Solved

Bestpractice in offsite password management

Posted on 2011-09-22
5
622 Views
Last Modified: 2012-05-12
8 employees are working offsite. Every employee have a PC with a local user and password. They all connect to a terminal server session using rdp wthout vpn against active directory(locating at the main office). Currently, the local password is set manualy the same as the active directory password.

My goal: I want to be able to change password or to force changes remotely. And I don't want user having 2 passwords.

I thought of changing local user for domain user but here is my concern: If I connect their pc to the domain and they leave the office the password will be save in cached. If a push a password change they will have to change their password when they connect to their RDP session but the local domain password save in cache will not be changed. So user will work with old and new password till they come back to office.

Please help me expert, I hope my story make sense.
0
Comment
Question by:Digico
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 7

Expert Comment

by:eugene20022002
ID: 36582814
HI

My initial thoughts were add the machine to the domain but what you could also consider is setting up a local group policy (Computer) and then setting the "maximum password age" to what you require e.g 60 so that every 2 months they would be prompted to change their passwords (locally)

You will need to set this up initially on each machine but if its just a few users,then it should go quick.

This way you can control their TS passwords thru AD and their local machine password with local group policy.

Is this something you think may work for you?
0
 
LVL 3

Author Comment

by:Digico
ID: 36582845
Thank you for your answer!

I thought of that. I really don't want user having to deal with two passwords. I would prefer a method were the computer password is sync or the same as the ts server password(ad).
0
 
LVL 7

Expert Comment

by:eugene20022002
ID: 36582908
how about setting both the local and AD password policy at the same time with the same amount of days? Then with a little user education (which you may want seeing they remote users) it can password prompt the same day and you can tell them to use the same password. If you set it to 60 days for example thats asking them to essentially change their password 6 times in a year which I think is hardly a tough ask from a users point of view.
0
 
LVL 7

Accepted Solution

by:
eugene20022002 earned 500 total points
ID: 36582931
0
 
LVL 3

Author Closing Comment

by:Digico
ID: 36600614
Thank
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will give a short introduction and overview of Backup Exec 2012 and how to navigate and perform basic functions. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as conne…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question