What is the difference between logging into an AD Domain versus connecting to network resource?



Can someone explain the difference between logging on to a computer that is part of an Active Directory domain using an Active Directory user account, versus logging on to a local computer and then connecting to a network resource (where the user is then prompted for network credentials). i.e. a user logs into his/her home computer and then VPNs into the work network).

Or a slightly different scenario, where a user logs into his/her laptop (that is part of the domain) offline, but then VPNs into the network afer they have logged in using locally cached credentials. I know for instance that group polices (user) aren't processed in either scenario, but realized I didn't entirely understand why. Or why when I logon to the domain from a domain member computer I can access resources from various servers with no prompting for credentials, where as from a non-domain computer I am prompted each time I try to access a different resource.

Thanks

.



Relevant Pages

  • restricting logons
    ... Does anybody know how in Active Directory or Group Policy if you can set a ... group of people to only allow logging on to one computer on a network at a ...
    (microsoft.public.windows.server.security)
  • Re: cached login credentials
    ... , it takes longer to investigate an attack and clean up after it than it does simply to nuke-and-pave, flatten-and-rebuild, whatever. ... then over time through precision monitoring of network ... Anything that does an interactive logon will store cached credentials, ... > domain admin account credentials), is a credential cached anywhere for> the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: cached login credentials
    ... administrator accounts is a good mitigation. ... then over time through precision monitoring of network ... you have a way to limit exposure to this sort of expanded attack originating ... Anything that does an interactive logon will store cached credentials, ...
    (microsoft.public.windowsxp.security_admin)
  • A newbies adventures with AD - HAAAAAALP!!!
    ... I've gotten my network, DHCP, DNS, File Server, ... I have published shares on the server in active directory, ... My Network Places> Entire Network> Directory ... to shared folder is: ...
    (microsoft.public.windows.server.networking)
  • Re: Domain troubles
    ... Workgroup administrative environment and the machine account in Active ... Another possiblity is that the Active Directory DNS cannot resolve the ... For example if you built a network segment and abitrarily choose ...
    (microsoft.public.windows.server.general)