RE: Login into Domain without network connectivity



Hi,

By Default, Windows 2000, Windows XP and Windows 2003 all keep a cache of
the last 10 users to logon to the machines. This cache is used to validate
their password in the event you are not able to contact a domain
controller. When creating a new user on the domain, this user has not
logged onto the workstation and therefore the username/password is not
cached.

The size of this cache can be adjusted with the policy:
Computer Configuration\Windows Settings\Local Policies\Security
Options\Interactive logon: Number of previous logons to cache (in case
domain controller is not available)

Be cautious in setting this cache to 0 as in the event all DCs are down, no
users will be able to logon.

Hope this helps,

Brian Delaney
Microsoft Canada
--

This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
Thread-Topic: Login into Domain without network connectivity
thread-index: AcbtCJmSDNhJAeX7QbCHZwvlfNcpuw==
X-WBNR-Posting-Host: 61.6.35.178
From: =?Utf-8?B?SG9uZyBKaW4=?= <HongJin@xxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: Login into Domain without network connectivity
Date: Wed, 11 Oct 2006 00:41:01 -0700

I realised that by using existing domain user accounts, even though i am
disconnected from the network, i could still logon to the domain.
However, when i create a new user account and try to logon to the domain
while i am offline, login was unsuccessful. Message box pop up written
domain
XXX could not be found.

Can i put control where each users must have a valid connection to the
domain before they are allowed to log on? Thank you.



.



Relevant Pages

  • Windows 2003 member server with Windows 2000 Domain Controller
    ... If anyone is having a Windows 2003 member server with a Windows 2000 Domain ... Windows cannot obtain the domain controller name for your computer network. ... There are currently no logon servers available to service the logon request. ...
    (microsoft.public.win2000.security)
  • Re: Does the ability to use cached logon expire?
    ... >> credentials, they need to log on to the Domain to reset it. ... > Microsoft Windows 2000 Security Hardening Guide ... > Disable Caching of Logon Information ... > how many user account entries Windows 2000 saves in the logon cache ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Local Caching
    ... Interactive logon: Number of previous logons to cache? ... Is it store in LSASS secrets? ... If we set our server to not store local cache of user's password what ...
    (microsoft.public.windows.server.active_directory)
  • Re: XP Domain users and Local users laptop login question??
    ... Check your GPO for "Interactive Logon: Number of logons to cache in case DC is not available" ... logon to the laptop some number of times not connected to the domain. ... to access all their files without this confusion. ...
    (microsoft.public.windows.server.general)
  • Re: Local Caching
    ... Number of previous logons to cache (in case domain ... > If we set our server to not store local cache of user's password what ... > logon to that server in that domain...But what other hidden gotchas are ...
    (microsoft.public.security)