi Sachin,
    The following code for your reference:
    <script src="http://code.jquery.com/jquery-1.11.1.min.js" type="text/javascript"></script>
    <script type="text/javascript">
    $(function () {
    var url ="http://sharepoint/_api/SP.UserProfiles.PeopleManager/GetPropertiesFor(accountName=@v)?@v='contoso\\administrator'";
    $.ajax({
    url: url,
    method: "GET",
    headers: { "Accept": "application/json; odata=verbose" },
    success: function (data) {
    var results=data.d.UserProfileProperties.results;
    error: function (data) {
    </script>
    Best Regards
    TechNet Community Support
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact
    [email protected]

  • I need to send an email where the recipient opens the PDF file with a password,   can anybody help me and show me how to do that

    Hello,  I am trying to send an email where the recipient opens the PDF file with a password,   can anybody show me how to do that

    Hi surez,
    To password protect a PDF file, you need to use Acrobat. If you don't have Acrobat, you can try it for free for 30 days. See www.adobe.com/products/acrobat.html for more information.
    In Acrobat, you choose File > Properties when the document is open, and then click the Security tab to set up a password.
    Please let us know how it goes.
    Best,
    Sara

  • A few days ago I bought my first IMAC. I needed to download Mountain Lion, and I would get it for free as it's a new IMAC. Apple sent me a 'content code' - several times - because every time I enter it, it says the code is wrong.

    A few days ago I bought my first IMAC. I needed to download Mountain Lion, and I would get it for free as it's a new IMAC. Apple sent me a 'content code' - several times - because every time I enter it, it says the code is wrong.

    Sorry to ask, but is it case sensitive?
    Otherwise best to contact support and register a ticket: http://www.apple.com/support/contact/

  • Are IntelliPoint Pro 6.1 for MAC and IntelliType Pro 6.1 for MAC compatible with Mac OS 10.6?

    Are Microsoft IntelliPoint Pro 6.1 for Mac and IntelliType Pro 6.1 for Mac compatible with Mac OS 10.6.7?

    These arent compatible with Mac OS 10.6.7.
    I only found some drivers for Mac OS 10.2 to 10.4 on the official Microsoft site.
    EDIT: http://www.microsoft.com/downloads/en/details.aspx?familyid=410342E1-B3BD-44EB-B D0A-8BB18A9F25DA&displaylang=en#SystemRequirements

  • OIM11g R2 - If two roles (ACF2 and AD) are selected together for a user req

    Hi ,
    We are facing a problem In the Catalog, if two roles (ACF2 and AD) are selected together for a user and checking it out.The request goes to approval process.We have not created any approval process flow.
    Plz let me know how to recover from it and provide an option to provision two roles simulaneously to a user without going into approval process.
    Steps to Reproduce:
    1. Create a user in OIM .
    2. Search that user.Administration->Users->Search User
    3. Click on 'Roles' tab and select 'Request Role' under that tab.
    4.'Catalog' tab opens .Click on Search icon and Add AD and ACF2 Role to the cart.
    5. Click on 'Check out'
    6. Click on Submit button
    7. Request Summary tab opens with Request status shown as 'Obtaining Request Approval' and Request Type as 'Assign Roles'.
    Note: If we assign AD and ACF2 individually to user and running Evaluate User Policies we are able to see account in Provisioned state under Accounts tab of User and request is not going to approval process
    Thanks in advance

    Hi,
    As mentioned I created two auto approval policies
    1. Request Type= Assign Roles
    Level= Request Level
    Auto Approval checked
    Approval Rule=Requester.UserLogin Equals XELSYSADM
    (Created this rule as i am logeed in as XELSYSADM)
    2. Request Type= Assign Roles
    Level= Operation Level
    Auto Approval checked
    All Scope Checked
    Approval Rule=Request.RequestType Equals Assign Roles
    After that i opened the user request role page and requested 2 roles (AD and ACF2).
    But now also request went to approval work flow
    Please point which step i have missed or any other step need to be performed.
    Regards,
    Edited by: Puneet Lobana on Jan 7, 2013 12:54 AM

  • I logged onto my MacBook Air and it is asking me for my "local items" keychain password for several different things. I do not know what this is or how to get rid of it. Please help. Thanks.

    I logged onto my MacBook Air and it is asking me for my "local items" keychain password for several different things. I do not know what this is or how to get rid of it. Please help. Thanks.

    There are several possible causes for this issue. Please take each of the following steps that you haven't already tried, testing after each one, until it's resolved. Back up all data before making any changes.
    Step 1
    Follow the directions in this support article.
    Step 2
    Open the iCloud preference pane and uncheck the Keychain box. You'll be prompted to delete the local iCloud keychain. Confirm. Then re-check the box. Follow one of the procedures described in this support article to set up iCloud Keychain on an additional device.
    Step 3
    Open the Keychains folder as in Step 1. There should be a file in that folder with the name "login.keychain". If there is also a file iwith the name "login_renamed_1.keychain", then please do as follows:
    Rename login.keychain to "login-old.keychain".
    Rename login_renamed_1.keychain to "login.keychain".
    You can then close the folder.
    Launch the Keychain Access application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Keychain Access in the icon grid.
    Delete the login keychain from the keychain list. Choose Delete References when prompted, not Delete References & Files.
    Select
    File ▹ Add Keychain...
    from the menu bar. Add back the file now named "login.keychain". If any of your needed keychain items are missing from it, also add back the file now named "login-old.keychain". I suggest you transfer any needed items from that keychain to the login keychain, then delete it. The transfers are made by drag-and-drop in Keychain Access. You'll need to enter your password for each item transferred.
    Select
    Keychain Access ▹ Keychain First Aid
    from the menu bar and repair the keychain. Quit Keychain Access.

  • I have set up two users, one for myself and one for children.  The computer automatically logs in for the children with no password required.  When the children go to spotlight and type in a search criteria all of my files show up.  How do I prevent this?

    I have set up two users, one for myself and one for children.  The computer automatically logs in for the children with no password required.  When the children go to spotlight and type in a search criteria all of my files show and open up.  How do I prevent this?

    Log in to your account, and move all your files to your home folder. No other users should be able to access them there and they won't show up with a Spotlight search.
    Make sure your kids' account(s) do not have admin privileges.

  • Fastest and best external hard disks for video use with Imac?

    What is the fastest and best external hard disks for video use with Imac (I believe it is currently not possible to use Esata on the Imac).

    For DVCam. HDV etc, I'm a fan of the G-raid drives. From personal experience they
    are very solid performers. I only had one issue with a new drive that was replaced
    next day. They are not the cheapest drives to be found but the build quality
    is excellent. Check out:
    http://www.g-technology.com/products/g-raid.cfm

  • Why is it ok for a verizon wireless service representative to lie to a customer? I went over my monthly data and i called to ask for some help with the overage because i was barely over. They told me they would take care of it and sold me on a shared data

    why is it ok for a verizon wireless service representative to lie to a customer? I went over my monthly data and i called to ask for some help with the overage because i was barely over. They told me they would take care of it and sold me on a shared data plan that would result in 2gb less data but told me i would save 20$ a month. I agreed and recieved my next statement and to my suprise my bill actually went up 15$ a month and i talked to several people and they all told me there is nothing that can be done to get back on the plan i was on and they can not even give me a discount to get me back to what i was paying. They can only offer me a convenience credit. I will be cancelling service.

    ajwest101,
    We do not want to see you go. I truly apologize for any misinformation regarding your plan. Let's investigate into this a little further. What plan were you on? What plan were you switched to? If you look at the detailed billing online of your previous bill do you see any additional charges other then the plan?
    LindseyT_VZW
    Follow us on Twitter @VZWSupport

  • MacKeeper (and other sites) keeps opening in new tabs

    HELP!!
    When browsing, new tabs open when I make selections in Safari. I've installed Sophus anti-virus and have scanned my laptop multiple times. Every time I scan with the anti-virus software, the software diagnoses that there where no issues detected. Does anyone have a solution?
    Saturday, February 7

    There is no need to download anything to solve this problem. You may have installed a variant of the "VSearch" ad-injection malware. Follow Apple Support's instructions to remove it.
    If you have trouble following those instructions, see below.
    Malware is always changing to get around the defenses against it. This procedure works as of now, as far as I know. It may not work in the future. Anyone finding this comment a few days or more after it was posted should look for a more recent discussion, or start a new one.
    The VSearch malware tries to hide itself by varying the names of the files it installs. To remove it, you must first identify the naming pattern.
    Triple-click the line below on this page to select it, then copy the text to the Clipboard by pressing the key combination  command-C:
    /Library/LaunchDaemons
    In the Finder, select
              Go ▹ Go to Folder...
    from the menu bar and paste into the box that opens by pressing command-V. You won't see what you pasted because a line break is included. Press return.
    A folder named "LaunchDaemons" may open. Look inside it for two files with names of the form
              com.something.daemon.plist
    and
               com.something.helper.plist
    Here something is a variable string of characters, which can be different in each case. So far it has always been a string of letters without punctuation, such as "cloud," "dot," "highway," "submarine," or "trusteddownloads." Sometimes it's a meaningless string such as "e8dec5ae7fc75c28" rather than a word. Sometimes the string is "apple," and then you must be especially careful not to delete the wrong files, because many built-in OS X files have similar names.
    If you find these files, leave the LaunchDaemons folder open, and open the following folder in the same way:
    /Library/LaunchAgents
    In this folder, there may be a file named
              com.something.agent.plist
    where the string something is the same as before.
    If you feel confident that you've identified the above files, back up all data, then drag just those three files—nothing else—to the Trash. You may be prompted for your administrator login password. Close the Finder windows and restart the computer.
    Don't delete the "LaunchAgents" or "LaunchDaemons" folder or anything else inside either one.
    The malware is now permanently inactivated, as long as you never reinstall it. You can stop here if you like, or you can remove two remaining components for the sake of completeness.
    Open this folder:
    /Library/Application Support
    If it has a subfolder named just
               something
    where something is the same string you saw before, drag that subfolder to the Trash and close the window.
    Don't delete the "Application Support" folder or anything else inside it.
    Finally, in this folder:
    /System/Library/Frameworks
    there may an item named exactly
                v.framework
    It's actually a folder, though it has a different icon than usual. This item always has the above name; it doesn't vary. Drag it to the Trash and close the window.
    Don't delete the "Frameworks" folder or anything else inside it.
    If you didn't find the files or you're not sure about the identification, post what you found.
    If in doubt, or if you have no backups, change nothing at all.
    The trouble may have started when you downloaded and ran an application called "MPlayerX." That's the name of a legitimate free movie player, but the name is also used fraudulently to distribute VSearch. If there is an item with that name in the Applications folder, delete it, and if you wish, replace it with the genuine article from mplayerx.org.
    This trojan is often found on illegal websites that traffic in pirated content such as movies. If you, or anyone else who uses the computer, visit such sites and follow prompts to install software, you can expect more of the same, and worse, to follow. Never install any software that you downloaded from a bittorrent, or that was downloaded by someone else from an unknown source.
    In the Security & Privacy pane of System Preferences, select the General tab. The radio button marked Anywhere  should not be selected. If it is, click the lock icon to unlock the settings, then select one of the other buttons. After that, don't ignore a warning that you are about to run or install an application from an unknown developer.
    Then, still in System Preferences, open the App Store or Software Update pane and check the box marked
              Install system data files and security updates (OS X 10.10 or later)
    or
              Download updates automatically (OS X 10.9 or earlier)
    if it's not already checked.

  • SCCM central site and primary site use the same SQL SERVER with two Instance.

    Hi  Guys,
    I want deploy SCCM 2012 central site and primary site in my domain. But Only one Sql server for me. Any one can tell me how to install the central site server and primary site server with the same SQL SERVER with two instance.
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
    Sean Xiao
    TechNet Community Support

    Although you can install like the configuration you said above, we do not recommend you do it this way. If your SQL box has  problems, all the data will go away and you will not have data redundancy.
    You need to configure the different SQL Port and SQL Broke service port e.g.
    SQL port 4023  SQL Broke Service port 4022 for CAS instance
    SQL port 4024  SQL Broke Service port 4021 for PRI instance
    Juke Chou
    TechNet Community Support
    I agree with Johan and this configuration should not be used. But I want to clarify that the default ports for "SQL port" (actually, SQL over TCP) is 1433 and the SQL Broker Service uses 4022. The configuration above should work but the "correct" would be
    to use 1433 and 4022 for the CAS and 10434 and 4023 for the Primary :)
    You can read more about Network Ports used by Configuration Manager here
    http://technet.microsoft.com/en-us/library/hh427328.aspx#BKMK_CommunicationPorts
    /Tim
    Tim Nilimaa | Blog: http://infoworks.tv | Twitter: @timnilimaa

  • I have an SIII and will be traveling out of the country.  Do I need to get a micro SIM card ? (I was told that Verizon has them for free but it needs to be set up and there was a charge for this.

    I have a Samsung SIII and will be traveling out of the country. Do I need to get a micro SIM card instaslled for international ?  I was told Verizon has them free for customers but that it needs to be "sert up". Also, are there alternatives to going through the verizon data plan (which is very expensive.
    Thanks

    Your phone already has a micro SIM card in the device so it can connect to the VZW network. You will need an international plan from VZW if you intend to use that SIM card. Otherwise you can get a new SIM card from the local carrier and setup the phone for global use with a separate APN with that carrier's specific information.

  • I need IMEI number, make, model and memory size of phone for insurance claim

    Hi Xanadu,Thank you for the info.What the insurers have asked for though is documentary proof of these details. Ie; something from EE that I can print off and send to them.Any suggestions ?Thanks

    Hi,
    Basically your insurers are trying to fob you off and are implying they don't believe you own the phone as who keeps this information?!?!
    You need to call your insurers and ask them to arrange a "three way call" with EE and you and then they can ask EE all the questions they want. If they again fob you off (which is likely) tell them you want to complain and intend to escalate this issue to FOS  http://www.financial-ombudsman.org.uk/   (this costs them £550 if you complain to the FOS) and then they will have to refer your case to complaints who will likely be the actual insurer/underwriter and then you will get your claims dealt with.
    Hope this helps.

  • Need to publish PHP files and be able to "open other movie"

    I am hoping someone can help me. I converted my published
    captivate projects to PHP per request of my company web team. In
    most projects, I link to an addional project using the On success:
    "Open other project" command. All projects are .cp files and this
    feature has always worked in the past when published and uploaded
    my projects as .htm. I can still upload my files as .php with the
    .swf file and opening a project from my web page works fine.
    However, when I click the link at the end of one project to open
    the next, I recieve an error stating the file cannot be found.
    Consequently, the file it is looking for is the .htm and I cannot
    figure out a way for it to look for the .php file. Because of
    company standards, I cannot simply upload all files (.php, .swf,
    .htm) as a work around. Does anyone have a procedure to make
    Captivate "call" the .php file extention when linking a project
    instead of the .htm?
    Any help is GREATLY appreciated!

    Welcome to our community, Especial del Dia
    You might try using the approach of "Open URL or File". Then
    point to the URL of the PHP page instead.
    I think if I were in your shoes, I'd arrange a meeting with
    the web team and see if you can figure out why HTM/SWF are bad and
    things MUST be PHP or die. You may just find that after you explain
    all the extra effort and time wasted in attempting to be compliant
    with what is often some IT person's whim and mandate, things will
    change and you will be allowed to publish what has always worked
    until IT wanted to change things and break it and point their
    fingers at you.
    Just thinking out loud... Rick

Maybe you are looking for

  • Text in Dynamic Textfield gets cut off

    Hi I have a dynamic text field which is just one line of text. For some reason letters like g or p that go below the regular line of text get cut off. I have made the field bigger, and also played around with the _height Property but it doesn't make

  • Problem In Vendor Master Creation

    When i am going to create vendor Master then Recon.Account option has no value .Its show No Entry Option Available . Pls help me and solve this problem. Thanks & Regard vipin yadav

  • BUT000-BPKIND history

    Hello I am looking for a database table which contains the history of changes of BUT000-BPKIND. Please help me. Thank you.

  • Can't burn iMovie3 movie on iDVD3

    I've used iMovie3 to make a short (3 min) film, but can't figure out how to burn it. I followed the instructions (several times) by clicking on the iDVD button and hit "create a new iDVD project." The quiet "gerbil" sounds ensued for about 2-3 minute

  • Problem opening illustrator CC document

    I tried open an adobe illustrator CC document in Ai CC in mac environment but it prompted me that the file is in an unknown format and cannot be opened. I am clueless...any one know why? please advise me. appreciate your help alot!