Policies on Remote Laptops

Posted on 2009-05-06
Last Modified: 2013-11-17
We are adding MDCs to our Deputy cars and I want to know some good policies.  Would it be better to add the users as local users or cached domain users?  We are using cell cards and then connecting to our network through VPN.  They will be using OWA and my worry is how passwords are going to work since we set a default GPO for passwords on both Domain & Local Policies.  Most of the MDC's will probably not log into our network very often so their domain password for OWA may expire without them knowing any good ideas on best practices? Is their a way to sink their local and domain user passwords to expire at the same time?
Question by:ocontoco
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
LVL 78

Expert Comment

ID: 24332746
A single location to manage the user is best.
You may wish to follow the same mechanism discussed in

Author Comment

ID: 24358716
I'm using a Cisco VPN Client.  I have created a Virtual Private Network and used the Dial-Up connect options but we use groups and there is no where to put the group when creating the network connection.  I have been able to change the passwords while using VPN but if I force a password change in AD it does flow through.  Also if I change the users password in AD it doesnt flow through untill I'm plugged into my network directly.  Any suggestion on what I need to be doing differently?
LVL 78

Expert Comment

ID: 24359680
The password change can only occur from the client side because when they are outside the LAN, they are working with Cached credentials.
You could set a local policy to expire passwords in the same frequency as you have on the AD, but as noted in the other similar EE post, the user must login into the laptop with the VPN option to push the password change to the AD.

Author Comment

ID: 24364061
How do you setup your VPN Client to do this? I seem to have problems getting this to work.  
LVL 78

Accepted Solution

arnold earned 125 total points
ID: 24366322
At the time of login, you have to use the dial-using VPN.  The other EE article discusses it.  Which Version of the cisco VPN client are you using?

Featured Post

DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lithium-ion batteries area cornerstone of today's portable electronic devices, and even though they are relied upon heavily, their chemistry and origin are not of common knowledge. This article is about a device on which every smartphone, laptop, an…
When you start your Windows 10 PC and got an "Operating system not found" error or just saw  "Auto repair for startup" or a blinking cursor with black screen. A loop for Auto repair will start but fix nothing.  You will be panic as there are no back…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Finding and deleting duplicate (picture) files can be a time consuming task. My wife and I, our three kids and their families all share one dilemma: Managing our pictures. Between desktops, laptops, phones, tablets, and cameras; over the last decade…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question