NT Workstation authentication with AD

  • Thread starter Thread starter Brian
  • Start date Start date
B

Brian

I have an NT workstation in Atlanta. There is a local DC
in Atlanta. My PDC Emulator is in Dallas. Will NT
workstations only authenticate against the server that is
the PDC Emulator? If this is true, if my link between
Atlanta and Dallas goes down my NT workstations will not
be able to authenticate to the domain anymore. Is that
correct?
 
-----Original Message-----
I have an NT workstation in Atlanta. There is a local DC
in Atlanta. My PDC Emulator is in Dallas. Will NT
workstations only authenticate against the server that is
the PDC Emulator? If this is true, if my link between
Atlanta and Dallas goes down my NT workstations will not
be able to authenticate to the domain anymore. Is that
correct?


.
Brian,

This is areally good question. I have never actually had
this situation but let's see if we can figure it out.

First of all, in order for your "legacy" clients ( aka
WINNT and WIN9x ) to become a bit AD-aware you should
consider installing the ADClient on them. One of the
benefits is that they now become site-aware.

Secondly, have you configured each Site that you
currently have in Active Directory Sites and Services (
ADSS ), created each existing Subnet that you currently
have and associated each with the appropriate Site? If
not, I would strongly suggest doing so.

Also, have you configured a Reverse Lookup Zone ( RLZ )
in your DNS? If not, pelase consider doing so. And look
at making it Active Directory Integrated.

Since I am here: I strongly suggest to everyone that they
install the Support Tools on each and every WIN2000
Server. The Support Tools are located in two places: the
WIN2000 Server CD in the Support | Tools folder or the
WIN2000 Service Pack CD in the Support | Tools folder.
Given the choice, I would install from the WIN2000
Service Pack.

Take a look at the following MSKB Articles:

How WIN2000 Clients find a Domain Controller
http://support.microsoft.com/default.aspx?scid=KB;en-
us;247811

How WINXP Clients find a Domain Controller
http://support.microsoft.com/default.aspx?scid=kb;
[LN];314861

Generic ( non site-specific ) Records
http://support.microsoft.com/default.aspx?scid=kb;en-
us;306602

Look at the last one and make sure that this is not the
case ( assuming that you have Sites properly set up and
configured ).

HTH,

Cary
 
Cary-

Thanks for the help. You have provided me with a lot of
useful information and I really appreciate it. Hopefully
I can make all this work. :)

-----Original Message-----
-----Original Message-----
I have an NT workstation in Atlanta. There is a local DC
in Atlanta. My PDC Emulator is in Dallas. Will NT
workstations only authenticate against the server that is
the PDC Emulator? If this is true, if my link between
Atlanta and Dallas goes down my NT workstations will not
be able to authenticate to the domain anymore. Is that
correct?


.
Brian,

This is areally good question. I have never actually had
this situation but let's see if we can figure it out.

First of all, in order for your "legacy" clients ( aka
WINNT and WIN9x ) to become a bit AD-aware you should
consider installing the ADClient on them. One of the
benefits is that they now become site-aware.

Secondly, have you configured each Site that you
currently have in Active Directory Sites and Services (
ADSS ), created each existing Subnet that you currently
have and associated each with the appropriate Site? If
not, I would strongly suggest doing so.

Also, have you configured a Reverse Lookup Zone ( RLZ )
in your DNS? If not, pelase consider doing so. And look
at making it Active Directory Integrated.

Since I am here: I strongly suggest to everyone that they
install the Support Tools on each and every WIN2000
Server. The Support Tools are located in two places: the
WIN2000 Server CD in the Support | Tools folder or the
WIN2000 Service Pack CD in the Support | Tools folder.
Given the choice, I would install from the WIN2000
Service Pack.

Take a look at the following MSKB Articles:

How WIN2000 Clients find a Domain Controller
http://support.microsoft.com/default.aspx?scid=KB;en-
us;247811

How WINXP Clients find a Domain Controller
http://support.microsoft.com/default.aspx?scid=kb;
[LN];314861

Generic ( non site-specific ) Records
http://support.microsoft.com/default.aspx?scid=kb;en-
us;306602

Look at the last one and make sure that this is not the
case ( assuming that you have Sites properly set up and
configured ).

HTH,

Cary
.
 
-----Original Message-----
Cary-

Thanks for the help. You have provided me with a lot of
useful information and I really appreciate it. Hopefully
I can make all this work. :)

-----Original Message-----
-----Original Message-----
I have an NT workstation in Atlanta. There is a local DC
in Atlanta. My PDC Emulator is in Dallas. Will NT
workstations only authenticate against the server that is
the PDC Emulator? If this is true, if my link between
Atlanta and Dallas goes down my NT workstations will not
be able to authenticate to the domain anymore. Is that
correct?


.
Brian,

This is areally good question. I have never actually had
this situation but let's see if we can figure it out.

First of all, in order for your "legacy" clients ( aka
WINNT and WIN9x ) to become a bit AD-aware you should
consider installing the ADClient on them. One of the
benefits is that they now become site-aware.

Secondly, have you configured each Site that you
currently have in Active Directory Sites and Services (
ADSS ), created each existing Subnet that you currently
have and associated each with the appropriate Site? If
not, I would strongly suggest doing so.

Also, have you configured a Reverse Lookup Zone ( RLZ )
in your DNS? If not, pelase consider doing so. And look
at making it Active Directory Integrated.

Since I am here: I strongly suggest to everyone that they
install the Support Tools on each and every WIN2000
Server. The Support Tools are located in two places: the
WIN2000 Server CD in the Support | Tools folder or the
WIN2000 Service Pack CD in the Support | Tools folder.
Given the choice, I would install from the WIN2000
Service Pack.

Take a look at the following MSKB Articles:

How WIN2000 Clients find a Domain Controller
http://support.microsoft.com/default.aspx?scid=KB;en-
us;247811

How WINXP Clients find a Domain Controller
http://support.microsoft.com/default.aspx?scid=kb;
[LN];314861

Generic ( non site-specific ) Records
http://support.microsoft.com/default.aspx?scid=kb;en-
us;306602

Look at the last one and make sure that this is not the
case ( assuming that you have Sites properly set up and
configured ).

HTH,

Cary
.
.
Glad to help. Let us know how things turned out.

Cary
 
Back
Top