Title: Message
So let me get this straight - your 'security' people are asking you to make your systems less secure?
 
I would think increasing the number of cached logins decreases the security of the system. IIRC, cached logins are reset basically whenever the system comes 'online' - in other words has access to a DC. Therefore, the more you cache the longer you're allowing the sytem to live autonomously, without getting policy updates, etc.
 
Roger
--------------------------------------------------------------
Roger D. Seielstad - MTS MCSE MS-MVP
Sr. Systems Administrator
Inovis Inc.
-----Original Message-----
From: De Schepper Marc [mailto:[EMAIL PROTECTED]
Sent: Friday, August 22, 2003 7:41 AM
To: [EMAIL PROTECTED]
Subject: [ActiveDir] Number of Interactive Logons

Hey all,
 
I would like to have some feedback of the following Policy setting:
 
Interactive logon: Number of previous logons to cache (in case domain controller is not available)
 
 
The default is 10, but our Security people would like to put it on 50.
 
Does anyone have some arguments not to use 50?
 
Marc 

*************************************************************

Dit e-mail bericht inclusief eventuele ingesloten bestanden kan informatie bevatten die vertrouwelijk is en/of beschermd door intellectuele eigendomsrechten. Dit bericht is uitsluitend bestemd voor de geadresseerde(n). Elk gebruik van de informatie vervat in dit bericht (waaronder de volledige of gedeeltelijke reproductie of verspreiding onder elke vorm) door andere personen dan de geadresseerde(n) is verboden. Indien u dit bericht per vergissing heeft ontvangen, gelieve de afzender hiervan te verwittigen en dit bericht te verwijderen.

This e-mail and any attachment thereto may contain information which is confidential and/or protected by intellectual property rights and are intended for the sole use of the addressees. Any use of the information contained herein (including but not limited to total or partial reproduction or distribution in any form) by other persons than the addressees is prohibited. If you have received this e-mail in error, please notify the sender and delete its contents.

*************************************************************

Reply via email to