philip andrew wrote: Now - as I know the user is currently logged into the domain, why can't that users credientials be sent to the server in order to identify who that user is without the user ever having to enter their user name and password. Because that machine does not belongs to the domain. That would be a huge security breach. If MS allowed what you're saying, as you navigate to any Web Site you could have your username/password stolen. My latest articles: Desktop Bob - Instant CP notifications XOR tricks for RAID data protection