Cross Domain Authentication Not Working As Expected
we experiencing unexpected behavior when authenticating different domain.
expected behavior when accessing resource on server in domain different domain user logged (workstation different - user , workstation both belong same domain) user prompted username , password enter credentials specific domain. path fqdn path (\\servername.domain.dmn\share).
what getting "the specified "path cannot found" and/ or "access denied". however, mapping drive letter resource , choosing "connect using different credentials" works expected.
on server in desination ad - security event log shows authenticaton attempt , displaying originating username , domain of user - failed of course.
any appreciated.
>>user , workstation both belong same domain) user prompted username , password enter >>credentials specific domain.
this not default behavior of windows os (any version) when both user , target server members of domains/trusted domains. default when target server or source user in workgroup or un-trusted domain. far know behavior cannot modified.
>>what getting "the specified "path cannot found" and/ or "access denied". however, mapping drive letter >>resource , choosing "connect using different credentials" works expected.
works expected? meaning user typing in what? same domain\username logged in as? or a different domain\username? latter.
since the response "access denied" expected....the user not have access, , should grant user access. access denied awalys indicates attempted login failed, shown in event log, , os not prompt second authentication attempt. not problem design. should grant user proper access.
more information:
built windows os (any version) automatic login, between computers regards of domain or workgroup membership. in workgroup/un-trusted domain model on failed login attempt (not access denied, rather unknown username/password) second prompt presented user. in domain/trusted domain model authentication successful, access may denied because of security. in case no second prompt present user.
from have explained appears security working expect, , correctly. have not configured permissions correctly.
Windows Server > Directory Services
Comments
Post a Comment