Trust between Windows 2003 and Windows NT

Trust between Windows 2003 and Windows NT

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Trust between Windows 2003 and Windows NT Eduard Timchenk 07-12-2005
Posted by =?Utf-8?B?RWR1YXJkIFRpbWNoZW5r on July 12, 2005, 12:52 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello
I have to define trust between Windwos 2003 DC and Windows NT DC
I order to do that i used following link
http://support.microsoft.com/kb/246261/

As part of procedure i had to set RestrictAnonymous to 0 (otherwise i could
not see WinNT users in Win2003 domain).

In Windows 2000 RestrictAnonymous parameter had three options and trust did
not worked with value 2, but worked with value 1.

In Windows 2003 the only options are 0 or 1. I want to minimize security
risk. Do i have an option to set security to the level that equivalent value
1 in Windows 2000?

Thanks
--
Eduard Timchenko
Business Technology Solutions Group
Verint Systems

Posted by Steven L Umbach on July 12, 2005, 3:11 am
If you were  Registered and logged in, you could reply and use other advanced thread options
In my expereince that value of 1 in Windows 2000 does not add much if any
protection from anonymous access. The options to restrict anonymous access
in Windows 2003 are more granular than in Windows 2000. The main three are
network access: do not allow anonymous enumeration of sam accounts, do not
allow anonymous enumeration of sam accounts and shares, and let everyone
permissions apply to anonymous users [which is disabled by default in
Windows 2003]. I am not sure exactly what you need configured and you could
test it out but I would advise that you read the KB link below that
discusses imcomapibilites of security settings with downlevel clients and
domains and goes into good detail on the anonymous access settings. In my
opinion the main concern is that your firewall protects your network so that
untrusted networks do not have access to information that they could
enumerate to use against you. Enforcement of strong passwords in the domain
will greatly reduce the risk of users being able to use the information that
they can access via a null session such as users/group names. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;823659


> Hello
> I have to define trust between Windwos 2003 DC and Windows NT DC
> I order to do that i used following link
> http://support.microsoft.com/kb/246261/
>
> As part of procedure i had to set RestrictAnonymous to 0 (otherwise i
> could
> not see WinNT users in Win2003 domain).
>
> In Windows 2000 RestrictAnonymous parameter had three options and trust
> did
> not worked with value 2, but worked with value 1.
>
> In Windows 2003 the only options are 0 or 1. I want to minimize security
> risk. Do i have an option to set security to the level that equivalent
> value
> 1 in Windows 2000?
>
> Thanks
> --
> Eduard Timchenko
> Business Technology Solutions Group
> Verint Systems



Similar ThreadsPosted
Windows Update fails on Windows 2003 server June 23, 2005, 7:27 pm
Windows 2003/Windows XP security question November 18, 2006, 12:34 pm
windows 2003 with sp1 ICF September 12, 2005, 5:06 am
Windows 2003 SP1 January 26, 2006, 5:26 am
802.1x on Windows 2003 x64 March 8, 2007, 4:00 pm
Windows 2003 CA 0x80092013 June 28, 2005, 4:25 am
RE: WIndows Server 2003 July 29, 2005, 12:16 am
Windows 2003 server SP1 September 16, 2005, 12:06 am
Windows 2003 DCOM October 17, 2005, 11:00 pm
windows 2003 activation December 6, 2005, 5:32 am

The site map in XML format XML site map

Contact Us | Privacy Policy