Solved

Policies on Remote Laptops

Posted on 2009-05-06
5
270 Views
Last Modified: 2013-11-17
We are adding MDCs to our Deputy cars and I want to know some good policies.  Would it be better to add the users as local users or cached domain users?  We are using cell cards and then connecting to our network through VPN.  They will be using OWA and my worry is how passwords are going to work since we set a default GPO for passwords on both Domain & Local Policies.  Most of the MDC's will probably not log into our network very often so their domain password for OWA may expire without them knowing any good ideas on best practices? Is their a way to sink their local and domain user passwords to expire at the same time?
0
Comment
Question by:ocontoco
  • 3
  • 2
5 Comments
 
LVL 76

Expert Comment

by:arnold
ID: 24332746
A single location to manage the user is best.
You may wish to follow the same mechanism discussed in http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/Q_24383606.html?cid=544
0
 

Author Comment

by:ocontoco
ID: 24358716
I'm using a Cisco VPN Client.  I have created a Virtual Private Network and used the Dial-Up connect options but we use groups and there is no where to put the group when creating the network connection.  I have been able to change the passwords while using VPN but if I force a password change in AD it does flow through.  Also if I change the users password in AD it doesnt flow through untill I'm plugged into my network directly.  Any suggestion on what I need to be doing differently?
0
 
LVL 76

Expert Comment

by:arnold
ID: 24359680
The password change can only occur from the client side because when they are outside the LAN, they are working with Cached credentials.
You could set a local policy to expire passwords in the same frequency as you have on the AD, but as noted in the other similar EE post, the user must login into the laptop with the VPN option to push the password change to the AD.
0
 

Author Comment

by:ocontoco
ID: 24364061
How do you setup your VPN Client to do this? I seem to have problems getting this to work.  
0
 
LVL 76

Accepted Solution

by:
arnold earned 125 total points
ID: 24366322
At the time of login, you have to use the dial-using VPN.  The other EE article discusses it.  Which Version of the cisco VPN client are you using?
http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_tech_note09186a00807955bc.shtml
0

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now