ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    [Help] Windows 10 lost AD profile [remote user]

    IT Discussion
    7
    33
    2.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • black3dynamiteB
      black3dynamite
      last edited by

      Interactive logon: Number of previous logons to cache

      https://docs.microsoft.com/en-us/windows/device-security/security-policy-settings/interactive-logon-number-of-previous-logons-to-cache-in-case-domain-controller-is-not-available

      Check to see if Protected Users is configured.

      https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/how-to-configure-protected-accounts

      S 1 Reply Last reply Reply Quote 0
      • S
        stess @Dashrender
        last edited by

        @dashrender said in [Help] Windows 10 lost AD profile [remote user]:

        @stess said in [Help] Windows 10 lost AD profile [remote user]:

        @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

        Sounds like the her cached user profile is not working correctly.

        I was told similarly from another post. But I am not sure what would be the cause.

        Disk corruption.

        That's a possibility. To note: it's a brand new laptop (2 months old) with decent spec.

        1 Reply Last reply Reply Quote 0
        • S
          stess @black3dynamite
          last edited by

          @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

          Interactive logon: Number of previous logons to cache

          https://docs.microsoft.com/en-us/windows/device-security/security-policy-settings/interactive-logon-number-of-previous-logons-to-cache-in-case-domain-controller-is-not-available

          Check to see if Protected Users is configured.

          https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/how-to-configure-protected-accounts

          I already checked protected user group. We do not have anyone/group in it.

          I'll read about this logon cache.

          black3dynamiteB 1 Reply Last reply Reply Quote 0
          • black3dynamiteB
            black3dynamite @stess
            last edited by

            @stess said in [Help] Windows 10 lost AD profile [remote user]:

            @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

            Interactive logon: Number of previous logons to cache

            https://docs.microsoft.com/en-us/windows/device-security/security-policy-settings/interactive-logon-number-of-previous-logons-to-cache-in-case-domain-controller-is-not-available

            Check to see if Protected Users is configured.

            https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/how-to-configure-protected-accounts

            I already checked protected user group. We do not have anyone/group in it.

            I'll read about this logon cache.

            It might just be easier if you setup VPN on her laptop and have her login.

            S 1 Reply Last reply Reply Quote 1
            • S
              stess @black3dynamite
              last edited by

              @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

              @stess said in [Help] Windows 10 lost AD profile [remote user]:

              @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

              Interactive logon: Number of previous logons to cache

              https://docs.microsoft.com/en-us/windows/device-security/security-policy-settings/interactive-logon-number-of-previous-logons-to-cache-in-case-domain-controller-is-not-available

              Check to see if Protected Users is configured.

              https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/manage/how-to-configure-protected-accounts

              I already checked protected user group. We do not have anyone/group in it.

              I'll read about this logon cache.

              It might just be easier if you setup VPN on her laptop and have her login.

              That's already on the list. But my plate is full, and it's not that urgent. Just that I've never seen this issue before. Any I want to prevent it from happening... ever again.

              1 Reply Last reply Reply Quote 0
              • JaredBuschJ
                JaredBusch
                last edited by

                Cached creds have expired.

                Log in on the network.

                S DashrenderD 2 Replies Last reply Reply Quote 2
                • S
                  stess @JaredBusch
                  last edited by

                  @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                  Cached creds have expired.

                  Log in on the network.

                  Anyway to prevent it from expiring? or extend the caching?

                  black3dynamiteB JaredBuschJ 2 Replies Last reply Reply Quote 0
                  • black3dynamiteB
                    black3dynamite @stess
                    last edited by black3dynamite

                    @stess said in [Help] Windows 10 lost AD profile [remote user]:

                    @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                    Cached creds have expired.

                    Log in on the network.

                    Anyway to prevent it from expiring? or extend the caching?

                    Increase the value. The max is 50.

                    S 1 Reply Last reply Reply Quote 0
                    • JaredBuschJ
                      JaredBusch @stess
                      last edited by

                      @stess said in [Help] Windows 10 lost AD profile [remote user]:

                      @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                      Cached creds have expired.

                      Log in on the network.

                      Anyway to prevent it from expiring? or extend the caching?

                      You can change domain settings related to this. But it has been years since I looked into it.

                      It could be the machine credentials have expired and not user.

                      Domain machines are not designed to be off the network forever.

                      1 Reply Last reply Reply Quote 2
                      • S
                        stess @black3dynamite
                        last edited by

                        @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                        @stess said in [Help] Windows 10 lost AD profile [remote user]:

                        @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                        Cached creds have expired.

                        Log in on the network.

                        Anyway to prevent it from expiring? or extend the caching?

                        Increase the value. The max is 50.

                        Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                        " ?

                        @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                        @stess said in [Help] Windows 10 lost AD profile [remote user]:

                        @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                        Cached creds have expired.

                        Log in on the network.

                        Anyway to prevent it from expiring? or extend the caching?

                        You can change domain settings related to this. But it has been years since I looked into it.

                        It could be the machine credentials have expired and not user.

                        Domain machines are not designed to be off the network forever.

                        Any keyword I can start off with? Especially the machine credentials setting.

                        black3dynamiteB 2 Replies Last reply Reply Quote 0
                        • black3dynamiteB
                          black3dynamite @stess
                          last edited by

                          @stess said in [Help] Windows 10 lost AD profile [remote user]:

                          Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                          " ?

                          Yes.

                          S 1 Reply Last reply Reply Quote 0
                          • black3dynamiteB
                            black3dynamite @stess
                            last edited by

                            @stess said in [Help] Windows 10 lost AD profile [remote user]:

                            @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                            @stess said in [Help] Windows 10 lost AD profile [remote user]:

                            @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                            Cached creds have expired.

                            Log in on the network.

                            Anyway to prevent it from expiring? or extend the caching?

                            Increase the value. The max is 50.

                            Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                            " ?

                            @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                            @stess said in [Help] Windows 10 lost AD profile [remote user]:

                            @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                            Cached creds have expired.

                            Log in on the network.

                            Anyway to prevent it from expiring? or extend the caching?

                            You can change domain settings related to this. But it has been years since I looked into it.

                            It could be the machine credentials have expired and not user.

                            Domain machines are not designed to be off the network forever.

                            Any keyword I can start off with? Especially the machine credentials setting.

                            https://docs.microsoft.com/en-us/windows/device-security/security-policy-settings/domain-member-maximum-machine-account-password-age

                            1 Reply Last reply Reply Quote 0
                            • S
                              stess @black3dynamite
                              last edited by

                              @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                              @stess said in [Help] Windows 10 lost AD profile [remote user]:

                              Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                              " ?

                              Yes.

                              I just checked all the GPOs. We do not have this enabled. Should I enable it?

                              black3dynamiteB 1 Reply Last reply Reply Quote 0
                              • DashrenderD
                                Dashrender @JaredBusch
                                last edited by

                                @jaredbusch said in [Help] Windows 10 lost AD profile [remote user]:

                                Cached creds have expired.

                                Log in on the network.

                                They do that?
                                I just today had a laptop come into the office that hasn't logged in over a year. In fact I had deleted the computer account too. While the PC was on the network, it refused to logon because there was no domain computer account, but once I disconnected the network, the cached creds worked just fine.

                                1 Reply Last reply Reply Quote 0
                                • momurdaM
                                  momurda
                                  last edited by

                                  You can try disabling nic then rebooting, then logging in using credentials. If it is a laptop wifi adapter you can do this with Fn keys probably. Might have to use [email protected] if they chose Other User previously.

                                  1 Reply Last reply Reply Quote 0
                                  • black3dynamiteB
                                    black3dynamite @stess
                                    last edited by

                                    @stess said in [Help] Windows 10 lost AD profile [remote user]:

                                    @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                                    @stess said in [Help] Windows 10 lost AD profile [remote user]:

                                    Are you referred to the "Interactive logon: Number of previous logons to cache (in case domain controller is not available)
                                    " ?

                                    Yes.

                                    I just checked all the GPOs. We do not have this enabled. Should I enable it?

                                    You normally have this enabled and set to 2 or more for mobile users.

                                    1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller
                                      last edited by

                                      Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                                      black3dynamiteB 1 Reply Last reply Reply Quote 0
                                      • black3dynamiteB
                                        black3dynamite @scottalanmiller
                                        last edited by

                                        @scottalanmiller said in [Help] Windows 10 lost AD profile [remote user]:

                                        Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                                        Not a bad idea. I’ve been going that route for mobile users for awhile.

                                        DashrenderD 1 Reply Last reply Reply Quote 0
                                        • DashrenderD
                                          Dashrender @black3dynamite
                                          last edited by

                                          @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                                          @scottalanmiller said in [Help] Windows 10 lost AD profile [remote user]:

                                          Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                                          Not a bad idea. I’ve been going that route for mobile users for awhile.

                                          How do you manage them? or do you just not worry about them?

                                          black3dynamiteB dbeatoD 2 Replies Last reply Reply Quote 0
                                          • black3dynamiteB
                                            black3dynamite @Dashrender
                                            last edited by

                                            @dashrender said in [Help] Windows 10 lost AD profile [remote user]:

                                            @black3dynamite said in [Help] Windows 10 lost AD profile [remote user]:

                                            @scottalanmiller said in [Help] Windows 10 lost AD profile [remote user]:

                                            Always worth asking.... is AD even needed? Maybe moving to local accounts would make more sense.

                                            Not a bad idea. I’ve been going that route for mobile users for awhile.

                                            How do you manage them? or do you just not worry about them?

                                            Majority of mobile users are instructors that don't have there own laptop uses the laptop issued to them for presentations.

                                            DashrenderD 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post