How can I disable 4.0 RAS servers in a Windows 2000 domain?

John Savill

November 22, 1999

1 Min Read
ITPro Today logo in a gray background | ITPro Today

A. When you run DCPROMO.EXE to create your Windows 2000 domain one ofthe stages asks if you wish to weaken security to enable 4.0 servers to act asRAS servers. If you said Yes but later decide you don't require this enter thefollowing command:

C:> net localgroup "Pre-Windows 2000 Compatible Access" everyone
/delete

This removes everyone from the local group "Pre-Windows 2000 Compatible Access". After entering the command you must restart thedomain controller.

Security may be compromised when enabled because it allows anonymous users to read information in this domain. When Windows NT 4.0 RAS servers no longer exist in the domain, you can remove legacy access to Active Directory by using thecommand above.

About the Author

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like