When you run the Active Directory (AD) installation wizard, DCPROMO, to create a new AD domain (as opposed to creating an additional domain controller—DC—in an existing domain), you encounter a configuration screen that lets you specify default permissions for user and group objects within AD. If your domain will include any Windows NT 4.0 RAS servers, you should select "Permissions compatible with pre-Windows 2000 Servers" to ensure that the system will reliably authenticate and grant access to dial-up users. Why? To help us understand this Win2K domain configuration issue, let's look quickly at how NT 4.0 processes dial-up user authentication requests.
You must be a paid Professional Member to access this entire article.
Already a Professional Member? Please log in now: