Enabling Claims Support on Domain Controllers


hello,

since there's no dedicated server 2012 directory services forum, post my question here...

following white paper dynamic access control, 1 of steps required enable claims based auth. enable gpo setting dcs hand out claims to

clients. far good.

however, ask myself: wouldn't better achieved automatically enabling feature when switch server 2012 domain/forest functionality mode?

enabling feature via gpo can lead situation in mixed environment win8 clients claims because authenticate 2012 dc , not because authenticate downlevel dc. hence you'll inconsistent behavior when access resources.

any insight apprecaited!

thanks

christian

hi,

claim-based authorization , auditing not have forest functional or domain functional requirement. can implement , configure claims mixture of windows server 2003, 2008, , 2008 r2 domain controllers provided domain has enough windows server 8 beta domain controllers support authentication requests include claim information.

for more information, please refer following microsoft article:

understand , troubleshoot dynamic access control in windows server "8" beta

http://www.microsoft.com/downloads/details.aspx?familyid=b3b9e3e1-3447-4f8c-8a30-f0f2421b2d04&displaylang=en&displaylang=en

regards,


arthur li

technet community support



Windows Server  >  Windows Server 2012 General



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...