Vista and Windows 2000 Authenticaiton Problems – Resolved

We have many test systems here. Ranging from Windows 2000 Server, Windows XP Home, to Windows 2008 x64. Something I noticed today while testing…when I tried to connect to some Windows 2000 machines – the remote computer would not accept my password:

Vista Workgroup Authentication Problems

I happened to be working from a Vista Ultimate machine. So I went over to one of our XP Pro installs – it worked fine. The more testing I did, I realized it only happened with machines that were Windows 2000

Immediately I remembered that there were different levels of NTLM authentication, I thought that Vista might be enforcing a higher level through security policy.

On my Vista machine I opened the local policy editor (You can find this under administrative tools in the control panel).

Drilled down to Local Policies -> Security Options

Looking at:

Network Security: LAN Manager authentication level

NTLM Authentication Windows 2000

I see that it only will allow NTLMv2 responses. Since I know that my physical network is protected, and I know all of the machines running on it I changed it to this:

Modified NTLM Authentication Windows 2000

Now I can connect to the admin$ share…and any other share on Windows 2000 computers.

This tip comes with a warning. Obviously dropping this down makes your Vista install less secure. If you think it is possible that you could have a rogue SMB server (A specially crafted windows share) on your network, I suggest not changing this. setting.

Filed Under: Windows

Leave a Reply

Please wait while we add your email address to our list

Join our Tips and Software Email List

Get free software, news, and tips
once a week by joining our email list
Enter your email address below

Just like you, we hate spam.

We promise to never sell, or spam your inbox

Thanks for joining our list, and have a great day!

Error adding address

There was an error adding your email address.
It might be because you are already on our list.
If this is not the case, please try again later. Thanks!