Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cached Credentials

Status
Not open for further replies.

Kiwica

IS-IT--Management
Feb 26, 2003
102
US
Hi.. My apoligises if this is the wrong forum...

I have an Xp pro lap-top thats part of a domain, and I want the user to be able to use the laptop at home (doesnt need domain resoources at home). How or where do I set it up so he can used cached credentials so he can log on outside the domain? At the moment he gets an error message telling him he cant log on as the domain cant be found.

The domain is windows 2003

Cheers for any help...

"Have you ever imagined a world with no hypothetical situations?
 
You have to distinguish between the local console and a workstation that is a member of a Domain.

The local console, and its Administrator, are what is created when you install XP. When you join a Domain, you are no longer at the local console, you are a Domain member, and the Domain Group Policies, User Profiles, and Administrator change.

This is reflected in the fact that you know have a scrollable box under Domain in the logon window. One entry will be for a Domain logon, one entry will be to logon to the local console (not as a Domain member)."

Windows XP Setup
thread779-621011
 
You do not need to be a local user on the computer for cached credentials to work. Windows XP caches the logon credentials of the last 10 users who log on to a system by default. This is so a user can continue to log on to a system in the instance that a domain controller can not be contacted. First thing, for cached credentials to work, make sure that the user has authenticated to a domain controller (with their most recent password) on the laptop to be used prior to using cached credentials. Other than that check these settings to make sure cached credentials are enabled.

- Click Start >Run >type gpedit.msc
- Check Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options
- Check "Interactive Logon: Number of Previous Logins To Cache" (if value is set to 0 then cached credentials is disabled)

Also check....
- Computer Configuration\Administrative Templates\System\Logon
- Check "Always wait for the network at computer startup and logon" (make sure that this is either not configured or disabled)

Joey
A+, MCP
 
With regards to this example, what possible reason could there be for windows xp to not allow a user to logon outside the domain?

The problem I have is that we have laptop shared by about 8 users. All users have logged into the laptop when its been connected to the domain. However, when away from the domain, the laptop will only allow the last person who logged into the laptop whilst it was on the domain to login. It will reject all other username and passwords when away from the domain.

Is this group policy related? Any advice would be appreciated!
 
Run a Resultant Set of Policy on the laptop (Start >Run >type rsop.msc) on the laptop. Navigate to the group policy setting "Interactive Logon: Number of Previous Logins To Cache" (see above for full path) and see if a policy is defined. If the value is set at "1" then the laptop will only remember the last person who logged in.

Joey
A+, Network+, MCP, Wireless#
 
Hi IllogicallyLogical, thanks for your reply!Much appreciated.

I ran your rsop.msc and the policy was undefined. I then ran gpedit.msc and the security setting is set to 10 logons.

If this is set to 10, do you have any other suggestions as to what could be causing my issue? Your advice is appreciated!
 
How often are the users logging into the laptop? Are they logging in after domain password changes to update the cached credentials?

Joey
A+, Network+, MCP, Wireless#
 
Another thing you can look at is this -

306992 - HOW TO: Manage Stored User Names and Passwords on a Computer in a Domain in Windows XP

306541 - HOW TO: Manage Stored User Names and Passwords on a Computer That Is Not in a Domain in Windows XP

Behavior of stored user names and passwords
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top