This behavior occurs if all of the following conditions are true:
� | The Active Directory Installation Wizard (DCPROMO) was used on the domain controller.
-and- |
� | The permission preference for DCPROMO was set to Permissions compatible only with Windows 2000 Servers.
-and- |
� | The Web server does not have Basic Authentication turned on (enabled). |
When you run DCPROMO, the built-in Pre-Windows 2000 Compatible Access group is added to the access control lists (ACLs) and user rights throughout Active Directory and the domain controller. However, when the
Permissions compatible only with Windows 2000 Servers preference is selected, the Everyone group is not nested in the Pre-Windows 2000 Compatible Access group. Therefore, the anonymous account does not have read access to the User Accounts Database (SAM) on the domain controller.