We help IT Professionals succeed at work.
Get Started

Disable a users ability to login to a laptop when AD is not available

677 Views
Last Modified: 2012-09-11
I am trying to figure out if I can set a timer on the cached credentials on a windows 7 laptop via gpo to disable the ability to logon to a laptop if they have not connected to AD for x amount of days.

So example:

Sales guy is on the road and gets let go.  While out of the office he is using his cached domain credentials for authentication.  I want to configure all the laptops so that if a user dosen't connect to AD in say 8 days that he will not be able to login to his laptop.  I also plan on enabling bitlocker so that if he pulls the drive he will not be able to get any data off it.

domain function level is at 2008 r2

has anyone done this?
Comment
Watch Question
Solutions Architect, Project Lead
CERTIFIED EXPERT
Top Expert 2013
Commented:
This problem has been solved!
Unlock 3 Answers and 3 Comments.
See Answers
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE