Vista + VPN = Locked Domain Account

Here’s a fun little feature with Microsoft Vista. All you need is a Vista machine and a VPN connection. If you get lucky, it’ll be an easy and instant way to repeatedly lockout your domain account!

First, from your Vista machine create a VPN connection to a non windows-authenticated VPN — for instance, at the office we use a Cisco appliance with non-domain username/password. Connect to it with your Vista machine. At first, things may seem fine. But at some point, you’ll find that every time you connect to the VPN, your domain account gets locked out!

Here’s what I know so far:

  1. It only happens to folks establishing the VPN connection from a Vista machine
    1. Doesn’t happen to folks running XP (seems obvious, but I’ll state it)
  2. Everything is fine initially with no lockout issues. I’m not sure when the trouble begins, but it seems to be one of the following:
    1. We changed our Active Directory domain passwords
    2. A recent windowsupdate within the past few weeks

Unfortunately, the two “possibles” pretty much coincide as far as timing goes, so I’m not sure which, but my gut tells me it’s the first one and related to caching passwords somewhere.

We don’t cache our VPN passwords. We don’t use offline folders (to my knowledge) which I believe do cache.

If not careful, I can repeatedly lock my account out every time I try and access a file share. The only cure I know is to do the following after the initial VPN connection:

  1. Go to the Control Panel
  2. Click on “User Accounts”
  3. Click on “User Accounts” again (on the next screen)
  4. Click on “Manage Your Network Passwords” under Tasks in the left sidebar.
  5. Select “<dialup session>” and click “Remove”

After following those steps, [and] once I get my domain account unlocked, it’ll stay unlocked. Fortunately, I’m the domain admin so I can just remote in and fix it, but geeze… Every time I connect to the VPN, it stores a new <dialup session> that I have to remember to go delete. Maddening!

More and more folks are getting Vista machines at home. I really don’t want to teach everyone at the office that 5 step dance from above followed by “then call Chris to reset your account”. That would suck.

Thus far, my web searches have been fruitless. If anyone has found a working fix to this, I’m all ears!

Possibly Related posts:

  1. Vista VPN / Firefox / More
  2. Vista Thoughts
  3. So You Lost Your Vista Password?
  4. Windows VPN tweak: Don’t use Remote’s Gateway
  5. Remote Desktop: No Console from Vista?


6 comments to Vista + VPN = Locked Domain Account

Leave a Reply

 

 

 

You can use these HTML tags

<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>