Re: Require Domain Controller authentication to unlock

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance




If the two options operated as the documentation indicates, that could lead
to an interesting situation. The user could log in to an off-network PC
with cached credentials, but then be unable to unlock it later on.

"R. vd Horn" <RvdHorn@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:5528FFAF-386A-4165-8D17-46AD2164F7DE@xxxxxxxxxxxxxxxx
Hello Meinolf,

If the number of cached credentials has to be set to 0 a DC is always
needed
to authenticate. The required DC setting would be useless (like it seems
now). The reqiured DC setting should force DC athentication even if there
are
cached credentials.

Interactive logon: Require Domain Controller authentication to unlock:
Logon information must be provided to unlock a locked computer. For domain
accounts, this security setting determines whether a domain controller
must
be contacted to unlock a computer. If this setting is disabled, a user can
unlock the computer using cached credentials. If this setting is enabled,
a
domain controller must authenticate the domain account that is being used
to
unlock the computer.

It has worked like the MS description but it doesn't anymore.

Setting the number of cached credentials to 0 works for me so i'll keep it
that way.

Thanks for your replies.

"Meinolf Weber [MVP-DS]" wrote:

Hello R. vd Horn,

If i understand both settings, there is a kind of realtionship, as long
as
you don't set it to 0 for cached credentials it will not contact the DC.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


Hello Meinolf,

The GPO is fully applied and the users are all restricted users.

Whether the setting is enabled or disabled it has no effect on the
behaviour.

The only thing I can do to prevent users from unlocking the
workstation without a DC is to set the number of cached logons to 0.

This works for now but it worries me that the DC required setting
seems to be ignored.

"Meinolf Weber [MVP-DS]" wrote:

Hello R. vd Horn,

If you run rsop.msc or gpresult /v logged on as domain user, can you
see the GPO is applied with all settings? Are your users local admin?

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
We have enabled the policy 'Interactive logon: Require Domain
Controller Authentication to unlock' but users can still unlock
their Windows XP workstations when a domaincontroller is NOT
present.

Enabling or disabling the policy has the no effect.

It used to work like it is supposed to and policies have not been
changed since it worked well.

Windows Server 2003 R2 and Windows XP Pro SP2 and SP3 workstations
with all the latest updates applied.

What's wrong here?






.



Relevant Pages

  • Re: Require Domain Controller authentication to unlock
    ... If the number of cached credentials has to be set to 0 a DC is always needed ... Interactive logon: Require Domain Controller authentication to unlock: ... Logon information must be provided to unlock a locked computer. ... domain controller must authenticate the domain account that is being used to ...
    (microsoft.public.windows.group_policy)
  • Re: Cached credentials
    ... being off the network connected to a domain controller. ... of times a domain user can logon with cached credentials. ... they will not be able to access domain network resources with the cached ...
    (microsoft.public.security)
  • Re: Cached Credentials causing problems with shares?
    ... Also note, cached credentials only log you in locally, they don't extend ... The failure code from authentication protocol Kerberos ... "There are currently no logon servers available to service the logon ... domain controller cannot be found to verify that user name." ...
    (microsoft.public.windows.server.active_directory)
  • Re: profile logon problem
    ... I'd imagine that if the user has also been using a local account, ... > the time of the last logon. ... > cached credentials are used instead of the updated credentials from the ... > communicate with a domain controller will not be allowed to enter into the ...
    (microsoft.public.win2000.security)
  • Re: Xp pro - Offline domain users/accounts
    ... those errors only indicate that the domain controller isn't ... cached credentials to log you on. ... >registry database was not freed. ...
    (microsoft.public.windowsxp.network_web)