Jump to content

Do not allow storage of credentials for network authenticati


Recommended Posts

Posted

We are adding some laptops which were previously standalone to our domain and I am replicating the local group policy settings of the standalones into a group policy in the AD. This has been fine except for one setting:

 

On the Local Group Policy in Computer Config > Windows Settings > Security Settings > Local Policies > Security Options you can use Network Access : Do not allow storage of credentials or .Net passports for network authentication which means that when users log in to SSL websites they cannot accidently save their password which can then be used by someone else (all users are using the same login).

 

Where is the equivalent in the AD group policies?

Posted

um.....in the same place :p

 

Edit one of your GPO's and follow the same route:

 

Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options 

...scroll down...

Network Access : Do not allow storage of credentials or .Net passports for network authentication

 

Enjoy :)

Posted

Have you got all the policy templates installed?

 

Open a GPO and Right-click on Administrative Templates on the Computer Configuration section and choose Add/Remove Templates...

 

Yuo should get a window appear with a list of "active" Policy Templates.

 

I have, for example:

 

conf

inetres

system

wmplayer

wuau

 

and likely on other GPO's, I'd have a few extra ones in place.

 

Its quite likely that if you cannot see the policy in my previous post, it would be down to this problem that the policy template isnt "active" on this particular GPO.

 

Just click the Add button and choose from the /inf folder and add ones that are missing.

 

They end in .adm if you down know.

 

I'd wager a quick guess at the system one is missing or outdated [if outdated, get the latest from the MS website. The link is elsewhere on the forum should you need it]

 

Regards

Nath

Posted

Thanks, I have got all the templates installed, including system. But as you say it may be out of date - (June 2003). However because we are on RM CC3 I supose I better not touch it. Quite annoying really.

 

Just out of interest - the client machines are Windows 2000.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...