General discussion
March 31, 2003 at 04:41 AM
eclipse860

Force LSA Update with Cached Credentials

by eclipse860 . Updated 23 years, 6 months ago

I have a Windows 2000 AD Domain. I have several laptops I have configured for field use. I used a RIS image to deploy OS. I have these machines locked down via Group Policy. I configured AT&T VPN software to connect into work. These laptops will never be plugged directly into the network again.

The only way to access my domain is through the VPN client. The user MUST logon to the system (with cached credentials) to use the dialer. The dialer will not work through the “Log on using dialup connection” option in the XP logon window.

My Question…

Is there ANY way to update the users Security IDs. In other words, is there any way to let the user know it is a member of a newly created group or to remove them from a group that the cached credentials currently beleives they are in. Maybe some way to force the LSA process to run.

My issue here is that not only can I NOT apply new GPOs (including logon scripts) but I also cannot change group membership.

Bottom line.. I have created a group in Active Directory called “Local Administrators”. I assigned this group to the laptops local Administrators group. This was done so that we could temporarily elevate privledges. My problem now is that they are full admins on the laptops and unless I have all the users send the laptops back to me to be plugged into the network, I cannot remove them from the admins group.

Any ideas as to what I can do?

This discussion is locked

All Comments