Share via

Cached domain user

Simas Marcinkevičius 0 Reputation points
2024-01-03T09:39:50.7233333+00:00

Hello,

We are currently facing an issue: we had a domain user with admin privileges, let's say "username123." This user account was disabled a few months ago. On all computers, the path C:/Users/username123 was changed to C:/Users/username123_old, and the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList was also modified.

A few days ago, we attempted to log in to one of the computers using the disabled user account (username123), and the login was successful. I suspect that the username and password were cached in the system: HKEY_LOCAL_MACHINE\Security\Cache.

Since the user was disabled, this computer has been connected to our office LAN multiple times (maintaining a connection to the domain controller). The question is, how can I ensure that this user cannot be used on any of our computers, and how was it possible for the login to succeed despite the user being disabled?

OG question: https://answers.microsoft.com/en-us/windows/forum/windows_10-security/cached-domain-user/6018723a-c5d7-4239-a97f-f2c9cf0b7a25

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Client for IT Pros | User experience | Other
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Anonymous
    2024-01-05T03:20:48.21+00:00

    Hello Simas Marcinkevičius,

    Thank you for posting in Q&A forum.

    In my test lab, I can logon the machine.

    And after I disable one AD user account, I cannot logon immediately and received the error message below.
    User's image

    It seems your machine is not connected to domain.

    Or maybe AD replication between all Domain Controllers is not working properly. I mean maybe the user account you are using is not disabled in all DCs.

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

    Best Regards,

    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

  2. Thameur-BOURBITA 36,506 Reputation points Moderator
    2024-01-03T11:12:37.6466667+00:00

    Hi @Simas Marcinkevičius

    The cache is used when the computer is disconnected the user login.

    If the user is disabled and the computer is disconnected during the user login , he will be able to login

    Are you sure that the computer is connected to domain controller before you try login with user 123 account ?


    Please don't forget to accept helpful answer


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.