User Account Bad Password Attempt - Workstation Lost Trust Relationship


i can't find definitive answer i'm hoping forum can assist.

senario: workstion cannot authenticate domain (i.e. password out of sync), , user tries log on domain using workstation and recieves message "trust relationship between workstation , primary domain failed".

my question still count bad password attempt in domain user account?

thank you.

hello,

once domain user has logged on machine domain user account password cached, in case of problems user can still log on machine, that's default.

but behavior can changed, if machine not connected domain, cached credentials not used.

therefore gpo can used: http://technet.microsoft.com/en-us/library/cc755473(v=ws.10).aspx use setting "0" prevent cached logons.

if dc isn't available account cannot locked out during authentication, if default settings used can still work locally.


best regards

meinolf weber

mvp, mcp, mcts

microsoft mvp - directory services

my blog: http://blogs.msmvps.com/mweber

disclaimer: posting provided no warranties or guarantees , confers no rights.

twitter:  




Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group