If you want to "automatically" extract Windows user credentials, one option (perhaps the only one?) Is NTLM . After you really get the credentials, you need to check them at an authoritative source. Active Directory provides details as LDAP, so most security systems can handle this.
I did such a thing a few years ago with Spring Security , including obtaining privileges based on membership in a Windows group, and it worked very well.
source
share