{"id":427,"date":"2017-10-19T09:04:10","date_gmt":"2017-10-19T09:04:10","guid":{"rendered":"https:\/\/www.web-workers.ch\/?p=427"},"modified":"2018-11-22T18:21:45","modified_gmt":"2018-11-22T18:21:45","slug":"windows-share-access-error-the-computer-you-are-signing-into-is-protected-by-an-authentication-firewall","status":"publish","type":"post","link":"https:\/\/www.web-workers.ch\/index.php\/2017\/10\/19\/windows-share-access-error-the-computer-you-are-signing-into-is-protected-by-an-authentication-firewall\/","title":{"rendered":"Windows Share Access: Error \u2013 The Computer You Are Signing Into Is Protected By An Authentication Firewall"},"content":{"rendered":"<h3>Problem<\/h3>\n<p>Today a customer contacted me, he told me the tries to map a network drive by using a \u2018net use\u2019 command. Unforantelty the command thows an error message as below.<\/p>\n<p><code>Protected By Authentication Firewall<\/code><code> System error 1935 has occurred<\/code><code>The computer you are signing into is protected by an authentication firewall. The specified account is not allowed to authenticate the computer.<br \/>\n<\/code><\/p>\n<p>I knew the customer is in the middle of a active directory migration and has established a trust between two domains. I googled around and i found <a href=\"https:\/\/www.petenetlive.com\/KB\/Article\/0001241\" target=\"_blank\" rel=\"noopener\">interesting information on Pete Longs PeteNetLive page<\/a>. This information gave me the hint, that this customer probably was using a trust relationship that was configured with selective authentication. In this case it&#8217;s required to explicitly &#8220;Allow to Authenticate&#8221; rights on the requested resource.<\/p>\n<h3>Solution<\/h3>\n<p>The root cause is in this case, the user (or the group the user is a member of)\u00a0has been granted the correct rights to get access to the share but obviously the\u00a0share is hosted in another domain.<\/p>\n<p><a href=\"https:\/\/www.web-workers.ch\/index.php\/2017\/10\/19\/windows-share-access-error-the-computer-you-are-signing-into-is-protected-by-an-authentication-firewall\/003-trust-selective-authentication1\/\" rel=\"attachment wp-att-429\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"429\" data-permalink=\"https:\/\/www.web-workers.ch\/index.php\/2017\/10\/19\/windows-share-access-error-the-computer-you-are-signing-into-is-protected-by-an-authentication-firewall\/003-trust-selective-authentication1\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.web-workers.ch\/wp-content\/uploads\/2017\/10\/003-Trust-Selective-Authentication1.png?fit=514%2C405&amp;ssl=1\" data-orig-size=\"514,405\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"003-Trust-Selective-Authentication[1]\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.web-workers.ch\/wp-content\/uploads\/2017\/10\/003-Trust-Selective-Authentication1.png?fit=514%2C405&amp;ssl=1\" class=\"alignnone wp-image-429\" src=\"https:\/\/i0.wp.com\/www.web-workers.ch\/wp-content\/uploads\/2017\/10\/003-Trust-Selective-Authentication1.png?resize=390%2C307&#038;ssl=1\" alt=\"\" width=\"390\" height=\"307\" srcset=\"https:\/\/i0.wp.com\/www.web-workers.ch\/wp-content\/uploads\/2017\/10\/003-Trust-Selective-Authentication1.png?w=514&amp;ssl=1 514w, https:\/\/i0.wp.com\/www.web-workers.ch\/wp-content\/uploads\/2017\/10\/003-Trust-Selective-Authentication1.png?resize=300%2C236&amp;ssl=1 300w\" sizes=\"auto, (max-width: 390px) 100vw, 390px\" \/><\/a><\/p>\n<p>The solution is to allow the user (or the group the user is a member of) to authenticate against the computer object in the target domain. This right has to be assigned selectively for ever computer object, as the name is saying it is required for &#8216;selective authentication&#8217;.<\/p>\n<p>1. Open Active Directory Users and Computers management console<br \/>\n2. Enable advanced features at the menu &#8216;View&#8217;<br \/>\n3. Locate the computer object hosting the resource<br \/>\n4. Open the properties of the object<br \/>\n5. Open the &#8216;Security&#8217; tab<br \/>\n6. Add the user\/group that requires access<br \/>\n7. Enable &#8216;Allowed to authenticate&#8217;<\/p>\n<p><a href=\"https:\/\/www.web-workers.ch\/index.php\/2017\/10\/19\/windows-share-access-error-the-computer-you-are-signing-into-is-protected-by-an-authentication-firewall\/002-alowed-to-authenticate-permission1\/\" rel=\"attachment wp-att-430\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"430\" data-permalink=\"https:\/\/www.web-workers.ch\/index.php\/2017\/10\/19\/windows-share-access-error-the-computer-you-are-signing-into-is-protected-by-an-authentication-firewall\/002-alowed-to-authenticate-permission1\/\" data-orig-file=\"https:\/\/i0.wp.com\/www.web-workers.ch\/wp-content\/uploads\/2017\/10\/002-Alowed-To-Authenticate-Permission1.png?fit=902%2C659&amp;ssl=1\" data-orig-size=\"902,659\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"002-Alowed-To-Authenticate-Permission[1]\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/i0.wp.com\/www.web-workers.ch\/wp-content\/uploads\/2017\/10\/002-Alowed-To-Authenticate-Permission1.png?fit=902%2C659&amp;ssl=1\" class=\"alignnone wp-image-430\" src=\"https:\/\/i0.wp.com\/www.web-workers.ch\/wp-content\/uploads\/2017\/10\/002-Alowed-To-Authenticate-Permission1.png?resize=578%2C422&#038;ssl=1\" alt=\"\" width=\"578\" height=\"422\" srcset=\"https:\/\/i0.wp.com\/www.web-workers.ch\/wp-content\/uploads\/2017\/10\/002-Alowed-To-Authenticate-Permission1.png?w=902&amp;ssl=1 902w, https:\/\/i0.wp.com\/www.web-workers.ch\/wp-content\/uploads\/2017\/10\/002-Alowed-To-Authenticate-Permission1.png?resize=300%2C219&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.web-workers.ch\/wp-content\/uploads\/2017\/10\/002-Alowed-To-Authenticate-Permission1.png?resize=768%2C561&amp;ssl=1 768w\" sizes=\"auto, (max-width: 578px) 100vw, 578px\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Problem Today a customer contacted me, he told me the tries to map a network drive by using a \u2018net use\u2019 command. Unforantelty the command thows an error message as [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":428,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[3,6],"tags":[54,97,63,60,69,43,49,75,52,41,44,48,28],"class_list":["post-427","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mswin","category-security","tag-access","tag-active-directory","tag-ad","tag-domain","tag-firewall","tag-http","tag-https","tag-ie","tag-log","tag-php","tag-root","tag-script","tag-windows"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.web-workers.ch\/wp-content\/uploads\/2017\/10\/001-Protected-By-Authentication-Firewall1.png?fit=677%2C343&ssl=1","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p8sxjX-6T","jetpack-related-posts":[],"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/www.web-workers.ch\/index.php\/wp-json\/wp\/v2\/posts\/427","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.web-workers.ch\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.web-workers.ch\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.web-workers.ch\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.web-workers.ch\/index.php\/wp-json\/wp\/v2\/comments?post=427"}],"version-history":[{"count":5,"href":"https:\/\/www.web-workers.ch\/index.php\/wp-json\/wp\/v2\/posts\/427\/revisions"}],"predecessor-version":[{"id":679,"href":"https:\/\/www.web-workers.ch\/index.php\/wp-json\/wp\/v2\/posts\/427\/revisions\/679"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.web-workers.ch\/index.php\/wp-json\/wp\/v2\/media\/428"}],"wp:attachment":[{"href":"https:\/\/www.web-workers.ch\/index.php\/wp-json\/wp\/v2\/media?parent=427"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.web-workers.ch\/index.php\/wp-json\/wp\/v2\/categories?post=427"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.web-workers.ch\/index.php\/wp-json\/wp\/v2\/tags?post=427"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}