Re: Logon using cached credentials



On 2007-03-01 20:14:12 +0000, Harry Johnston <harry@xxxxxxxxxxxxxxxxxx> said:

Dharan Prakash wrote:

What happens if the user is removed from the central Active Directory store? Will the user still be able to login in the workstation using locally cached credentials ?

Yes, though (presumably) not when the workstation is on the network.

Harry.

I'm interested in the "presumably" qualifier here.

Could someone clarify whether the following is true:

User logs on to a system using a domain account, and logs off.
Sysadmin removes account from domain (or disables the account, or changes the password).
User attempts to log on to domain account using original password).
Since the system has cached the user's credentials, it allows the logon. However, simultaneously to this, the logon attempt is sent to the domain controller.
The logon failure is received from the domain controller.
The user has the same local authorisation as he had before, but no domain authorisation.

If the sysadmin hadn't done anything, the domain logon would succeed, would replace the existing credentials, and the user would be fully logged on to the system and domain.

Cheers,
kevin

.



Relevant Pages

  • Re: Cant use WM6 to access network shares
    ... unfortunately nothing in any of the event logs. ... the logon prompt. ... So for whatever reason it's just not passing my credentials ... Can get to about any other share on the network. ...
    (microsoft.public.pocketpc.wireless)
  • Re: Hacking attempts?
    ... Windows logs logon type 3 in most cases when you access a computer from elsewhere on the network. ... One of the most common sources of logon events with logon type 3 is connections to shared folders or printers. ... You can use the IIS logs to track down the ip addressthat are attempting unauthorized login. ...
    (microsoft.public.windows.server.sbs)
  • Re: Please Help
    ... In an Active Directory setup I use logon and logoff scripts that log the ... Use the Event logs. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Remote User Needs to Change PWD without connecting to domain
    ... credentials to log on and eventually the password expired. ... > I think you are misinterpreting the "10 logon" settings. ... > Settings, Security Settings, Local Policy, Security Options). ... >> account (note: this should only be temporary as this presents a security ...
    (microsoft.public.win2000.security)
  • Re: Change local password for domain account while disconnected
    ... control -alt -delete and then try to unlock it with new credentials. ... The Microsoft VPN client ... also has an option to logon to the domain in it's properties which may be ... > She then VPN's into the corporate network but the corporate VPN ...
    (microsoft.public.security)