That would be helpful, but I was also thinking how useful it would be if I could somehow use that information to correlate back to which users were using NTLM so I could see if these were users that were running NT, XP, etc.  Also, I could find out if certain lines of business were using NTLM because it may help me uncover things like custom applications that aren’t using Kerberos, etc.

 

It’s just a thought and it may be too difficult to implement.  But I thought I’d see if anyone had done it.

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ryan A. Conrad
Sent: Friday, March 03, 2006 8:35 AM
To: ActiveDir@mail.activedir.org
Subject: Re: [ActiveDir] "NTLM Authentication" Security Principal

 

In the NTDS performance object there are two counters: NTLM Authentcations and Kerberos Authentications. They wouldn't be able to tell you "who" is authencating using those methods, but they would be able to provide a better idea.  Both counters are in number of requests per second.

 

Ryan

 

On 3/3/06, Rachui, Scott <[EMAIL PROTECTED]> wrote:

I have an interest in finding out how many of the users in our primary
forest are authenticating via NTLM instead of Kerberos.  I know that in
Windows 2003 there is a new well-known security principal called "NTLM
Authentication" which dynamically contains the list of people who
authenticated via NTLM.

My question is, does anyone know how to query this security principal so
I could get that list of people?  Even if it's an ever-changing list, a
snapshot at different times would be useful to see volumes.  I was
thinking of comparing that list to the "This Organization" security
principal so I could tell what % of authentication were NTLM.

If there's another way to do this, I'm open to suggestions as well.
Thanks in advance for any comments.

Scott
List info   : http://www.activedir.org/List.aspx
List FAQ    : http://www.activedir.org/ListFAQ.aspx
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

 

Reply via email to