Can RODC PRP autheticate and cache whoever is logging into that specific sites&services location??
i'd prp our 3 branch sites cache whomever works @ site automatically based on fact logging subnet allocated sites/services support individual rodcs. possible? example bob works out of branch , machine , user account cached in branch a's prp. when bob travels branch b 3 weeks, branch b cache machine , user account in it's prp because logging new site/subnet. after bob leaves branch b, rodc there configured remove account automatically after 3 days of no logins bob @ site.
it seams possible based on lifecycle blog post read, don't know how implemented.
i'm trying avoid creating shadow groups 45 rodcs have deploy our branch sites. help.
it’s possible developing custom applications can scheduled run periodically.
1. develop , deploy logon script records logon information, including user account, time, , sites, database or kind of storage.
2. develop , schedule application enumerate users , corresponding logon information recorded in database. based on logon information , cached password clearance policy, application can clear cached password stored in rodc.
however, need intensive development work , costs much. if develp appliation, it’s suggested submit new post in msdn forum more suggestions. best resource kind of problem.
msdn forum
http://social.msdn.microsoft.com/forums/en-us/categories/
thanks.
this posting provided "as is" no warranties, , confers no rights. please remember click "mark answer" on post helps you, , click "unmark answer" if marked post not answer question. can beneficial other community members reading thread.
Windows Server > Directory Services
Comments
Post a Comment