I am trying to figure out if I can set a timer on the cached credentials on a windows 7 laptop via gpo to disable the ability to logon to a laptop if they have not connected to AD for x amount of days.
Sales guy is on the road and gets let go. While out of the office he is using his cached domain credentials for authentication. I want to configure all the laptops so that if a user dosen't connect to AD in say 8 days that he will not be able to login to his laptop. I also plan on enabling bitlocker so that if he pulls the drive he will not be able to get any data off it.
domain function level is at 2008 r2
has anyone done this?