[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference decwet::windows-nt

Title:Windows NT
Notice:See note 15.0 for HCL location
Moderator:TARKIN::LIN.com::FOLEY
Created:Thu Oct 31 1991
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:6086
Total number of notes:31449

6041.0. "WNT domain security" by TPOVC::SIMONLEE () Mon May 26 1997 12:44

    
    It seems nobody asked questions of this sort. If you think my question is
    stupid, please forgive me.
    
    In a windows NT domain, there is a windows NT server (neither PDC nor
    BDC). If I have a local account on the server and I have a domain
    account with the same username and password as that local account, when
    I logon to the server, I get the same access privilege to the domain as
    if I have logon to the domain. Is this intensionally designed to be so,
    or is it a security hole? If it is normal, it implys that you
    automatically logon to domain when you logon to the server. It is in
    many cases not desirable. Can anybody give comments and give me correct
    information about the MS domain design philosophy? Thanks!
    
    
    /Simon
    
    
    
T.RTitleUserPersonal
Name
DateLines
6041.1BIGUN::nessus.cao.dec.com::MayneA wretched hive of scum and villainyMon May 26 1997 20:145
This is intentional.

If it's not desirable, use a different password.

PJDM
6041.2alf_dial7_port1.alf.dec.com::jenningsI'm still hereTue May 27 1997 09:054
The behaviour you see is intentional.  If you don't want it, use different 
passwords and/or usernames for the account(s).  Microsoft is assuming that if the 
two accounts have exactly the same username and password, then it must be the 
same person.