Domain Account Lockouts on Shared Lab Laptops

Fredle Coper 20 Reputation points
2026-09-30T15:46:19.6633333+00:00

No recent GPO changes.

No issues with Active Directory authentication.

Multiple users are logging into shared lab laptops and encountering unexpected account lockouts. The behavior appears to be related to cached domain credentials in the background, where previously stored credentials continue attempting authentication after user switches.

Looking for guidance on disabling domain credential caching through Group Policy to prevent these account lockouts on shared devices.

Windows for business | Windows Server | Devices and deployment | Configure application groups
0 comments No comments

2 answers

Sort by: Most helpful
  1. Domic Vo 34,165 Reputation points Independent Advisor
    2026-09-30T16:17:53.4366667+00:00

    Hello,

    Verify first that the VPN gateway is sending RADIUS Access-Request packets to the RADIUS server on UDP 1812. Run packet captures on both the VPN appliance and the RADIUS server to determine where the traffic stops.

    If requests leave the VPN gateway but never reach the RADIUS server, review firewall rules, NAT policies, and deny logs for UDP 1812. If you use Microsoft NPS, check Event Viewer under Applications and Services Logs\Microsoft\Windows\NetworkPolicyandAccessServices.

    If no NPS events appear during authentication attempts, the requests are being blocked before reaching the server. If NPS receives the request but rejects it, verify the RADIUS client configuration, source IP address, and shared secret.

    The quickest way to isolate the problem is to trace the Access-Request and confirm whether the Access-Accept or Access-Reject response successfully returns to the VPN gateway. This will identify the exact point where authentication traffic is being dropped.

    I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!

    DV.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-09-30T15:46:30.2133333+00:00

    To disable cached domain credential sign-in on shared lab laptops, configure the Windows security policy that controls cached logons:

    1. Open Group Policy Management and edit the GPO applied to the shared laptops.
    2. Go to: Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options
    3. Configure Interactive logon: Number of previous logons to cache (in case domain controller is not available).
    4. Set the value to 0 to turn off cached logon information.

    Supported ranges in the documentation are:

    • 0 to 50 cached logons
    • 0 disables logon caching
    • Default is typically 10 cached logons

    Important impact:

    • With caching disabled, users cannot sign in when a domain controller is unavailable.
    • The expected message is: “The system cannot log you on now because the domain <DOMAIN_NAME> is not available.”
    • If a domain controller is reachable and the user authenticates successfully, normal domain sign-in continues.

    If the goal is specifically to reduce account lockouts, the documented guidance is to troubleshoot the source of repeated bad-password attempts first rather than only changing lockout behavior. In managed domain scenarios, changing lockout policy does not unlock accounts that are already locked.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.