Cross forest authentication
I have to sites that are in completely separate forests that do NOT have trusts. The client has set up the same usernames in both forests (I know, I know). They want users in Forest A to access folder shares in forest B using UNC paths, their expectation is that it would pop up a username/password prompt for them to login. It actually DOES work for some people, but for other people it locks their account out in Forest B before asking for their user/pass. I'm in the process of getting them to set up trusts...but until then I just need to understand why it woks for some and not others? These are XP machines.
April 17th, 2011 10:51am

it would appear that some of the users have the same passwords on both accounts, while other users have different passwords. For those users that have different passwords, the accounts are locking. Visit: anITKB.com, an IT Knowledge Base.
Free Windows Admin Tool Kit Click here and download it now
April 17th, 2011 1:46pm

No they all have different passwords...for some users it asks for a user/pass and once they enter it it works, for other users it still asks for a user/pass but the accounts get locked out on the other forest even before they enter it...
April 17th, 2011 3:06pm

Hi, If I understand correctly, all the users are prompted for credential when they try to access the share in forest B. But some accounts get locked before the users try to enter their credential. I suggest that we start by enabling logon audit in forest B. In this way, we can confirm where the bad password attempts come from and result in the lockout. Meanwhile, for the users encounter the account locked out issue, please check if there is any mapped network drive on the their computer. The following article could be helpful to understand the behavior: Troubleshooting Account Lockout http://technet.microsoft.com/en-us/library/cc773155(WS.10).aspxThis posting is provided "AS IS" with no warranties, and confers no rights. Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
April 18th, 2011 5:45am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics