Sorting out Active Directory remote office authentication problems

Sorting out Active Directory remote office authentication problems

    Requires Free Membership to View

Q: We have two sites set up in Active Directory. Whenever someone travels to a remote office, they always authenticate to one of our sites and not the remote office's NT 4.0 Server. Why would this be?

A: My guess is that the laptops are installed with Windows 2000 Professional (or perhaps server). Windows 2000 machines, once they have discovered that an AD exists and there are Windows 2000 DCs, will favor the Windows 2000 DCs for authentication. The laptops will use LDAP and Kerberos for discovery and authentication against the domain. Windows NT 4.0 BDCs cannot perform LDAP and Kerberos authentication, so the laptops bypass the NT 4.0 BDCs and seek out the Win2000 DCs.

This was first published in August 2002

Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.