To disable cached domain credential sign-in on shared lab laptops, configure the Windows security policy that controls cached logons:
- Open Group Policy Management and edit the GPO applied to the shared laptops.
- Go to:
Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > Security Options - Configure Interactive logon: Number of previous logons to cache (in case domain controller is not available).
- Set the value to 0 to turn off cached logon information.
Supported ranges in the documentation are:
- 0 to 50 cached logons
- 0 disables logon caching
- Default is typically 10 cached logons
Important impact:
- With caching disabled, users cannot sign in when a domain controller is unavailable.
- The expected message is: “The system cannot log you on now because the domain <DOMAIN_NAME> is not available.”
- If a domain controller is reachable and the user authenticates successfully, normal domain sign-in continues.
If the goal is specifically to reduce account lockouts, the documented guidance is to troubleshoot the source of repeated bad-password attempts first rather than only changing lockout behavior. In managed domain scenarios, changing lockout policy does not unlock accounts that are already locked.
References: