Re: Ability to logon after account has been disabled

From: Steven L Umbach (n9rouz_at_nscomcast.net)
Date: 11/16/03


Date: Sun, 16 Nov 2003 19:00:12 GMT

I tend to doubt it was a fictitious password. What happens is by default W2K allows
"cached credentials" so that a user can log into their local machine when a domain
controller is unable to authenticate their account. The purpose is to allow users to
still use their local machine, but obviously people have found out how to abuse it.
There is a security option that can be configured at various levels such as local,
domain, or Organizational Unit to disable it. For instance in Local Security Policy
it would be in security settings/local policies/security options - number of previous
logons to cache. Set it to zero to not allow domain cached logons. That will not
stop a user from logging on to a local machine account if they have one - possibly
one you do not know about. --- Steve

"Bob" <anonymous@discussions.microsoft.com> wrote in message
news:073101c3ac67$d11a8150$a501280a@phx.gbl...
> I have an account locked out and the user was able to
> enter User name, unplug the network hub, enter a
> ficticious password, and then plug the power back into
> the hub and the PC logged on and reconnected to Domain
> resources like Internet Explorer, etc. How can I fix
> this??



Relevant Pages

  • RE: focus-ms@securityfocus.com
    ... If I may....Quoting MS Security Resource Kit... ... Cached Credentials ... "By default, Windows NT, Windows 2000, and Windows XP cache the ... >Security Policy Automation for Web Applications. ...
    (Focus-Microsoft)
  • Re: RDC Access for just one VPN Client
    ... >> I suppose one thing that he could do is disable cached credentials on the ... >> laptops which would make his scenario less likely. ... > If you mean the cached account for logging into the laptop itself,..I did ...
    (microsoft.public.isa)
  • Re: Add domain user to client computer.
    ... They should be able to use cached credentials when out of the office/away ... from the network. ... then it will not allow a domain logon. ... you do not have a domain user account, ...
    (microsoft.public.windows.server.sbs)
  • Re: Can I hide my personal information from administrators of a domain?
    ... In the local security policy ... set the number of cached credentials to store policy to zero. ... > "Roger Abell" wrote in message ... >> Microsoft MVP ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Outlook Messages are not leaving exchange for one user
    ... I removed the cached credentials on the machine. ... In Outlook is shows the message in the sent box, but no one ever gets it. ... Using a OWA on the same machine with his account works fine, ... Event Source: AutoEnrollment ...
    (microsoft.public.windows.server.sbs)