Re: Bypass Domain GPO when not connected to network?

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 10/25/05

  • Next message: Ross Luker: "Re: Bypass Domain GPO when not connected to network?"
    Date: Tue, 25 Oct 2005 09:25:08 -0500
    
    

    There is no hack that I have ever heard of or figured out and unfortunately
    that is a bad situation. There is an option to logon via dial up connection
    that a user will see when they first try to logon after they do
    ctrl-alt-delete [they may have to select options box if they do not see it]
    to their computer where they will have to select that checkbox and then
    choose the VPN connectoid. Have them try that to see what happens as that
    works a bit differently that the VPN connection after logging onto the
    computer. If that does not work then about the best you can do is have them
    try to logon with the built in administrator account and have them VPN in
    and you may have to instruct them how to configure the VPN connectoid. If
    they can not VPN logged on as a local administrator have them create a local
    user account that matches their domain logon and password and try that. Tell
    them how to use secedit/gpupdate to refresh computer configuration policy
    and if it refreshes successfully they should then be able to logon with
    their domain account but of course they would still know the local
    administrator password. If they can not logon as the local administrator the
    computers will need to be connected to the domain somehow or rebuilt and
    they would need to logon with local computer user account until such time it
    had been joined to the domain again. I have never tried it over a VPN
    connection but it may be possible to join the computer to the domain using
    the netdom command. You may also want to post in the Active_directory
    newsgroup.--- Steve

    "Ross Luker" <ross_luker@hotmail.com> wrote in message
    news:1130229368.527529.156250@f14g2000cwb.googlegroups.com...
    > Hi,
    >
    > We have a problem where the "Log on locally" entry in the Default
    > Domain GPO was messed with (an entry was put in without specifying
    > other users). This was quickly fixed, as soon as we noticed users
    > being denied the right to log on. However, I've got several users that
    > were connected to our VPN when the GPO changed, and now when they
    > reboot they're denied access to the machine. Obviously, just
    > connecting the PC to the network will refresh to the working GPO, but
    > several users are in a different country - is there a way I can get
    > them logged in to the machine so that they can access the VPN and
    > refresh group policy?
    >
    > TIA
    > Ross
    >


  • Next message: Ross Luker: "Re: Bypass Domain GPO when not connected to network?"

    Relevant Pages

    • RE: SBS Standard VPN Setup using L2TP
      ... I understand that the login script is not applied when users logon through ... Windows" dialog box and choose an appropriate connection to gain access to ... and then logon by using dial-up connection option after you create the VPN ... Did you configure a login script group policy in AD or configure a logon ...
      (microsoft.public.windows.server.sbs)
    • Re: offline files and vpn
      ... Perhaps try establishing the VPN connection PRIOR to logging into your ... Options>> Windows Logon Properties ... The folder is set up for offline use. ...
      (microsoft.public.windowsxp.work_remotely)
    • Where are VPN Connections in Windows Logon Dialog Box?
      ... up connection" in the Windows XP Logon Screen, ... The workstation then dials in to the RAS server, ... No we are implementing a Windows 2003 RAS Server with VPN over IPSec for our ...
      (microsoft.public.windowsxp.work_remotely)
    • Logon to domain through VPN
      ... I have a windows xp PC try to logon to the domain controller remotely ... through VPN connection, failed. ... password, after two prompt, it just dropped connection. ...
      (microsoft.public.windowsxp.work_remotely)
    • Re: Applying User GPO for Remote Users
      ... You'll have to get them to log on to the domain - that is start up the VPN ... In the logon screen there's a "dial ... I've linked the GPO to an OU with the users I ... refresh intervals with no luck. ...
      (microsoft.public.win2000.group_policy)