Solved

Bestpractice in offsite password management

Posted on 2011-09-22
5
619 Views
Last Modified: 2012-05-12
8 employees are working offsite. Every employee have a PC with a local user and password. They all connect to a terminal server session using rdp wthout vpn against active directory(locating at the main office). Currently, the local password is set manualy the same as the active directory password.

My goal: I want to be able to change password or to force changes remotely. And I don't want user having 2 passwords.

I thought of changing local user for domain user but here is my concern: If I connect their pc to the domain and they leave the office the password will be save in cached. If a push a password change they will have to change their password when they connect to their RDP session but the local domain password save in cache will not be changed. So user will work with old and new password till they come back to office.

Please help me expert, I hope my story make sense.
0
Comment
Question by:Digico
  • 3
  • 2
5 Comments
 
LVL 7

Expert Comment

by:eugene20022002
ID: 36582814
HI

My initial thoughts were add the machine to the domain but what you could also consider is setting up a local group policy (Computer) and then setting the "maximum password age" to what you require e.g 60 so that every 2 months they would be prompted to change their passwords (locally)

You will need to set this up initially on each machine but if its just a few users,then it should go quick.

This way you can control their TS passwords thru AD and their local machine password with local group policy.

Is this something you think may work for you?
0
 
LVL 3

Author Comment

by:Digico
ID: 36582845
Thank you for your answer!

I thought of that. I really don't want user having to deal with two passwords. I would prefer a method were the computer password is sync or the same as the ts server password(ad).
0
 
LVL 7

Expert Comment

by:eugene20022002
ID: 36582908
how about setting both the local and AD password policy at the same time with the same amount of days? Then with a little user education (which you may want seeing they remote users) it can password prompt the same day and you can tell them to use the same password. If you set it to 60 days for example thats asking them to essentially change their password 6 times in a year which I think is hardly a tough ask from a users point of view.
0
 
LVL 7

Accepted Solution

by:
eugene20022002 earned 500 total points
ID: 36582931
0
 
LVL 3

Author Closing Comment

by:Digico
ID: 36600614
Thank
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Scenario:  You do full backups to a internal hard drive in either product (SBS or Server 2008).  All goes well for a very long time.  One day, backups begin to fail with a message that the disk is full.  Your disk contains many, many more backups th…
I was supporting a handful of Windows 2008 (non-R2) 2 node clusters with shared quorum disks. Some had SQL 2008 installed and some were just a vendor application that we supported. For the purposes of this article it doesn’t really matter which so w…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question