----- Original Message -----
> From: "Edward Ned Harvey" <[email protected]>
> To: "Ryan Frantz" <[email protected]>, "LOPSA Discuss List" 
> <[email protected]>
> Sent: Wednesday, March 28, 2012 9:09:23 AM
> Subject: RE: [lopsa-discuss] Managing Telecommuter Laptops: Windows Password 
> Resets
> > From: [email protected] [mailto:discuss-
> > [email protected]] On Behalf Of Ryan Frantz
> 
> Assuming the user is able to get on a wired internet, or you have the
> wifi driver that allows them to join wifi before windows logon... You
> can remote control their computer, login as yourself (or a local admin
> account) connect the VPN, and cache the user credentials. (The way I
> like to cache the credentials is to use "Run As" on a shortcut to
> CMD.) After that, the user will be able to login as themselves.

We've tested a scenario using a dedicated, cached "recovery" account (with 
restricted privileges) on the laptops.  That account information can be shared 
with the telecommuter to get logged in, automatically start the VPN connection, 
and take corrective action from there.

> 
> You also might consider a VPN software that's able to connect before
> windows logon.
> 
> One thing is certain:
> 
> You either need some other account credentials (such as yourself or a
> local admin user account) or you need the ability to connect VPN
> without login. There's no other way.

I've always wanted to do this with remote Windows systems.  I'm going to 
research creating a custom service that starts at boot time as I think it's a 
more elegant (as in, less effort on behalf of the user, in the end) solution 
and may offer additional management capabilities for me.

> 
> Well, there's one other way. The user must carry the laptop to some
> place where you have a company internal network connection.

For some reason, I'm picturing Neo and Trinity huddled inside a phone booth...

Ryan
_______________________________________________
Discuss mailing list
[email protected]
https://lists.lopsa.org/cgi-bin/mailman/listinfo/discuss
This list provided by the League of Professional System Administrators
 http://lopsa.org/

Reply via email to