Groups | Blog | Home
all groups > iis security > august 2004 >

iis security : Integrated WIndows Authentication and IE


Miha Pihler
8/21/2004 9:59:59 AM
Hi Charlie,

There is not much you can do on IIS side, but you can do few things on AD
side (Group Policy- GP)

One thing (that does not involve GP) is for users to use e.g. http://my_site
instead of http://my_site.domain.com. IE should automatically recognize this
address ad Local Intranet.

On AD side, open Group Policy Editor at appropriate level (e.g. domain
level, OU level, ...). Under User configuration open Windows Settings >
Internet Explorer Maintenance > Security > Open Security Zones > click in
Import the Current Security Zone > Modify Settings > Click on Local intranet
[quoted text, click to view]

For security reasons don't enter here sites that are not in trusted network
(LAN).

I hope this helps,

Mike

[quoted text, click to view]

Charlie
8/21/2004 3:45:43 PM
Hi,

I have created an Intranet website and uses Integrated Windows
Authentication to allow domain users who are logged in to AD to access the
Intranet site without being prompted for logon.

However, on all the users PC IE settings, I will need to add the Intranet
site via the IE security options in order for users to access the site
without being prompted.

Is there any way to do anything via the IIS (but still using Integrated
Windows Authentication) without changing all the PC's IE settings ?

Any help is appreciated and thanks in advance.

Charlie

Charlie
8/22/2004 10:37:36 AM
Hi Mike,
appreciate your response.
I will test it out and revert on the status.

Thanks,
Charlie

[quoted text, click to view]
Miha Pihler
8/24/2004 2:53:22 PM
Sorry there is not much I can do about that :-\ ... Still I am pretty sure
you could write a script that would import proxy setting into registry.

Mike

[quoted text, click to view]

Charlie
8/24/2004 8:53:56 PM
Hi Mike,
just to update you that the Group Policy works just fine.

thanks...

However, GP does not run on Win9x.. :(

Regards..

[quoted text, click to view]

Charlie
8/24/2004 9:13:01 PM
Hi Mike and Ken,

thanks and appreciate your reply..

Cheers !!

[quoted text, click to view]

Ken Schaefer
8/24/2004 10:54:07 PM
You will need to use logon scripts for Win9x

Cheers
Ken


[quoted text, click to view]

AddThis Social Bookmark Button