Compare cert salaries and plan your next career move
spike_tomahawk wrote: After you unlock their account, they can go to another computer, log on, they will be prompted to change their password, after changing then they can go back and log on to the locked machine with the new password, they just changed it to.
bighornsheep wrote: spike_tomahawk wrote: After you unlock their account, they can go to another computer, log on, they will be prompted to change their password, after changing then they can go back and log on to the locked machine with the new password, they just changed it to. I am pretty sure this only works if the GP setting "cached credentials" is disabled, and you force "authentication with DC", otherwise the workstation will parse your unlock process locally with the cached logon information.
sprkymrk wrote: We do not have "Require domain controller authentication to unlock workstation" set, and we do enable cached logons. We have used Spike's method in the past before we required smart cards and it worked. I belive it is because the computer will only normally resort to cached credentials if the network cable is unplugged or it is unable to contact the DC.
bighornsheep wrote: sprkymrk wrote: We do not have "Require domain controller authentication to unlock workstation" set, and we do enable cached logons. We have used Spike's method in the past before we required smart cards and it worked. I belive it is because the computer will only normally resort to cached credentials if the network cable is unplugged or it is unable to contact the DC. Was this in a Win2k3 + XP environment? Or Mix Win2k/Win2k3 + XP/Win2k...I've tried the "login to another workstation method" described above before with XP+Win2k3 and it didn't work, the sysadmin told me it's likely because of cached credentials.
Lee H wrote: how can you say it is not a flaw there should be something in place to protect these users from losing work how about this - once password has expired and user locks PC, when they re-log into PC it then asks for a change of password as it has now expired, it should not lock them out completely and have them restart pc to get in does anyone agrre with blargoe that this isnt a flaw lee h
Compare salaries for top cybersecurity certifications. Free download for TechExams community.