Cached credentials

Cached credentials

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Cached credentials luissol 10-22-2007
Posted by luissol on October 22, 2007, 9:06 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi I want to know how much time a credential of a user belonging a
domain lasts in a computer without access to the domain controller?

I know there is a configuration for saving the cache credentials for
10 users, but I want to know if there is other way besides putting the
value of "number of previous logons to chache" to zero that allow me
to control the time that a cached credential is valid

thanks a lot
Luis


Posted by Steven L Umbach on October 22, 2007, 11:17 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
As far as I can tell cached credentials are good for a very long time and
don't know if there is an actual time limit. I have come across a user that
had a old laptop from work that was using them over a year after being off
the network connected to a domain controller.

The value you see in security policy controls the number of domain users
that can have cached credentials on a domain computer and not the number of
times a domain user can logon with cached credentials. Of course if a domain
user connects to their network where a domain controller lives [or through a
VPN] and their password has been changed in Active Directory they will not
be able to access domain network resources with the cached credentials that
use the old password.

Steve


> Hi I want to know how much time a credential of a user belonging a
> domain lasts in a computer without access to the domain controller?
>
> I know there is a configuration for saving the cache credentials for
> 10 users, but I want to know if there is other way besides putting the
> value of "number of previous logons to chache" to zero that allow me
> to control the time that a cached credential is valid
>
> thanks a lot
> Luis
>



Posted by Steve Riley [MSFT] on October 23, 2007, 9:17 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Correct, cached credentials never expire.

--
Steve Riley
steve.riley@microsoft.com
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com


> As far as I can tell cached credentials are good for a very long time and
> don't know if there is an actual time limit. I have come across a user
> that had a old laptop from work that was using them over a year after
> being off the network connected to a domain controller.
>
> The value you see in security policy controls the number of domain users
> that can have cached credentials on a domain computer and not the number
> of times a domain user can logon with cached credentials. Of course if a
> domain user connects to their network where a domain controller lives [or
> through a VPN] and their password has been changed in Active Directory
> they will not be able to access domain network resources with the cached
> credentials that use the old password.
>
> Steve
>
>
>> Hi I want to know how much time a credential of a user belonging a
>> domain lasts in a computer without access to the domain controller?
>>
>> I know there is a configuration for saving the cache credentials for
>> 10 users, but I want to know if there is other way besides putting the
>> value of "number of previous logons to chache" to zero that allow me
>> to control the time that a cached credential is valid
>>
>> thanks a lot
>> Luis
>>
>
>

Posted by Steven L Umbach on October 24, 2007, 12:17 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks for verifying that Steve.

Steve


> Correct, cached credentials never expire.
>
> --
> Steve Riley
> steve.riley@microsoft.com
> http://blogs.technet.com/steriley
> http://www.protectyourwindowsnetwork.com
>
>
>> As far as I can tell cached credentials are good for a very long time and
>> don't know if there is an actual time limit. I have come across a user
>> that had a old laptop from work that was using them over a year after
>> being off the network connected to a domain controller.
>>
>> The value you see in security policy controls the number of domain users
>> that can have cached credentials on a domain computer and not the number
>> of times a domain user can logon with cached credentials. Of course if a
>> domain user connects to their network where a domain controller lives [or
>> through a VPN] and their password has been changed in Active Directory
>> they will not be able to access domain network resources with the cached
>> credentials that use the old password.
>>
>> Steve
>>
>>
>>> Hi I want to know how much time a credential of a user belonging a
>>> domain lasts in a computer without access to the domain controller?
>>>
>>> I know there is a configuration for saving the cache credentials for
>>> 10 users, but I want to know if there is other way besides putting the
>>> value of "number of previous logons to chache" to zero that allow me
>>> to control the time that a cached credential is valid
>>>
>>> thanks a lot
>>> Luis
>>>
>>
>>



Similar ThreadsPosted
Access with cached credentials December 19, 2005, 4:31 am
Clearing Cached Credentials? January 11, 2007, 8:54 am
Control time limit of cached credentials July 2, 2008, 10:58 am
How to removed cached credentials from Remote Desktop Client February 5, 2007, 6:05 pm
the credentials cannot be verified June 12, 2008, 9:41 am
How to use WinLogon API to solicit credentials? July 19, 2005, 1:21 pm
Machine and User credentials October 9, 2006, 5:10 pm
Re: Logon to account with different credentials February 12, 2007, 12:44 am
Logon to account with different credentials February 11, 2007, 9:12 pm
TASKLIST.EXE runs under alt credentials without password? December 13, 2005, 2:41 pm

The site map in XML format XML site map

Contact Us | Privacy Policy