Article ID: 296094 - Last Review: October 31, 2006 - Revision: 2.2 HOW TO: Set Up the Internet Authentication Service for Multiple Domain Logon Sessions by Using the Realm Replacement RulesThis article was previously published under Q296094 On This PageSUMMARY
This article describes the steps to set up the Internet Authentication Service (IAS) in Windows 2000 for multiple domain logon sessions by using the Realm Replacement rules.
The IAS enables the authentication of user accounts that are located in the same domain as the Remote Authentication Dial-In User Service (RADIUS) server. Also, the IAS can be configured to authenticate users in specific child domains that are in the same Windows 2000 forest. If the RADIUS server is located in DomainA and the user account that the server is trying to authenticate is in DomainB (a child domain), the user must specify "DomainB\username" during the logon process. You can use a Realm Replacement rule to specify a user principal name (UPN). The IAS (RADIUS) server searches the global catalog (GC) server for all child domains, and then authenticates the user. Set Up IAS to Authenticate a User AccountTo set up the IAS to authenticate a user account in any domain that has a "Microsoft" name in the same Windows 2000 forest:
To be successful, the UPN for all users in the same forest must use the "@forestname.com" format, instead of the "@child.forestname.com" format. Typically, users make two common mistakes when they use the Realm Replacement rules:
If the Windows 2000 IAS Server is a member of a Windows NT 4.0 domain and it is validating logons for trusted Windows 2000 domains, the Everyone group must be added to the Pre-Windows 2000-Compatible Access group in each Windows 2000 domain that is to be validated. After the server receives ACCESS_REQUEST from a Remote Access Service (RAS) or Network Access Server (NAS), the that is running IAS Server must contact the specified domain to confirm that the user name has dial-in permissions before it issues an ACCESS_GRANTED. In this situation, unless Everyone is in the Pre-Windows 2000-Compatible Access group, the contacted domain will refuse the IAS login as coming from a downlevel domain member and the RADIUS authentication will fail.
| Article Translations
|
Back to the top
