|
| |||||||||
| Tags: active directory, interactive logon, password, smart card, username |
![]() |
| | Thread Tools | Search this Thread |
|
#1
| |||
| |||
| Smart card is required for interactive logon |
|
#2
| |||
| |||
|
HKLM\Software\Microsoft\Windows\CurrentVersion\Pol icies\System\ScForceOption SCFORCEOPTION = 1 - change to 0 (zero) If you don't have this in your registry, you will have to find another way unless your unit is willing to give the poor guy a CAC card. The thing is if Group Policy is in force the "option" will change back to "1" as soon as the machine is seen by AD and GP... Either way, it's a pain. It's not possible in a military system to set up an OU... I am giving the "best" answer for those who are not at the OU level. In a corporate environment where "we" would be much 'higher' in the food chain deleting or making an OU might work. |
|
#3
| |||
| |||
| Re: Smart card is required for interactive logon
In a US "military" AD the structure for Cryptographic Logon Exceptions ALREADY EXISTS ! Additionally the cards may be generically called SmartCards but that is not the DoD name. What I described, (setup an OU as a CrytptoGraphic Logon Exception. Then MOVE/CREATE the user's AD Account into the CrytptoGraphic Logon Exception OU) is industry *best* practice. Having worked with PKI on AD for 6~7 years, I know this to be a fact. Final notes... US Military application of "SmartCards" is not and should NEVER be discussed in public forums! Bypassing DoD security measures is a violation of DoD regulations. |
|
#4
| |||
| |||
| Re: Smart card is required for interactive logon
On a related note, has anyone had an issue where if they want to turn on "Require Smart Card" for certain privileged accounts in active directory, it works, but if you then untoggle the "Require smart card" attribute on the user object, it seems to invalidate the active directory user account password, needing a manual password change. The password last set attribute still shows the time of the previous AD password change, but it just seems that toggling "require smart card" mangles it and doesn't update the password last set attribute in AD. |
![]() |
|
| Thread Tools | Search this Thread |
| |
Similar Threads for: "Smart card is required for interactive logon" | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Windows Vista smart card logon on stand alone machine | Michele | Vista Security | 2 | 27-05-2009 06:50 PM |
| SMART Introduces New Generation of Interactive Whiteboard System | mauricio | Web News & Trends | 1 | 02-12-2008 11:21 AM |
| Smart Card Certificate based logon with Windows XP SP2 | Kr8zyCanuck | Operating Systems | 2 | 05-11-2008 04:17 PM |
| Smart Card Logon | JayW | Windows Security | 7 | 16-09-2008 04:00 PM |
| Can't Turn Off "Smart card is required for interactive logon" | Jim Burns | Windows Security | 3 | 21-11-2006 02:51 AM |