how do you handle mobile users and account lockout?


windows server 2008 r2

in article, interactive logon: require domain controller authentication unlock workstation

mentions that:

"set interactive logon: require domain controller authentication unlock workstation enabled , set interactive logon: number of previous logons cache (in case domain controller not available) 0. when console of device locked user or automatically screen saver time-out, console can unlocked if user able re-authenticate domain controller. if no domain controller available, users cannot unlock devices."

reading seems easy implement comes mobile users. if outside company, how going authenticate without cached credentials?

how others implementing account lockout then?

hi,

yes. after implementing fine grained password policies worked. thread https://social.technet.microsoft.com/forums/en-us/244b0f71-a5f7-4f77-bf76-ecc4e2539328/ad-user-still-not-getting-lockout?forum=winservergp

thanks help.

regards,



Windows Server  >  Windows Server General Forum



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file