ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    [Help] Windows 10 lost AD profile [remote user]

    IT Discussion
    7
    33
    2.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      stess @black3dynamite
      last edited by

      @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

      @stess said in [Help] Windows 10 lost AD profile [remote user]:

      @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

      Interactive logon: Number of previous logons to cache

      https://docs.microsoft.com/en-us/windows/device-security/security-policy-settings/interactive-logon-number-of-previous-logons-to-cache-in-case-domain-controller-is-not-available

      Check to see if Protected Users is configured.

      https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/how-to-configure-protected-accounts

      I already checked protected user group. We do not have anyone/group in it.

      I'll read about this logon cache.

      It might just be easier if you setup VPN on her laptop and have her login.

      That's already on the list. But my plate is full, and it's not that urgent. Just that I've never seen this issue before. Any I want to prevent it from happening... ever again.

      1 Reply Last reply Reply Quote 0
      • JaredBuschJ
        JaredBusch
        last edited by

        Cached creds have expired.

        Log in on the network.

        S DashrenderD 2 Replies Last reply Reply Quote 2
        • S
          stess @JaredBusch
          last edited by

          @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

          Cached creds have expired.

          Log in on the network.

          Anyway to prevent it from expiring? or extend the caching?

          black3dynamiteB JaredBuschJ 2 Replies Last reply Reply Quote 0
          • black3dynamiteB
            black3dynamite @stess
            last edited by black3dynamite

            @stess said in [Help] Windows 10 lost AD profile [remote user]:

            @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

            Cached creds have expired.

            Log in on the network.

            Anyway to prevent it from expiring? or extend the caching?

            Increase the value. The max is 50.

            S 1 Reply Last reply Reply Quote 0
            • JaredBuschJ
              JaredBusch @stess
              last edited by

              @stess said in [Help] Windows 10 lost AD profile [remote user]:

              @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

              Cached creds have expired.

              Log in on the network.

              Anyway to prevent it from expiring? or extend the caching?

              You can change domain settings related to this. But it has been years since I looked into it.

              It could be the machine credentials have expired and not user.

              Domain machines are not designed to be off the network forever.

              1 Reply Last reply Reply Quote 2
              • S
                stess @black3dynamite
                last edited by

                @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                @stess said in [Help] Windows 10 lost AD profile [remote user]:

                @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                Cached creds have expired.

                Log in on the network.

                Anyway to prevent it from expiring? or extend the caching?

                Increase the value. The max is 50.

                Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                " ?

                @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                @stess said in [Help] Windows 10 lost AD profile [remote user]:

                @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                Cached creds have expired.

                Log in on the network.

                Anyway to prevent it from expiring? or extend the caching?

                You can change domain settings related to this. But it has been years since I looked into it.

                It could be the machine credentials have expired and not user.

                Domain machines are not designed to be off the network forever.

                Any keyword I can start off with? Especially the machine credentials setting.

                black3dynamiteB 2 Replies Last reply Reply Quote 0
                • black3dynamiteB
                  black3dynamite @stess
                  last edited by

                  @stess said in [Help] Windows 10 lost AD profile [remote user]:

                  Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                  " ?

                  Yes.

                  S 1 Reply Last reply Reply Quote 0
                  • black3dynamiteB
                    black3dynamite @stess
                    last edited by

                    @stess said in [Help] Windows 10 lost AD profile [remote user]:

                    @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                    @stess said in [Help] Windows 10 lost AD profile [remote user]:

                    @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                    Cached creds have expired.

                    Log in on the network.

                    Anyway to prevent it from expiring? or extend the caching?

                    Increase the value. The max is 50.

                    Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                    " ?

                    @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                    @stess said in [Help] Windows 10 lost AD profile [remote user]:

                    @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                    Cached creds have expired.

                    Log in on the network.

                    Anyway to prevent it from expiring? or extend the caching?

                    You can change domain settings related to this. But it has been years since I looked into it.

                    It could be the machine credentials have expired and not user.

                    Domain machines are not designed to be off the network forever.

                    Any keyword I can start off with? Especially the machine credentials setting.

                    https://docs.microsoft.com/en-us/windows/device-security/security-policy-settings/domain-member-maximum-machine-account-password-age

                    1 Reply Last reply Reply Quote 0
                    • S
                      stess @black3dynamite
                      last edited by

                      @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                      @stess said in [Help] Windows 10 lost AD profile [remote user]:

                      Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                      " ?

                      Yes.

                      I just checked all the GPOs. We do not have this enabled. Should I enable it?

                      black3dynamiteB 1 Reply Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender @JaredBusch
                        last edited by

                        @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                        Cached creds have expired.

                        Log in on the network.

                        They do that?
                        I just today had a laptop come into the office that hasn't logged in over a year. In fact I had deleted the computer account too. While the PC was on the network, it refused to logon because there was no domain computer account, but once I disconnected the network, the cached creds worked just fine.

                        1 Reply Last reply Reply Quote 0
                        • momurdaM
                          momurda
                          last edited by

                          You can try disabling nic then rebooting, then logging in using credentials. If it is a laptop wifi adapter you can do this with Fn keys probably. Might have to use [email protected] if they chose Other User previously.

                          1 Reply Last reply Reply Quote 0
                          • black3dynamiteB
                            black3dynamite @stess
                            last edited by

                            @stess said in [Help] Windows 10 lost AD profile [remote user]:

                            @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                            @stess said in [Help] Windows 10 lost AD profile [remote user]:

                            Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                            " ?

                            Yes.

                            I just checked all the GPOs. We do not have this enabled. Should I enable it?

                            You normally have this enabled and set to 2 or more for mobile users.

                            1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller
                              last edited by

                              Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                              black3dynamiteB 1 Reply Last reply Reply Quote 0
                              • black3dynamiteB
                                black3dynamite @scottalanmiller
                                last edited by

                                @scottalanmiller said in [Help] Windows 10 lost AD profile [remote user]:

                                Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                                Not a bad idea. I’ve been going that route for mobile users for awhile.

                                DashrenderD 1 Reply Last reply Reply Quote 0
                                • DashrenderD
                                  Dashrender @black3dynamite
                                  last edited by

                                  @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                                  @scottalanmiller said in [Help] Windows 10 lost AD profile [remote user]:

                                  Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                                  Not a bad idea. I’ve been going that route for mobile users for awhile.

                                  How do you manage them? or do you just not worry about them?

                                  black3dynamiteB dbeatoD 2 Replies Last reply Reply Quote 0
                                  • black3dynamiteB
                                    black3dynamite @Dashrender
                                    last edited by

                                    @dashrender said in [Help] Windows 10 lost AD profile [remote user]:

                                    @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                                    @scottalanmiller said in [Help] Windows 10 lost AD profile [remote user]:

                                    Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                                    Not a bad idea. I’ve been going that route for mobile users for awhile.

                                    How do you manage them? or do you just not worry about them?

                                    Majority of mobile users are instructors that don't have there own laptop uses the laptop issued to them for presentations.

                                    DashrenderD 1 Reply Last reply Reply Quote 0
                                    • DashrenderD
                                      Dashrender @black3dynamite
                                      last edited by

                                      @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                                      @dashrender said in [Help] Windows 10 lost AD profile [remote user]:

                                      @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                                      @scottalanmiller said in [Help] Windows 10 lost AD profile [remote user]:

                                      Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                                      Not a bad idea. I’ve been going that route for mobile users for awhile.

                                      How do you manage them? or do you just not worry about them?

                                      Majority of mobile users are instructors that don't have there own laptop uses the laptop issued to them for presentations.

                                      And I'll pull a @JaredBusch here - That's not an answer to my questions.

                                      black3dynamiteB 1 Reply Last reply Reply Quote 0
                                      • black3dynamiteB
                                        black3dynamite @Dashrender
                                        last edited by

                                        @dashrender said in [Help] Windows 10 lost AD profile [remote user]:

                                        @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                                        @dashrender said in [Help] Windows 10 lost AD profile [remote user]:

                                        @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                                        @scottalanmiller said in [Help] Windows 10 lost AD profile [remote user]:

                                        Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                                        Not a bad idea. I’ve been going that route for mobile users for awhile.

                                        How do you manage them? or do you just not worry about them?

                                        Majority of mobile users are instructors that don't have there own laptop uses the laptop issued to them for presentations.

                                        And I'll pull a @JaredBusch here - That's not an answer to my questions.

                                        The short answer: I don't.

                                        1 Reply Last reply Reply Quote 0
                                        • dbeatoD
                                          dbeato @Dashrender
                                          last edited by

                                          @dashrender said in [Help] Windows 10 lost AD profile [remote user]:

                                          @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                                          @scottalanmiller said in [Help] Windows 10 lost AD profile [remote user]:

                                          Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                                          Not a bad idea. I’ve been going that route for mobile users for awhile.

                                          How do you manage them? or do you just not worry about them?

                                          You can use IaaS such as JumpCLoud or anything else.

                                          scottalanmillerS DashrenderD 2 Replies Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller @dbeato
                                            last edited by

                                            @dbeato said in [Help] Windows 10 lost AD profile [remote user]:

                                            @dashrender said in [Help] Windows 10 lost AD profile [remote user]:

                                            @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                                            @scottalanmiller said in [Help] Windows 10 lost AD profile [remote user]:

                                            Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                                            Not a bad idea. I’ve been going that route for mobile users for awhile.

                                            How do you manage them? or do you just not worry about them?

                                            You can use IaaS such as JumpCLoud or anything else.

                                            JumpCloud is SaaS.

                                            Vultr is IaaS.

                                            dbeatoD 1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post