Hot Downloads

×

Notice

The forum is in read only mode.
Welcome, Guest
Username: Password: Remember me
  • Page:
  • 1
  • 2

TOPIC: Domain cached password

Domain cached password 10 years 4 months ago #25497

I know that if I join a computer to a domain and take that computer off the network (by unplugging it) I can still use the domain username and password to login.

Is there a timeout period for this? I would think that the cached credentials would eventually expire and need to communicate with the domain controller eventually. Maybe not.

Thanks.

Re: Domain cached password 10 years 4 months ago #25500

I know that if I join a computer to a domain and take that computer off the network (by unplugging it) I can still use the domain username and password to login.

Is there a timeout period for this? I would think that the cached credentials would eventually expire and need to communicate with the domain controller eventually. Maybe not.

Thanks.


Check Cached Credentials Security In Windows Server 2003, in Windows XP, and in Windows 2000
Cached Domain Logon Information

Re: Domain cached password 10 years 4 months ago #25501

  • Smurf
  • Smurf's Avatar
  • Offline
  • Moderator
  • Moderator
  • Posts: 1390
  • Karma: 1
  • Thank you received: 0
It can be controlled in Group Policies. i.e. disabled.

Re: Domain cached password 10 years 4 months ago #25504

Computer configuration > Windows Settings > Security Settings > Local Policies > Security Options, and "Interactive logon: Number of previous logons to cache..."

I disable it in my home lab because it can mislead you in troubleshooting network issues.

Also note that if you leave the computer disconnected from the network for more than thirty days, that at one point you'll need to reconnect it and possibly reset the computer account so it could "resync" with the DC (or just drop and add it back onto the domain). Basically, computers maintain a secure password protected connection between themselves and the DC, when the communicate is broken (leaving a computer disconnected for too long), the communication path is broken.

That's just to continue your train of thought on the cache expiring idea.

Re: Domain cached password 10 years 4 months ago #25520

  • S0lo
  • S0lo's Avatar
  • Offline
  • Moderator
  • Moderator
  • Posts: 1577
  • Karma: 3
  • Thank you received: 7
It's very misleading and some times causes havoc when users are expected to login to multiple machines frequently. In my work place (University) students are expected to login to any PC in the lab.

Picture this, a student logs in to one PC and does some changes to one of his word documents. Logsoff saving his profile and document to the DC safely. The next day the student sits on another empty chair and logs-in, but the PC (for some reason) was disconnected say because of a pulled out UTP cable or switch port that was mis functioning. Eventually, he logs-in with an old cached profile (Not realizing it off course) and finds out that all the changes that he made yesterday was gone. He gets frustrated!!. He retypes his changes and adds more and more. Logsoff. Comes the next day to the first PC (which was connected), logs-in, and find out that he got back his old changes but not the changes that he made yesterday. :x :x :cry:

A very bad default behavior in my opinion.

Re: Domain cached password 10 years 4 months ago #25521

Thanks for the information.

I see that the default is 10 previously used logins. Does this mean that a user could login cached forever? Or would even these 10 cached credentials expire?
  • Page:
  • 1
  • 2
Time to create page: 0.164 seconds

CCENT/CCNA

Cisco Routers

  • SSL WebVPN
  • Securing Routers
  • Policy Based Routing
  • Router on-a-Stick

VPN Security

  • Understand DMVPN
  • GRE/IPSec Configuration
  • Site-to-Site IPSec VPN
  • IPSec Modes

Cisco Help

  • VPN Client Windows 8
  • VPN Client Windows 7
  • CCP Display Problem
  • Cisco Support App.

Windows 2012

  • New Features
  • Licensing
  • Hyper-V / VDI
  • Install Hyper-V

Linux

  • File Permissions
  • Webmin
  • Groups - Users
  • Samba Setup