Microsoft KB Archive/818088

= You cannot log on to a computer that is using cached credentials after you change your password by using a domain controller =

Article ID: 818088

Article Last Modified on 10/30/2006

-

APPLIES TO


 * Microsoft Windows 2000 Professional Edition

-



SYMPTOMS
On a computer that you use to log on to a domain, you may be unable to log on to the computer when you are disconnected from the domain, even though in the past you could log on to the computer while disconnected from the domain.



CAUSE
This issue may occur if all of the following conditions are true (in the order presented):
 * 1) You successfully log on to the domain with the computer in question, either through a remote access, virtual private network (VPN), or network connection.
 * 2) You log on to the domain and are prompted to change your password.
 * 3) You have not successfully logged on to the domain through a remote access, VPN, or network connection since you changed your domain password.

When you successfully log on to a domain with a domain user account, your domain logon credentials are cached locally on your computer. If you then disconnect that computer from the network and log on, you are logged on with the cached credentials for the domain.

When you log on to the domain and are prompted to change your password, your cached domain logon credentials are not updated until you successfully log on to the domain with the new password. After you have successfully logged on to the domain with the new password, your cached domain credentials are updated, and you can then log on to the computer when you are disconnected from the domain.



RESOLUTION
To resolve this issue, you must use the network, remote access, or VPN to log on to the domain.

Therefore, connect the computer to the network, and then log on to the domain. Or, to use remote access or VPN to log on to the domain, follow these steps:
 * 1) Start your computer.
 * 2) On the logon screen, type your user name in the User name box.
 * 3) In the Password box, type your domain password.
 * 4) In the Log on to list, click the name of the domain.
 * 5) Click to select the Logon using dial-up connection check box, and then click OK.
 * 6) In the Choose a network connection list, click the dial-up or VPN connection that you want to use, and then click Connect.

Note There are no tools or utilities from Microsoft to update cached credentials. This is by design. Only cached validated domain logons are stored as cached credentials.



WORKAROUND
If you are using third-party VPN software that does not interface with Dial-Up Networking, you may not be able to access your domain when you click to select the Logon using dial-up connection check box, and therefore you cannot update your cached domain credentials. To work around this issue, create a local account on the computer. Use the local account to log on locally, and then make a VPN connection to the domain.

To create a local account, follow these steps:
 * 1) Log on to the computer as Administrator.
 * 2) Click Start, point to Settings, and then click Control Panel.
 * 3) Double-click Users and Passwords.
 * 4) Click Add, in the User name box, type a user name, and then click Next.
 * 5) In the Password box, type a password, type the same password in the Confirm password box, and then click Next.
 * 6) Under What level of access do you want to grant this user, click to select Standard user, Restricted user, or Other. If you select Other, select the type of account that you want in the Other list.
 * 7) Click Finish.

To log on locally with the new local account, follow these steps:
 * 1) On the logon screen, type the name of the local user account that you created earlier in the &quot;Workaround&quot; section of this article in the User name box.
 * 2) In the Password box, type the password for the user account.
 * 3) In the Log on to list, click the name of the computer, and then click OK.



MORE INFORMATION
For more information about how to set up a remote access connection, see the &quot;Network and Dial-Up Connections&quot; topic in the Windows 2000 Help files.

Additional query words: logon RAS

Keywords: kbprb KB818088

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.