Go Back   TechArena Community > Technical Support > Computer Help > Microsoft Windows Security > Windows Security
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , , ,

Smart card is required for interactive logon

Windows Security


Reply
 
Thread Tools Search this Thread
  #1  
Old 26-01-2009
Member
 
Join Date: Jan 2009
Posts: 1
Smart card is required for interactive logon

I have several users that logon without smart cards on a daily basis. I also have users that are required to login with smart cards. I have one user in particular that doesn't have a smart card and so his account is setup to allow him to login with a username and password. The problem is that for this one individual every day when he comes into work and attempts to login it tells him he needs a smart card. So everyday he calls me, I go into Active Directory, and sure enough "Smart card is required for interactive logon" is checked. I uncheck this box and he is fine for the rest of the day. Does anybody have any ideas on this?

Reply With Quote
  #2  
Old 07-01-2010
Member
 
Join Date: Jan 2010
Posts: 1
HKLM\Software\Microsoft\Windows\CurrentVersion\Pol icies\System\ScForceOption
SCFORCEOPTION = 1 - change to 0 (zero)

If you don't have this in your registry, you will have to find another way unless your unit is willing to give the poor guy a CAC card.

The thing is if Group Policy is in force the "option" will change back to "1" as soon as the machine is seen by AD and GP... Either way, it's a pain.

It's not possible in a military system to set up an OU... I am giving the "best" answer for those who are not at the OU level. In a corporate environment where "we" would be much 'higher' in the food chain deleting or making an OU might work.

Reply With Quote
  #3  
Old 07-01-2010
David H. Lipman
 
Posts: n/a
Re: Smart card is required for interactive logon

In a US "military" AD the structure for Cryptographic Logon Exceptions ALREADY EXISTS !
Additionally the cards may be generically called SmartCards but that is not the DoD name.

What I described, (setup an OU as a CrytptoGraphic Logon Exception. Then MOVE/CREATE the
user's AD Account into the CrytptoGraphic Logon Exception OU) is industry *best* practice.
Having worked with PKI on AD for 6~7 years, I know this to be a fact.

Final notes...
US Military application of "SmartCards" is not and should NEVER be discussed in public
forums!
Bypassing DoD security measures is a violation of DoD regulations.

Reply With Quote
  #4  
Old 1 Week Ago
Member
 
Join Date: Mar 2010
Posts: 1
Re: Smart card is required for interactive logon

On a related note, has anyone had an issue where if they want to turn on "Require Smart Card" for certain privileged accounts in active directory, it works, but if you then untoggle the "Require smart card" attribute on the user object, it seems to invalidate the active directory user account password, needing a manual password change. The password last set attribute still shows the time of the previous AD password change, but it just seems that toggling "require smart card" mangles it and doesn't update the password last set attribute in AD.

Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Microsoft Windows Security > Windows Security


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads for: "Smart card is required for interactive logon"
Thread Thread Starter Forum Replies Last Post
Windows Vista smart card logon on stand alone machine Michele Vista Security 2 27-05-2009 06:50 PM
SMART Introduces New Generation of Interactive Whiteboard System mauricio Web News & Trends 1 02-12-2008 11:21 AM
Smart Card Certificate based logon with Windows XP SP2 Kr8zyCanuck Operating Systems 2 05-11-2008 04:17 PM
Smart Card Logon JayW Windows Security 7 16-09-2008 04:00 PM
Can't Turn Off "Smart card is required for interactive logon" Jim Burns Windows Security 3 21-11-2006 02:51 AM


All times are GMT +5.5. The time now is 09:01 AM.