Windows Server modifies NTLM network authentication behavior

Microsoft Windows Server 2003 Service Pack 1 (SP1) modifies NTLM network authentication behavior. After you install Windows Server 2003 SP1, domain users can use their old password to access the network for one hour after the password is changed. Existing components that are designed to use Kerberos for authentication are not affected by this change.

INTRODUCTION (kb/906305)
Microsoft Windows Server 2003 Service Pack 1 (SP1) modifies NTLM network authentication behavior. After you install Windows Server 2003 SP1, domain users can use their old password to access the network for one hour after the password is changed. Existing components that are designed to use Kerberos for authentication are not affected by this change.
MORE INFORMATION
To reliably support network access for NTLM network authentication in distributed environments, Windows Server 2003 SP1 modifies the NTLM network authentication behavior as follows:

  • After a domain user successfully changes a password by using NTLM, the old password can still be used for network access for a user-definable time period. This behavior allows accounts, such as service accounts, that are logged on to multiple computers to access the network while the password change propagates.
  • The extension of the password lifetime period applies only to network access by using NTLM. Interactive logon behavior is unchanged. This behavior does not apply to accounts that are hosted on stand-alone servers or on member servers. Only domain users are affected by this behavior.
  • The lifetime period of the old password can be configured by editing the registry on a domain controller. No restart is required for this registry change to take effect.

How to change the lifetime period of an old password
 
ImportantThis section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:
322756 How to back up and restore the registry in Windows
To change the lifetime period of an old password, add a DWORD entry that is named OldPasswordAllowedPeriod to the following registry subkey on a domain controller:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
To do this, follow these steps:

  1. Click Start, click Run, type regedit, and then click OK.
  2. Locate and then click the following registry subkey:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
  3. On the Edit menu, point to New, and then click DWORD Value.
  4. Type OldPasswordAllowedPeriod as the name of the DWORD, and then press ENTER.
  5. Right-click OldPasswordAllowedPeriod, and then click Modify.
  6. In the Value data box, type the value in minutes that you want to use, and then click OK.

NoteThe lifetime period is set in minutes. If this registry value is not set, the default lifetime period for an old password is 60 minutes.
Quit Registry Editor.
Note This registry setting does not require a restart to take effect.
Note This behavior does not cause a security weakness. As long as only one user knows both passwords, the user is still securely authenticated by using either password.
If a user’s password is known to be compromised, the administrator should reset the password for that user. The administrator should ask the user to change the password at the next logon to invalidate the old password as soon as possible.
To reset a user’s password, follow these steps:

  1. Start Active Directory Users and Computers.
  2. Locate the user account whose password must be reset.
  3. Right-click the user object, and then click Reset Password.
  4. Type the new password in the New password box and in the Confirm password box.
  5. Click to select the User must change password at next logon check box, and then click OK.

Note The behavior that is described in this article occurs only if the effective password policy on the domain controllers has Enforce Password History set to a value that specifies that two or more passwords will be remembered. The password policy should be set at the domain level. You can determine whether the policy has taken effect on the domain controllers by using the Secpol.msc snap-in.

© 版权信息:
作者:PANGSHARE
发布平台:PANGSHARE | 文章链接:https://www.pangshare.com/windows-server-modifies-ntlm-network-authentication-behavior/
本文内容仅限非商业性使用,如需商用(包括但不限于广告投放、付费专栏、企业宣传等),请邮件联系原作者获得独家授权,违者将依法追究法律责任。

(0)
打赏 微信扫一扫 微信扫一扫
上一篇 2014年7月31日 下午3:15
下一篇 2014年8月1日 下午12:30

相关推荐

  • 如何在Excel中实现级联菜单

    很长一段没更新雨说,很长一段时间没更新胖胖减肥记,但我每天都会登陆上来看看有没有朋友的留言,虽然每天都看不到浏览吧。哈哈今天在工作上遇到一个自己提给自己的需求,那就是如何在Exce…

    2016年4月19日
    7.3K00
  • Windows Azure Pack 体系结构

    您可以使用快速安装来创建概念证明部署。在快速部署中,所有 Windows Azure 包 的必需组件安装在同一计算机上。如果您还要安装可选组件,将需要其他计算机。快速部署不应在生产…

    2014年4月17日
    9.9K10
  • Win8.1工作组状态下管理Win2012R2Hyper-V

    今天跟大家分享一下在Win8.1工作组状态下如何管理Win2012R2 Hyper-V虚拟机。当然,如果Win8.1和Win2012R2都在域环境下我们就不聊了,直接就可以添加并管…

    2015年7月8日
    8.2K00
  • Azure技术分享 – 构建Lime Survey

    上一篇跟大家分享了在Azure上如果构建PHP环境,(Azure技术分享 – Azure构建PHP环境)下面我们在Azure上开始部署Lime Survey。 准备阶段 登陆Azu…

    微软技术 2014年8月21日
    7.2K00
  • 是时候考虑Windows Server 2012迁移了

    Windows Server 2012被视为数据中心发展过程中的一个关键里程碑,之后微软迅速发布了R2版本。快速的发布速度和其中许多受欢迎的特性无疑为Windows Server …

    2014年4月17日
    8.4K00
  • 如何成为微软MVP

    微软最有价值专家(MVP)是指具备一种或多种微软技术专业知识,并且积极参与在线或离线的社群活动,经常与其他专业人士分享知识和专业技能,受人尊敬、信任,而且平易近人的专家。实际生活中…

    2014年4月17日
    10.2K00
  • WordPress迁移Azure之二WordPress部署

        通过上一篇文章,我们已经在环境中成功的部署了PHP环境,下面我们要做的是下载wordpress程序,并进行部署。     上篇文章中未描述关于My SQL的部署,基本都是普…

    2015年2月1日
    7.2K00
  • 通过Visio快速创建组织架构图

    用Visio画流程图是大家经常使用的,最近有几个复杂的组织架构图需要画,量稍微有点大,只能借助自动化的工具了,想到了使用Visio来做,下面我简单的描述一下步骤。 打开Office…

    微软技术 2014年8月14日
    10.8K00
  • WordPress迁移Azure介绍

    本次要跟大家分享的是WordPress迁移至Windows Azure的过程,从基础讲起,在分享的过程中,对于我也是一个知识沉淀的过程,本系列教程首发站点为雨说博客,为了提高访问量…

    微软技术 2015年1月20日
    7.4K00
  • WordPress使用Windows Live Write报错

    大家好,有段时间没有更新博客了,但是看到其实每天还有访问量,这也是让我比较奇怪的,难道还有粉丝不成?哈哈。近期计划更新一套文章,希望可以跟51cto同步,所以考虑到使用Window…

    微软技术 2015年1月19日
    6.7K00

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

技术交流

有任何问题都能在评论区留言呀~ 小编看到会第一时间回复!

工作时间:周一至周五,9:30-18:30,节假日休息