I understand that when a user logs onto a client in an AD environment, the client needs to be able to contact a GC in order to verify the user's group membership..
I was wondering, what happens if a GC cannot be reached? Would the user still be able to be logged in?
And- once the user has logged in once succesfully, does the GC need to be contacted the subsequent times, or is the group membership info cached?
And I assume this applies only to multidomain forests?