TomPro
asked on
Running KeyMgr.dll remotely
As many other people have complained, we've had problems with people saving credentials when they connect through a proxy server, and then their accounts get locked out weeks later when they change their password.
We have proven that this problem can be solved by accessing KeyMgr.dll and deleting any of the saved credentials.
We have users who touch literally 100's of computers in a month, and so when their account gets locked out, trying to track down which computers they might have touched, and then log into each individually and clear the credentials by hand is an arduous task.
Question: Is there a way to do the equivalent of running KeyMgr.dll and deleting ALL saved credentials, but to do this remotely (or even better: via batch) to computers remotely?
We have proven that this problem can be solved by accessing KeyMgr.dll and deleting any of the saved credentials.
We have users who touch literally 100's of computers in a month, and so when their account gets locked out, trying to track down which computers they might have touched, and then log into each individually and clear the credentials by hand is an arduous task.
Question: Is there a way to do the equivalent of running KeyMgr.dll and deleting ALL saved credentials, but to do this remotely (or even better: via batch) to computers remotely?
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
RobSampson had it right. Thanks VERY much for all your help. I apologize for the delay in closing.
ASKER
Is there a way to run the /list version remotely? For instance: Can I create a batch that runs on the AD that would query each of the domain members one by one and return the results of a CmdKey /list for each?
I want to add the script with the delete/*, but I'd like to be able to check all of the systems before I implement the script to make sure that I'm not deleting something that should really still be there, and with some 1000 member servers, it'll take forever for me to log into each one at a time to check their listings.