Re: Cached credentials



As far as I can tell cached credentials are good for a very long time and
don't know if there is an actual time limit. I have come across a user that
had a old laptop from work that was using them over a year after being off
the network connected to a domain controller.

The value you see in security policy controls the number of domain users
that can have cached credentials on a domain computer and not the number of
times a domain user can logon with cached credentials. Of course if a domain
user connects to their network where a domain controller lives [or through a
VPN] and their password has been changed in Active Directory they will not
be able to access domain network resources with the cached credentials that
use the old password.

Steve


"luissol" <luissol@xxxxxxxxx> wrote in message
news:1193101565.965955.179060@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi I want to know how much time a credential of a user belonging a
domain lasts in a computer without access to the domain controller?

I know there is a configuration for saving the cache credentials for
10 users, but I want to know if there is other way besides putting the
value of "number of previous logons to chache" to zero that allow me
to control the time that a cached credential is valid

thanks a lot
Luis



.



Relevant Pages

  • Re: Cached credentials
    ... I have come across a user that had a old laptop from work that was using them over a year after being off the network connected to a domain controller. ... The value you see in security policy controls the number of domain users that can have cached credentials on a domain computer and not the number of times a domain user can logon with cached credentials. ... Of course if a domain user connects to their network where a domain controller lives and their password has been changed in Active Directory they will not be able to access domain network resources with the cached credentials that use the old password. ...
    (microsoft.public.security)
  • Re: Cached credentials
    ... being off the network connected to a domain controller. ... of times a domain user can logon with cached credentials. ... they will not be able to access domain network resources with the cached ...
    (microsoft.public.security)
  • Re: Cached Credentials causing problems with shares?
    ... Also note, cached credentials only log you in locally, they don't extend ... The failure code from authentication protocol Kerberos ... "There are currently no logon servers available to service the logon ... domain controller cannot be found to verify that user name." ...
    (microsoft.public.windows.server.active_directory)
  • Re: profile logon problem
    ... I'd imagine that if the user has also been using a local account, ... > the time of the last logon. ... > cached credentials are used instead of the updated credentials from the ... > communicate with a domain controller will not be allowed to enter into the ...
    (microsoft.public.win2000.security)
  • Re: Require Domain Controller authentication to unlock
    ... If the number of cached credentials has to be set to 0 a DC is always ... Interactive logon: Require Domain Controller authentication to unlock: ...
    (microsoft.public.windows.group_policy)