PC Review


Reply
Thread Tools Rate Thread

Authenticate as computer and wireless security

 
 
=?Utf-8?B?SmVhbi1DaHJpc3RvcGhl?=
Guest
Posts: n/a
 
      2nd Jun 2004
We are using PEAP, TKIP and IAS to authenticate against Active Directory.
Some computers are authenticating on our Wireless network ("Authenticate as computer when computer information is available" checkbox cheked).
What could be security issues ? What can "do" a computer authenticated on our wireless network before the user enter his credential ?
How can we avoid that our users check that checkbox ? Any way to avoid that computer authenticate ?

Thanks
(please reply to my email if possible)
Jean-Christophe
 
Reply With Quote
 
 
 
 
Steve Riley [MSFT]
Guest
Posts: n/a
 
      6th Jun 2004
That's a *good* thing, you don't want to disable it!

By having the computer authenticate using its machine account, the computer
will process machine group policies, startup scripts, software installation
settings, software restriction policies -- all the same things that wired
computers do when then they authenticate to the domain.

This is the beauty of 802.1X (whether EAP-TLS or PEAP): wired and wireless
logons behave exactly the same.

Steve
(E-Mail Removed)



"Jean-Christophe" <(E-Mail Removed)> wrote in message
news:06DC6E4D-3B59-45B7-97BF-(E-Mail Removed)...
> We are using PEAP, TKIP and IAS to authenticate against Active Directory.
> Some computers are authenticating on our Wireless network ("Authenticate
> as computer when computer information is available" checkbox cheked).
> What could be security issues ? What can "do" a computer authenticated on
> our wireless network before the user enter his credential ?
> How can we avoid that our users check that checkbox ? Any way to avoid
> that computer authenticate ?
>
> Thanks
> (please reply to my email if possible)
> Jean-Christophe



 
Reply With Quote
 
Steve Riley [MSFT]
Guest
Posts: n/a
 
      6th Jun 2004
That's a *good* thing, you don't want to disable it!

By having the computer authenticate using its machine account, the computer
will process machine group policies, startup scripts, software installation
settings, software restriction policies -- all the same things that wired
computers do when then they authenticate to the domain.

This is the beauty of 802.1X (whether EAP-TLS or PEAP): wired and wireless
logons behave exactly the same.

Steve
(E-Mail Removed)



"Jean-Christophe" <(E-Mail Removed)> wrote in message
news:06DC6E4D-3B59-45B7-97BF-(E-Mail Removed)...
> We are using PEAP, TKIP and IAS to authenticate against Active Directory.
> Some computers are authenticating on our Wireless network ("Authenticate
> as computer when computer information is available" checkbox cheked).
> What could be security issues ? What can "do" a computer authenticated on
> our wireless network before the user enter his credential ?
> How can we avoid that our users check that checkbox ? Any way to avoid
> that computer authenticate ?
>
> Thanks
> (please reply to my email if possible)
> Jean-Christophe



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
how to authenticate to another computer management console SBS user Windows XP General 1 23rd Oct 2008 10:36 PM
Authenticate as computer and wireless security =?Utf-8?B?SmVhbi1DaHJpc3RvcGhl?= Windows XP Help 3 12th Nov 2004 12:11 PM
Authenticate as computer and wireless security =?Utf-8?B?SmVhbi1DaHJpc3RvcGhl?= Microsoft Windows 2000 Security 2 6th Jun 2004 03:59 AM
WinXP, cannot authenticate computer error at logon - Reboot Mark Windows XP General 1 21st Feb 2004 10:08 PM
Re: Using XP to authenticate wireless users...radius maybe? NeKeta [MSFT] Windows XP General 0 21st Nov 2003 04:24 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 05:41 PM.