ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    [Help] Windows 10 lost AD profile [remote user]

    IT Discussion
    7
    33
    2.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DashrenderD
      Dashrender @stess
      last edited by

      @stess said in [Help] Windows 10 lost AD profile [remote user]:

      @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

      Sounds like the her cached user profile is not working correctly.

      I was told similarly from another post. But I am not sure what would be the cause.

      Disk corruption.

      S 1 Reply Last reply Reply Quote 0
      • black3dynamiteB
        black3dynamite
        last edited by

        Interactive logon: Number of previous logons to cache

        https://docs.microsoft.com/en-us/windows/device-security/security-policy-settings/interactive-logon-number-of-previous-logons-to-cache-in-case-domain-controller-is-not-available

        Check to see if Protected Users is configured.

        https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/how-to-configure-protected-accounts

        S 1 Reply Last reply Reply Quote 0
        • S
          stess @Dashrender
          last edited by

          @dashrender said in [Help] Windows 10 lost AD profile [remote user]:

          @stess said in [Help] Windows 10 lost AD profile [remote user]:

          @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

          Sounds like the her cached user profile is not working correctly.

          I was told similarly from another post. But I am not sure what would be the cause.

          Disk corruption.

          That's a possibility. To note: it's a brand new laptop (2 months old) with decent spec.

          1 Reply Last reply Reply Quote 0
          • S
            stess @black3dynamite
            last edited by

            @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

            Interactive logon: Number of previous logons to cache

            https://docs.microsoft.com/en-us/windows/device-security/security-policy-settings/interactive-logon-number-of-previous-logons-to-cache-in-case-domain-controller-is-not-available

            Check to see if Protected Users is configured.

            https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/how-to-configure-protected-accounts

            I already checked protected user group. We do not have anyone/group in it.

            I'll read about this logon cache.

            black3dynamiteB 1 Reply Last reply Reply Quote 0
            • black3dynamiteB
              black3dynamite @stess
              last edited by

              @stess said in [Help] Windows 10 lost AD profile [remote user]:

              @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

              Interactive logon: Number of previous logons to cache

              https://docs.microsoft.com/en-us/windows/device-security/security-policy-settings/interactive-logon-number-of-previous-logons-to-cache-in-case-domain-controller-is-not-available

              Check to see if Protected Users is configured.

              https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/how-to-configure-protected-accounts

              I already checked protected user group. We do not have anyone/group in it.

              I'll read about this logon cache.

              It might just be easier if you setup VPN on her laptop and have her login.

              S 1 Reply Last reply Reply Quote 1
              • S
                stess @black3dynamite
                last edited by

                @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                @stess said in [Help] Windows 10 lost AD profile [remote user]:

                @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                Interactive logon: Number of previous logons to cache

                https://docs.microsoft.com/en-us/windows/device-security/security-policy-settings/interactive-logon-number-of-previous-logons-to-cache-in-case-domain-controller-is-not-available

                Check to see if Protected Users is configured.

                https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/how-to-configure-protected-accounts

                I already checked protected user group. We do not have anyone/group in it.

                I'll read about this logon cache.

                It might just be easier if you setup VPN on her laptop and have her login.

                That's already on the list. But my plate is full, and it's not that urgent. Just that I've never seen this issue before. Any I want to prevent it from happening... ever again.

                1 Reply Last reply Reply Quote 0
                • JaredBuschJ
                  JaredBusch
                  last edited by

                  Cached creds have expired.

                  Log in on the network.

                  S DashrenderD 2 Replies Last reply Reply Quote 2
                  • S
                    stess @JaredBusch
                    last edited by

                    @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                    Cached creds have expired.

                    Log in on the network.

                    Anyway to prevent it from expiring? or extend the caching?

                    black3dynamiteB JaredBuschJ 2 Replies Last reply Reply Quote 0
                    • black3dynamiteB
                      black3dynamite @stess
                      last edited by black3dynamite

                      @stess said in [Help] Windows 10 lost AD profile [remote user]:

                      @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                      Cached creds have expired.

                      Log in on the network.

                      Anyway to prevent it from expiring? or extend the caching?

                      Increase the value. The max is 50.

                      S 1 Reply Last reply Reply Quote 0
                      • JaredBuschJ
                        JaredBusch @stess
                        last edited by

                        @stess said in [Help] Windows 10 lost AD profile [remote user]:

                        @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                        Cached creds have expired.

                        Log in on the network.

                        Anyway to prevent it from expiring? or extend the caching?

                        You can change domain settings related to this. But it has been years since I looked into it.

                        It could be the machine credentials have expired and not user.

                        Domain machines are not designed to be off the network forever.

                        1 Reply Last reply Reply Quote 2
                        • S
                          stess @black3dynamite
                          last edited by

                          @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                          @stess said in [Help] Windows 10 lost AD profile [remote user]:

                          @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                          Cached creds have expired.

                          Log in on the network.

                          Anyway to prevent it from expiring? or extend the caching?

                          Increase the value. The max is 50.

                          Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                          " ?

                          @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                          @stess said in [Help] Windows 10 lost AD profile [remote user]:

                          @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                          Cached creds have expired.

                          Log in on the network.

                          Anyway to prevent it from expiring? or extend the caching?

                          You can change domain settings related to this. But it has been years since I looked into it.

                          It could be the machine credentials have expired and not user.

                          Domain machines are not designed to be off the network forever.

                          Any keyword I can start off with? Especially the machine credentials setting.

                          black3dynamiteB 2 Replies Last reply Reply Quote 0
                          • black3dynamiteB
                            black3dynamite @stess
                            last edited by

                            @stess said in [Help] Windows 10 lost AD profile [remote user]:

                            Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                            " ?

                            Yes.

                            S 1 Reply Last reply Reply Quote 0
                            • black3dynamiteB
                              black3dynamite @stess
                              last edited by

                              @stess said in [Help] Windows 10 lost AD profile [remote user]:

                              @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                              @stess said in [Help] Windows 10 lost AD profile [remote user]:

                              @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                              Cached creds have expired.

                              Log in on the network.

                              Anyway to prevent it from expiring? or extend the caching?

                              Increase the value. The max is 50.

                              Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                              " ?

                              @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                              @stess said in [Help] Windows 10 lost AD profile [remote user]:

                              @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                              Cached creds have expired.

                              Log in on the network.

                              Anyway to prevent it from expiring? or extend the caching?

                              You can change domain settings related to this. But it has been years since I looked into it.

                              It could be the machine credentials have expired and not user.

                              Domain machines are not designed to be off the network forever.

                              Any keyword I can start off with? Especially the machine credentials setting.

                              https://docs.microsoft.com/en-us/windows/device-security/security-policy-settings/domain-member-maximum-machine-account-password-age

                              1 Reply Last reply Reply Quote 0
                              • S
                                stess @black3dynamite
                                last edited by

                                @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                                @stess said in [Help] Windows 10 lost AD profile [remote user]:

                                Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                                " ?

                                Yes.

                                I just checked all the GPOs. We do not have this enabled. Should I enable it?

                                black3dynamiteB 1 Reply Last reply Reply Quote 0
                                • DashrenderD
                                  Dashrender @JaredBusch
                                  last edited by

                                  @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                                  Cached creds have expired.

                                  Log in on the network.

                                  They do that?
                                  I just today had a laptop come into the office that hasn't logged in over a year. In fact I had deleted the computer account too. While the PC was on the network, it refused to logon because there was no domain computer account, but once I disconnected the network, the cached creds worked just fine.

                                  1 Reply Last reply Reply Quote 0
                                  • momurdaM
                                    momurda
                                    last edited by

                                    You can try disabling nic then rebooting, then logging in using credentials. If it is a laptop wifi adapter you can do this with Fn keys probably. Might have to use [email protected] if they chose Other User previously.

                                    1 Reply Last reply Reply Quote 0
                                    • black3dynamiteB
                                      black3dynamite @stess
                                      last edited by

                                      @stess said in [Help] Windows 10 lost AD profile [remote user]:

                                      @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                                      @stess said in [Help] Windows 10 lost AD profile [remote user]:

                                      Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                                      " ?

                                      Yes.

                                      I just checked all the GPOs. We do not have this enabled. Should I enable it?

                                      You normally have this enabled and set to 2 or more for mobile users.

                                      1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller
                                        last edited by

                                        Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                                        black3dynamiteB 1 Reply Last reply Reply Quote 0
                                        • black3dynamiteB
                                          black3dynamite @scottalanmiller
                                          last edited by

                                          @scottalanmiller said in [Help] Windows 10 lost AD profile [remote user]:

                                          Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                                          Not a bad idea. I’ve been going that route for mobile users for awhile.

                                          DashrenderD 1 Reply Last reply Reply Quote 0
                                          • DashrenderD
                                            Dashrender @black3dynamite
                                            last edited by

                                            @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                                            @scottalanmiller said in [Help] Windows 10 lost AD profile [remote user]:

                                            Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                                            Not a bad idea. I’ve been going that route for mobile users for awhile.

                                            How do you manage them? or do you just not worry about them?

                                            black3dynamiteB dbeatoD 2 Replies Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post