Overview[1]#

How passwords are used in Windows (and password-hash) is not all about Microsoft Active Directory.

When a user logs on, the password the user types is converted into password-hash and held in Random Access Memory (RAM) by the Local Security Authority Subsystem Service (LSASS) process. If the user using a local account for authentication, the Hash Functions is compared against the locally stored NTLMv2 Hash, and if the two match, the user is logged on.

If the user is authenticating against an Microsoft Active Directory AD DOMAIN by using a hostname to access a resource, the NTLMv2 Hash is used in a Kerberos logon against the Key Distribution Center (KDC), which is typically the Domain Controller. The password verifier is computed by WINLOGON, not LSASS.

Kerberos cannot be used in the following situations:

In these situations, the authentication process uses different protocols that are determined by the LAN Manager authentication level Group Policy setting.

More Information#

There might be more information for this subject on one of the following:

Add new attachment

Only authorized users are allowed to upload new attachments.
« This page (revision-4) was last changed on 21-Jun-2017 11:36 by jim