Local Session Authentication Cache



Hi,
Here's my puzzle:
I have a secure, hidden server separated from our AD domain in a
workgroup. Select domain users need to access hidden shares on this
server via statically mapped drives and local (non-domain) accounts.
When they connect, they are forced to authenticate. But, once
authenticated, the session is cached until the users either logs off or
shuts down. The problem is a security concern because the mapped
connection is left wide open without any timeouts. If the PC is left
unlocked by the user, a malicious or curious user could hit the mapped
drive without a challenge. I would like to prevent this.

I'm looking to enable an idle session timeout, disconnecting the user
after a period of inactivity.

I've already tried editing the local user account\sessions settings but
although it did disconnect the drive, the credentials were still cached
(no challenge.)

Thanks in advance!
Chuck M.

.



Relevant Pages

  • Re: A method to gain access to files via built in account
    ... By default, no drives or folders are shared, so there is no network access ... This account is automatically added to 'domain users' when the ... server joins the domain. ... discovered that the could map shares by adding the UNC path to a word ...
    (microsoft.public.windows.server.general)
  • Re: Incorrect mapped drives size
    ... Apply, then re-enable Quota Managment? ... > Our quotas were set at 2GB, but the mapped drives are still saying 1GB. ... >> GB for domain users and 'unlimited' for admins. ... >> Merv Porter [SBS MVP] ...
    (microsoft.public.windows.server.sbs)
  • Re: Login Script refuses to map a share?
    ... you can remove mapped drives with net use also. ... I was creating a login script to map network shares. ... > /persistent:yes it lets me disconnect? ... >>>I have a faithful Windows 2000 login script batch file for domain users. ...
    (microsoft.public.scripting.vbscript)
  • Re: Sharing a network drive when not logged in
    ... | drives from "SERVER A" so that they can be shared to domain users. ... | We do not want "SERVER B" to be logged in, as any user, all the time. ... | see the shared drives on "SERVER B". ...
    (microsoft.public.windows.file_system)