Active Directory General Question

Support, Discussion, Reviews
Post Reply
User avatar
Dups.
Almost 1337
Almost 1337
Posts: 580
Joined: July 22, 2002, 9:19 pm

Active Directory General Question

Post by Dups. »

Ok, so let's say I am using windows 2000 and I lock my computer via CAD.

I forget my password. I ask the network admin to reset my password. He does so.

I end up remembering my password so I simply type it in and unlock my workstation because I am still using the local copy of my username and password.

Now, the local copy and network copy of my username and password are different.


At which point do the two scynchronize?
Does it happen the next time I try to access something on the network?


If this is not clear lemme know and I will try to clarify. Thanks.
I have no sense of decency. This way , all my other senses are enhanced!
User avatar
Zaelath
Way too much time!
Way too much time!
Posts: 4621
Joined: April 11, 2003, 5:53 am
Location: Canberra

Post by Zaelath »

They don't synch as such. In fact, you'll find various things get rather pissed off about the situation ;)

The equation is obfuscated further if you have BDCs and it's even worse if you have a WAN. Most domain controllers will propagate password changes between themselves instantly on a LAN, but if you're part of a WAN you might find there's a lag (I've seen 20-30 mins). It's purely a discretionary call as to how much SAM synch traffic you want on your WAN.

The other thing to remember is if you're on a 2000 network you're not even passing your logon info around to the server, you're giving it a kerberos ticket.. which also has an expiry time.

Regardless, in the situation you're best to log off and reboot (as that will make the machine check the domain controller version of your password before resorting to the cached copy).
User avatar
Fallanthas
Way too much time!
Way too much time!
Posts: 1525
Joined: July 17, 2002, 1:11 pm

Post by Fallanthas »

Depends on whether your system admin was smart enough to set AD not to accept changes from local profiles or not.


AD can be a bitch. Sometimes it's like trying to put together a jigsaw puzzle without fingers.
User avatar
Bubba Grizz
Super Poster!
Super Poster!
Posts: 6121
Joined: July 3, 2002, 12:52 pm
Gender: Male
Location: Green Bay, Wisconsin

Post by Bubba Grizz »

Normally we change the password and force them to change on relogging. Usually they are stuck at the login screen anyhow otherwise we tell them to reboot. Sometimes they have to wait for about 15 minutes for the change to take effect but mostly it is almost instant. If it is a lock out then it is easy enough to unlock them. The pain in the ass comes when you are using both Active Directory and User Manager.
Post Reply