- Fri, Apr 3 2020 at 3:28 pm #1555663Stephen BoydParticipantMember Points: 187Rank: 2
As with staff from most companies mine took their laptops home. We did not have too much time to prepare so missed a few things, like;
- How AD and Windows 10 profile passwords will be kept in sync
- How apps like Office and possibly even windows will communicate with KMS
- How Windows computer accounts will stay current
The laptops are all Windows and are domain joined and staff use domain profiles. KMS is on the DC’s.
We thankfully have Cisco AnyConnect on the computers but I don’t know how to set it up / the firewall to deal with the above 3 points. I also don’t want to give full and unfetted access to the Domain Controllers from the laptops.
Can someone please offer me some suggestions. I’m guessing others will be in the same boat?
- Sat, Apr 4 2020 at 2:42 am #1555664Leos MarekModeratorMember Points: 23,212Rank: 4
if you have a VPN up and running, you should be all good in all points.
How AD and Windows 10 profile passwords will be kept in sync?
remotely it works like this:
- User is notified about password will expire soon
- User has to be on VPN and then he changes the password normally
- After the change, he HAS to lock his computer (Win+L)
- Unlock the computer with new password
Thats it. The important steps are 3 and 4. If this is not done, there can be a situation when user has to unlock computer with old password and then join VPN with new password, which usually ends with some troubles and possible locking the user out of his PC completely.
How apps like Office and possibly even windows will communicate with KMS
On VPN, no problem. Even without VPN there is like 30 days or so when the apps stay activated (not sure about the number of days). Then user gets notification upon Office start that it needs to be reactivated.
How Windows computer accounts will stay current
The password change is initiated by the computer, not by AD. If AD is not available, the change will not occur. You should be all good there too.
Hope that helps
- You must be logged in to reply to this topic.