Can access domain network resources while logged on as a local administrator on a workstation.

Please help me in figuring this one out.
I have a Server 2003 R2 domain with a bunch of workstations and some servers having the same local admin password.
I know it is not good practice, but that's an issue of it's own.
The issue is that when I log on as that local admin (WORKSTATION\Administrator) I can suddenly browse to ALL the hidden shares(c$, d$) of ALL the servers and workstations that have the same local admin password. If I change password or disable that account
the symptom goes away.  I though if I do try accessing hidden shares it should still ask me for credentials, after all these are local credentials on DIFFERENT machines. I checked to make sure that the credentials are not cached and as far as I can tell
they are not. This really freaks me out.
This is kind of a big deal because even if I change local passwords on servers, I'm not sure we will be setting up different local Administrator password for each workstation.
My question is: Is this the a normal/documented Windows behavior? If not why is this happening? Can someone please explain how is this possible?

Yes, this is the default behavior for workgroup machines - this is so-called pass-through authentication of the NTLM protocol. You can lock down the usage of NTLM with policies.
I have accidentally just tested pass-through authentication as I am working on a solution that involves a bunch of servers that are not in a domain. Without this sort of authentication you could not do authentication easily against another machine in such
an environment.
Admin power is limited though: Even if the user in question is admin on both machines and you try to remotely reset a password in an admin cmd session (e.g. using pspasswd) it will fail because of UAC per default - unless you tweaked UAC or related registry
keys.
I tried to find some official documentation: In
this book (hope it works - link to page via Google books) on Windows security pass-through is explicitly mentioned as the method used in a workgroup environment, this
MS support article explains NTLM passthrough authn in a domain environment.
I have seen some articles that say that NTLM is locked down per default on newer OS - but I can confirm if works if e.g. connecting from a W2K8 R2 server to a Windows 7 machine (both workgroup machines, no domain policies applied).
Elke

Similar Messages

  • FaceTime reports Network failure while logging! help appreciated

    I upgraded my intel Imac software to Os X 10.7.2. While logging on to  FaceTime - reports "error in network connection. check with your sevice provider" and my net connection drops very frequently since the upgrade from snow leopard.
    On my Ipad I can successfully logon to FaceTime on the same network! I have Mac Keeper antivirus software installed. Seek help. Thanks.

    I don't have a solution to your problem, but I would recommend getting rid of MacKeeper now. It will cause you a LOT more trouble than it's worth.

  • VPN clients can't see network resources unless Firewall is disabled.

    If the firewall is turned off, connected VPN clients can access other PCs over the VPN. But I would like to enable a rule that allows them to access computers even with the firewall turned on. I just don't know what the rule should be.

    Hi,
    Any update? If you could update us at your convenience that would be wonderful.
    Regards
    Yolanda Zhu
    TechNet Community Support

  • I ran an iTunes update on a PC Win 7 and got "apple mobile device failed to start verify that you have sufficient privileges to start system services" ? I deleted iTunes, ran download, and now I can't reinstall. I am logged onto the PC as Administrator.

    I ran iTunes update 11.1.4.62x64 on a PC Win 7 and got "apple mobile device failed to start verify that you have sufficient privileges to start system services" and got kicked out of the install process? I deleted iTunes, ran download to reinstall, and now I can't reinstall - same error message. I am logged onto the PC as Administrator. How do I downlaod and install iTunes.

    Try the following user tip:
    Troubleshooting issues with iTunes for Windows updates

  • How to add first log on user to local administrator group

    Hi All,
    When first time user log in to system, i need to add that particular user to local administrator group?
    How to achieve it using vbscript?
    Thanks
    Divakar

    It is also now against federal law in the US, Canada and, I believe, the UK. 
    In the US HIPAA and the federal network security act (???) and Sarbanes-Oxley all prohibit users running as Admins.   This may not specifically affect your
    installation but it does show how important this is.
    There is NEVER a good reason to make a user an administrator.  It is only lack of technical know how that leads to this scenario.  Any vendor product that
    requires this is not a safe product to use in a corporate network.  Malware specifically looks for this as an attack vector.
    I spent three years arguing with Inuit to get there software to work.  Every time they said you have to run as an admin I told them it would never be.  We
    were always able to find a way.  Now QuickBooks installs as a standard user with no issues.
    It can be done.
    ¯\_(ツ)_/¯
    It is also now against federal law in the US, Canada and, I believe, the UK. 
    In the US HIPAA and the federal network security act (???) and Sarbanes-Oxley all prohibit users running as Admins.   This may not specifically affect your
    installation but it does show how important this is.
    There is NEVER a good reason to make a user an administrator.  It is only lack of technical know how that leads to this scenario.  Any vendor product that
    requires this is not a safe product to use in a corporate network.  Malware specifically looks for this as an attack vector.
    I spent three years arguing with Inuit to get there software to work.  Every time they said you have to run as an admin I told them it would never be.  We
    were always able to find a way.  Now QuickBooks installs as a standard user with no issues.
    It can be done.
    ¯\_(ツ)_/¯

  • Accessing a network resource via javascript

    Hello,
    we have been using Adobe Reader for linux provided by the yum repository for quite some time, without major issues. Currently, however, we are seeing a mysterious problem with a PDF form which is designed to exchange data with a local server, using javascript functionality, as far as I can see. On one of our machines (running CentOS 5.8 64-bit) this has stopped working recently, and I cannot figure out why. Clicking the respective field simply has no effect, there is no error message, neither in the Reader window, or on the console, both in normal mode and debug mode. Nothing in the system logs either. The function simply seems to be ignored!
    Some observations which might be helpful:
    1. Uninstalling and reinstalling the Reader package, after clearing all personal preferences, did not have any effect.
    2. Using a fresh version of the PDF form did not solve the problem.
    3. Firewall and SElinux are disabled anyway.
    4. With a "clean" account on the same machine, the same problem occurs.
    5. On a very similar machine (same OS, same Reader version) the operation is working properly!
    So it seems to be something specific to this machine, but not specific to a certain account. It is obviously neither a corrupted Reader installation, nor a problem with this specific reader version, nor a corrupted PDF form. Now I am running out of ideas...
    Any suggestions what else might be preventing network access (via javascript) from functioning properly? Javascript itself is (by default) enabled in the preferences.
    Thanks in advance
    Oliver

    Sorry for the double post, but help would be appreciated...

  • Can't add any users while logged in as the ADMIN

    Back in my post, http://discussions.apple.com/message.jspa?messageID=5314598#5314598 , I was stuck in a broken auto login, unable to get past the solid blue screen. I was able to fix that but now I can not add any new users to the accounts pane. Logged in as the ADMIN, I click on the + and nothing happens. I can not add anymore accounts. What can I do to solve this?

    It is probably some residual effect from your single user mode actions detailed in your previous post.
    Run *Repair Permissions* from Disk Utility to see if that is the cause.
    If that doesn't fix it, try deleting the com.apple.loginwindow.plist from your admin account's Library/Preferences folder.
    There is also the same file in
    HD/Library/Preferences/com.apple.loginwindow.plist
    but I am not sure about the consequences of deleting that, as I've never done it.
    Whichever you delete, log out and log back in again to re-create them.

  • IPhone5 can access guest network without password

    I have just finished setting up the Cisco Valet M20 and tried to access the "guest network" using password. All devices connected to "guest network" were taken to a login screen for a password. All except the iPhone5. The phone was able to have connect wirelessly without having to go to the login screen and enter the guest password. I have tried changing "guest network's" password and resetting the network configuration of my iPhone5, still the same result.  My laptop, iPad and andriod phone did go  through the login screen for password. Is there a fix to this problem? 

    Since other wireless devices were working thru the guest network as they should, I believe it has something to do with the IPhone5. How about you try this workaround: disable the guest network, turn the M20 off for 10-15 seconds, once you power it back on, access the cisco connect software again and enable the guest network. On your iphone, try to reset the network settings again then try to connect to the guest network.

  • On wake, MBAir can't see network resources?

    I've been pulling my hair out trying to figure this out, but basically I just close my MBAir when I'm done and I don't shut it down - so it's just sleeping.  Well, when I wake it up it gets a network connection and everything works... except that it can't see my network printer, network drives, or other mac on the network.
    First solution that works is to reboot, but of course that shouldn't be the case.  The other solution that seems to work is turning off my wi-fi connection and turning it back on again.  Voila!  I can see everything.  I just don't know why I would need to do that and I don't know if that's a problem with the MBAir hardware or Lion.
    Ideas folks?
    Thanks.
    AC

    Hi,
    As you mentioned several times in the post that you set up the VPN with a router. In this way, there will be no VPN Server or VPN client, all the computers and router are in the same network.
    When you dial in the network with another computer, there will be another internet connection icon appeared at the Network and Sharing Center, then right click the icon, then click set as default connection.
    In this way, all the computers can visit each other.
    There is still one thing that confuses me, do you deploy a VPN server with a windows server? Or with a third party software? I don’t understand what do you mean the “VPN server”.
    I think you should post more information about the VPN server for further troubleshooting.
    Regards,

  • Post laptop crash: form won't submit/can't access network resource

    I distributed a form on 5/12 through the 'distribute form wizard' in Acrobat 9 Pro. On 5/14 my laptop motherboard fried. We retrieved my data & imaged another computer, but then my responses file seemed to have issues, not wanting to import any responses, and it appeared I'd lost data. Fastforward to today: I have my laptop back w/new motherboard, and the original responses file is intact including data from responses made last week before the crash. Form submission deadline was yesterday, and I'm missing responses I expected to have by now. I used the link to checkout the form's condition and filled it out myself and learned it can't be submitted.Error msg: 'Acrobat could not submit your data. Please see Tracker for more information.' Tracker says Could not access the network resource.
    So the question is..... how do I fix this, and can I repair this without notifying all the people or what? This is critical - I'd done so much testing before distributing the form, but who would have known the end was near for my motherboard? I'm assuming that incident had something to do with all this, although I'm not sure I understand exactly why. Please help...thanks! --Karen <>

    Hi.  I have had very similar problems and have not received any help at all.  Have you?

  • PC Still Can Access Network without Joining AD in ISE Environment

    Hi Folks,
    I'm new to ISE and I have a problem about access control with ISE and here's my situation:
    The wired 802.1X is deployed with windows AD using ISE. For now, Clients joined the domain can access the network well, however, for computers which havn't joined the domain can also access the network if the users know their account of the domain. They can start the 802.1X service by themselves and configure the network card properly, connect the network cable, when the windows dialog pops up, the user can enter the username starts with the domain like "mydomain\username"(mydomain is the domain name) and the passowrd, then the computer can gain the access just like it had joined the domain. So I think there may be some mistakes with my Authentication and Authorization Policy.
    My authentication policy is configured like this:
    the ChinaPnR-ISE is the AD name
    My authorization policy is configured like this:
    I'm wondering if I can add one condition to math the hostnames of the windows as computers which had joined have the unified format?
    Thanks!

    It didn't really work for me.
    I managed to set up the AEBS better now, but still no true networking.
    I can access the USB HDD from the iMac that is connected via the WAN port on the AEBS. But it's not mounted.
    I started up my old iMac, and connected to my network. Interestingly, if I search through the folders in the network link of my old iMac, I find the USB HDD and can actually access it!
    The old iMac also sees my netbook (identified by brand and MAC address, which I recognise and is correct for the netbook).
    When trying to access that netbook, it asks for a workgroup, a user name and a password. No idea why and what those may be. I assume I have to set those up on my netbook?
    Then when trying to do software updates on the old iMac, it does not seem to be able to connect, whilst I have safari open and running fine on the same machine at the same time, what's up with that???
    In the mean time my new iMac does NOT see the netbook or the old iMac. I wonder why that is?

  • I cannot access firefox. but i can access it if i use another log on name from the same computer. how do i get to my bookmarks from my log on name.

    i can access firefox from a different log on name but not my own. i want to retrieve my bookmarks.

    See if you can boot into the Safe Mode.
    Safe Mode - About
    Safe Mode

  • I can't print from network computer while in bootcamp

    Although I can see the network printer while in Windows 7 on bootcamp, I can't get it to print.  I am trying to print reports from Quicken 2012.  Any ideas?  

    Then this could be a driver issue. What brand and model of printer do you have? I want to check what driver options are available for this model.
    The other possible cause is the protocol you have used, although Windows is often better at selecting the correct protocol to use compared to Mac. To check what you are using on Windows, open Devices and Printers and select the printer. Then right-click its icon and select Printer Properties. Then select the Ports tab and then click on Configure Port. Is the queue configured to use LPD or RAW?

  • Direct Access DNS resolution local domain network

    Hey guys,
    some information to my test environment...
    My direct access server and my DC are based on Windows Server 2012 R2. The direct access server has one nic. Port 443 requests are forwarded through an firewall to the direct access server. The configuration for direct access is based on the built in assistens
    to configure it.
    On client side i am using Windows 8.1 x64.
    Now the to my problem...
    If I do an ping or a gpupdate when i am not connected to my local company network, the server responds and gpupdate/ping works fine. As soon as i am connected to my local company network i am not able to do a gpupdate or a ping (error in resolving dns).
    But i am able to use nslookup to query names.
    Anyone a suggestion where the problem could be?

    Hi,
    It seems that this problem is caused by the issue of Network Location Server.
    Does the client know that it is connected to the local network?
    When the client connects to the local network, it should show "Connected to network locally or through VPN".
    Here is the screenshot of my lab server,
    Aslo, we can use the command below to verify this,
    netsh dns show state
    The Machine location should be "Inside corporate network"  when the client is connected to the local network.
    If the client doesn't know that it is inside the corporate network, please check if client can access the Network Location Server.
    Best Regards.
    Steven Lee
    TechNet Community Support

  • My PC is connected to my airport by Ethernet. I can connect to the network, but not the internet. My wireless devices can access the internet

    My PC is connected to AirPort Extreme by ethernet, I can access the network, but not the internet. The wireless devices on the extreme can access the internet

    Hey DM,
    Is the Wireless(WL) router signal coming through the wired-router?
    My ISP requires that my Wireless Router is identified from their end. I use AirPort Express, so they need its MAC address from the router. Without that, my network will show up, but my ISP doesn't recognize it and won't allow it to route he internet. I don't know your exact situation though.
    Can other wireless computers access the internet? If they can through the WL router, then it might be the MacBook. If they can't, then you might want to contact your ISP and ask if they can see your wireless router?
    Let us know.
    Adam

Maybe you are looking for

  • SSL configuration for ABAP engine

    Hi Experts, Can you please tell me how to configure SSL on ABAP engine? Can you please guide me in details of the first part i.e. installation of SAPCRYPTOLIB for ABAP part? I am not getting the document properly. I am telling you what I have done. 1

  • Macbook pro 13 Speaker problem

    When I listen to music in Mono, it's supposed to be that the speakers sound exactly the same from both channels. But when I move the balance of the speakers in System Preferences, the left speaker sounds very distorted and muffled and in the right sp

  • 1130AG Lightweight IOS V12.(7)JX - static ip on it can't removed

    Hi there - I'm stuck on this problem... my 1130AG lightweight access point has and static ip address on fa0 AP0007.0e5f.f430#show ip int brie Interface IP-Address OK? Method Status Protocol FastEthernet0 10.40.0.1 YES other up down I want to clear th

  • Local Director SNMP for CPU and Memory

    Is there any way to get the CPU and memory utilization from a Local Director using SNMP? When I do an SNMP walk, I don't see any objects for CPU and memory. Thank you

  • 29.97 Drop Frame Broken?

    Hey all, I'm trying to lock Pro Tools up to Logic 8, like I've been doing in Logic 7 for years. Strangely, it only works if I put PT into 29.97 (non drop). Whether or not I put Logic into 29.97df or not, PT locks up if it's in 29.97 non drop. This su