
Microsoft
®
Windows Server
™
2003 White Paper
Windows NT 4.0 Server Upgrade Guide 142
Figure 67. Permissions Compatibility dialog box
On servers running Windows NT Server 4.0 and earlier, read access for user and group
information is assigned to anonymous users so that existing applications, including Microsoft
BackOffice
®
, SQL Server, and some non–Microsoft applications, function correctly.
In Window 2000 and Windows Server 2003, members of the Anonymous Logon group have read
access to this information only when the group is added to the Pre–Windows 2000 Compatible
Access group.
Using the Active Directory Installation Wizard, you can choose if you want the Anonymous Logon
group and the Everyone security groups to be added to the Pre–Windows 2000 Compatible
Access group by selecting the Permissions compatible with pre-Windows 2000 server
operating systems option. To prevent members of the Anonymous Logon group from gaining
read access to user and group information, choose the Permissions compatible only with
Windows Server 2003 operating systems option.
You can manually switch between the backward compatible and high-security settings on Active
Directory objects by adding the Anonymous Logon security group to the pre-Windows 2000
Compatible Access security group using the Active Directory Users and Computers snap-in.
Choose the first option if there are other Windows NT 4.0 domain controllers and servers that still
need to communicate with the Windows Server 2003 Active Directory domain. This option
reduces security but is absolutely necessary if these servers exist. Choose the second option if no
other Windows NT 4.0 domain controllers or servers exist. After making this selection, a dialog
box asks for the Restore Mode password as the figure below shows.
Kommentare zu diesen Handbüchern