Strange Trust Permissions Issue


hi all,

wonder if can shed light on one...

have server 2008 domain external trust connected server 2000 domain.

on 2000 domain can add users , groups 2008 domain file/folder permissions without problem.

on 2008 domain, when i'm on server 2008 machine , try add user 2000 domain have access file/folder asks me enter network password. try domain admin user 2000 domain , 'logon failure: unknown user name or bad password'

if go 2003 member server on 2008 domain , try adding user have access same file/folder , without hitch...

so, why 2008 servers prompting me user/password when try find users in 2000 domain? there way can 2008 server stop doing this?

thanks
niels

hi niels,

based on research, issue due enhancement of security settings on windows server 2008. prevent windows server 2008 based computer prompting error, please try disable following security option in both local group policy , default domain controller policy.

steps:

1. edit both local group policy , default domain controller policy on windows server 2008.

2. find , locate

computer configuration\windows settings\security settings\local policies\security options

disable following option:

microsoft network client: digitally sign communications (always)


network access: not allow anonymous enumeration of sam accounts , shares

network access: restrict anonymous access named pipes , shares


enable
following option:

microsoft network server: digitally sign communications(if client agrees)
microsoft network client: digitally sign communications(if server agrees)
3. restart domain controller make take effect.


please check if can resolve resources of windows 2000 domain windows server 2008 domain successfully.  dns name resolution issue.

meanwhile, please try set restrictanonymous registry value 1 on windows 2000 domain controller

1.this registry value can found at:

hkey_local_machine\system\currentcontrolset\control\lsa

value: restrictanonymous
value type: reg_dword
value data: 0x1(hex)

2. restart domain controller.

for more reference, please check kb

client, service, , program incompatibilities may occur when modify security settings , user rights assignments
http://support.microsoft.com/kb/823659

hope helps.

posting provided "as is" no warranties, , confers no rights.


Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL