<div class="content" name="NETLOGON_SAM_LOGON_RESPONSE" uuid="9b333971-6dd7-4003-a898-6e51b2c02110"><p>The NETLOGON_SAM_LOGON_RESPONSE structure is the first
extended version of the server&#39;s response to an <span><a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_a01cea16-0836-469c-81d4-9eeb52be1ad6" data-linktype="relative-path">LDAP ping</a></span> (section <span><a href="895a7744-aff3-4f64-bcfa-f8c05915d2e9" data-linktype="relative-path">6.3.3</a></span>)
or a <span><a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_0a5fd868-ff77-4beb-838e-79f98cbe3898" data-linktype="relative-path">mailslot
ping</a></span> (section <span><a href="2cff75a9-5871-4493-a704-017b506f8df0" data-linktype="relative-path">6.3.5</a></span>).</p><table>
 <tbody><tr>
  <th><p><br/>0</p></th>
  <th><p><br/>1</p></th>
  <th><p><br/>2</p></th>
  <th><p><br/>3</p></th>
  <th><p><br/>4</p></th>
  <th><p><br/>5</p></th>
  <th><p><br/>6</p></th>
  <th><p><br/>7</p></th>
  <th><p><br/>8</p></th>
  <th><p><br/>9</p></th>
  <th><p>1<br/>0</p></th>
  <th><p><br/>1</p></th>
  <th><p><br/>2</p></th>
  <th><p><br/>3</p></th>
  <th><p><br/>4</p></th>
  <th><p><br/>5</p></th>
  <th><p><br/>6</p></th>
  <th><p><br/>7</p></th>
  <th><p><br/>8</p></th>
  <th><p><br/>9</p></th>
  <th><p>2<br/>0</p></th>
  <th><p><br/>1</p></th>
  <th><p><br/>2</p></th>
  <th><p><br/>3</p></th>
  <th><p><br/>4</p></th>
  <th><p><br/>5</p></th>
  <th><p><br/>6</p></th>
  <th><p><br/>7</p></th>
  <th><p><br/>8</p></th>
  <th><p><br/>9</p></th>
  <th><p>3<br/>0</p></th>
  <th><p><br/>1</p></th>
 </tr>
 <tr>
  <td colspan="16">Opcode</td>
  <td colspan="16">UnicodeLogonServer (variable)</td>
 </tr>
 <tr>
  <td colspan="32">...</td>
 </tr>
 <tr>
  <td colspan="32">UnicodeUserName (variable)</td>
 </tr>
 <tr>
  <td colspan="32">...</td>
 </tr>
 <tr>
  <td colspan="32">UnicodeDomainName (variable)</td>
 </tr>
 <tr>
  <td colspan="32">...</td>
 </tr>
 <tr>
  <td colspan="32">DomainGuid (16 bytes)</td>
 </tr>
 <tr>
  <td colspan="32">...</td>
 </tr>
 <tr>
  <td colspan="32">...</td>
 </tr>
 <tr>
  <td colspan="32">NullGuid (16 bytes)</td>
 </tr>
 <tr>
  <td colspan="32">...</td>
 </tr>
 <tr>
  <td colspan="32">...</td>
 </tr>
 <tr>
  <td colspan="32">DnsForestName (variable)</td>
 </tr>
 <tr>
  <td colspan="32">...</td>
 </tr>
 <tr>
  <td colspan="32">DnsDomainName (variable)</td>
 </tr>
 <tr>
  <td colspan="32">...</td>
 </tr>
 <tr>
  <td colspan="32">DnsHostName (variable)</td>
 </tr>
 <tr>
  <td colspan="32">...</td>
 </tr>
 <tr>
  <td colspan="32">DcIpAddress</td>
 </tr>
 <tr>
  <td colspan="32">Flags</td>
 </tr>
 <tr>
  <td colspan="32">NtVersion</td>
 </tr>
 <tr>
  <td colspan="16">LmNtToken</td>
  <td colspan="16">Lm20Token</td>
 </tr>
</tbody></table><p><b>Opcode (2 bytes): </b>Operation code (see section <span><a href="07133ff2-a9a3-4aa9-8896-a7dcb53bdfe9" data-linktype="relative-path">6.3.1.3</a></span>).</p><p><b>UnicodeLogonServer (variable): </b>Null-terminated
<span><a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_c305d0ab-8b94-461a-bd76-13b40cb8c4d8" data-linktype="relative-path">Unicode</a></span>
value of the <span><a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_b86c44e6-57df-4c48-8163-5e3fa7bdcff4" data-linktype="relative-path">NetBIOS</a></span> name of the
server. This field always contains at least one character: the null terminator.
Each Unicode value is encoded as 2 bytes.</p><p><b>UnicodeUserName (variable): </b>Null-terminated
Unicode value of the name of the user copied directly from the client&#39;s request.
This field always contains at least one character: the null terminator. Each
Unicode value is encoded as 2 bytes.</p><p><b>UnicodeDomainName (variable): </b>Null-terminated
Unicode value of the NetBIOS name of the <span><a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_784c7cce-f782-48d8-9444-c9030ba86942" data-linktype="relative-path">NC</a></span>. This field
always contains at least one character: the null terminator. Each Unicode value
is encoded as 2 bytes.</p><p><b>DomainGuid (16 bytes): </b>The value of the NC&#39;s <b>GUID</b>
<span><a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_108a1419-49a9-4d19-b6ca-7206aa726b3f" data-linktype="relative-path">attribute</a></span>
specified as a <span><a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_f49694cc-c350-462d-ab8e-816f0103c6c1" data-linktype="relative-path">GUID</a></span> structure,
which is defined in <span><a href="../ms-dtyp/cca27429-5689-4a16-b2b4-9325d93e4ba2" data-linktype="relative-path">[MS-DTYP]</a></span>
section <span><a href="../ms-dtyp/4926e530-816e-41c2-b251-ec5c7aca018a" data-linktype="relative-path">2.3.4</a></span>.</p><p><b>NullGuid (16 bytes): </b>A <span><a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_ba500a5b-8c29-467c-a335-0980c8b11304" data-linktype="relative-path">NULL GUID</a></span>.
The GUID structure is defined in [MS-DTYP] section 2.3.4. Always set zero
values for all fields in the GUID structure.</p><p><b>DnsForestName (variable): </b><span><a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_409411c4-b4ed-4ab6-b0ee-6d7815f85a35" data-linktype="relative-path">UTF-8</a></span>
encoded value of the <span><a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_604dcfcd-72f5-46e5-85c1-f3ce69956700" data-linktype="relative-path">DNS</a></span> <span><a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_fd104241-4fb3-457c-b2c4-e0c18bb20b62" data-linktype="relative-path">forest</a></span>
name, compressed as specified in <span><a href="https://go.microsoft.com/fwlink/?LinkId=90264" data-linktype="external">[RFC1035]</a></span>
section 4.1.4. To get the decompressed string, see section <span><a href="b0ef9479-78d8-40c1-b6d2-0baad834ed39" data-linktype="relative-path">6.3.7</a></span>.</p><p><b>DnsDomainName (variable): </b>UTF-8 encoded value
of the DNS NC name, compressed as specified in [RFC1035] section 4.1.4. To get
the decompressed string, see section 6.3.7.</p><p><b>DnsHostName (variable): </b>UTF-8 encoded value of
the DNS server name, compressed as specified in [RFC1035] section 4.1.4. To get
the decompressed string, see section 6.3.7.</p><p><b>DcIpAddress (4 bytes): </b>The <span><a href="b645c125-a7da-4097-84a1-2fa7cea07714#gt_76a05049-3531-4abd-aec8-30e19954b4bd" data-linktype="relative-path">domain
controller</a></span> IP address, as specified in <span><a href="https://go.microsoft.com/fwlink/?LinkId=392659" data-linktype="external">[RFC791]</a></span>.</p><p><b>Flags (4 bytes): </b>DS_FLAG Options (see section <span><a href="f55d3f53-351d-4407-940e-f53eb6154af0" data-linktype="relative-path">6.3.1.2</a></span>).</p><p><b>NtVersion (4 bytes): </b>Set to
NETLOGON_NT_VERSION_1 | NETLOGON_NT_VERSION_5.</p><p><b>LmNtToken (2 bytes): </b>This MUST be set to
0xFFFF.</p><p><b>Lm20Token (2 bytes): </b>This MUST be set to
0xFFFF.</p><p><b>Note</b>  All multibyte quantities are
represented in little-endian byte order.</p></div>