Kerberos will be used by default on all W2K/XP Pro/W2003 computers though
there can be exceptions if the time skew between computers is more than five
minutes, which should not normally happen since domain computers will synch
their time with the pdc fsmo, or if a share/computer is accessed by IP
address instead of name. To find out what is being used you can enable
auditing of account logon events in Domain Controller Security policy and
audit logon events for domain computers and examine the logons in the
security log for authentication type. If your domain is all W2K/XP Pro/W2003
it would be a good idea to set the lan manager authentication level security
option to send ntlmv2 Reponses only - refuse lm for Domain and Domain
Controller Security Policy. --- Steve
http://www.microsoft.com/resources/...dowsserv/2003/standard/proddocs/en-us/576.asp
-- description of security option for lan manager authentication level