Solved

Bestpractice in offsite password management

Posted on 2011-09-22
5
618 Views
Last Modified: 2012-05-12
8 employees are working offsite. Every employee have a PC with a local user and password. They all connect to a terminal server session using rdp wthout vpn against active directory(locating at the main office). Currently, the local password is set manualy the same as the active directory password.

My goal: I want to be able to change password or to force changes remotely. And I don't want user having 2 passwords.

I thought of changing local user for domain user but here is my concern: If I connect their pc to the domain and they leave the office the password will be save in cached. If a push a password change they will have to change their password when they connect to their RDP session but the local domain password save in cache will not be changed. So user will work with old and new password till they come back to office.

Please help me expert, I hope my story make sense.
0
Comment
Question by:Digico
  • 3
  • 2
5 Comments
 
LVL 7

Expert Comment

by:eugene20022002
ID: 36582814
HI

My initial thoughts were add the machine to the domain but what you could also consider is setting up a local group policy (Computer) and then setting the "maximum password age" to what you require e.g 60 so that every 2 months they would be prompted to change their passwords (locally)

You will need to set this up initially on each machine but if its just a few users,then it should go quick.

This way you can control their TS passwords thru AD and their local machine password with local group policy.

Is this something you think may work for you?
0
 
LVL 3

Author Comment

by:Digico
ID: 36582845
Thank you for your answer!

I thought of that. I really don't want user having to deal with two passwords. I would prefer a method were the computer password is sync or the same as the ts server password(ad).
0
 
LVL 7

Expert Comment

by:eugene20022002
ID: 36582908
how about setting both the local and AD password policy at the same time with the same amount of days? Then with a little user education (which you may want seeing they remote users) it can password prompt the same day and you can tell them to use the same password. If you set it to 60 days for example thats asking them to essentially change their password 6 times in a year which I think is hardly a tough ask from a users point of view.
0
 
LVL 7

Accepted Solution

by:
eugene20022002 earned 500 total points
ID: 36582931
0
 
LVL 3

Author Closing Comment

by:Digico
ID: 36600614
Thank
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Scenario:  You do full backups to a internal hard drive in either product (SBS or Server 2008).  All goes well for a very long time.  One day, backups begin to fail with a message that the disk is full.  Your disk contains many, many more backups th…
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
This tutorial will give a an overview on how to deploy remote agents in Backup Exec 2012 to new servers. Click on the Backup Exec button in the upper left corner. From here, are global settings for the application such as connecting to a remote Back…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

930 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now