Maintain access to network(shared folders) resources if the site loses access to a Domain Controller?

Scenario
Windows 7 users log on to workstations at a site. Domain Controller is up and does the domain authentication for those users across the WAN. Users are then accessing a local(same building) Shared directory on a Windows 2008r2 server, in order to open, modify,
save new files, etc.
Then, the site loses access to the Domain Controller due to a WAN outage.
Question
Will those users that have already logged onto their Windows 7 workstations continue to have access to the shared resources on the local Windows 2008r2 server with their cached credentials(assuming they don't logoff or restart their machines)?? This has
been the case in the past, but wondering if anything has changed with Windows 2008??
Thanks

Hi,
The duration that you can access the server depends on when the server requires re-authentication.
In Windows implementation, SMB session expiration is enforced based upon the client’s support of dynamic re-authentication capability [MS-SMB].
If the client enables the CAP_DYNAMIC_REAUTH capability bit, the server will enforce session expiration. If a client does not set CAP_DYNAMIC_REAUTH, the Windows server does not return STATUS_NETWORK_SESSION_EXPIRED. 
The SMB dynamic re-authentication feature was introduced in Windows XP. From there, Windows-based clients set the CAP_DYNAMIC_REAUTH capability bit to indicate to the server that the client supports re-authentication when the Kerberos service ticket for
the session expires.
Windows servers do check CAP_DYNAMIC_REAUTH:
If clientCapabilities sets CAP_DYNAMIC_REAUTH, the server will set Server. Session.AuthenticationExpirationTime to the expiry time returned by AcceptSecuirtyContext.
If clientCapabilities does not set CAP_DYNAMIC_REAUTH, the server will not set Server. Session.AuthenticationExpirationTime, basically a CAP_DYNAMIC_REAUTH capability bit not set by the client means the session will not expire on the server side.
To configure Maximum lifetime for service ticket, you can use grouppolicy. The default value of
Maximum lifetime for service ticket
in Default Domain Policy is 600 minutes.
Note:This setting is applied to DC, not clients.
For detailed information, please view the link below
CIFS and SMB Timeouts in Windows
http://blogs.msdn.com/b/openspecification/archive/2013/03/19/cifs-and-smb-timeouts-in-windows.aspx
Maximum lifetime for service ticket
http://technet.microsoft.com/en-us/library/jj852188.aspx
Hope this helps.
Steven Lee
TechNet Community Support

Similar Messages

  • How do the User and Shared Folders relate to the main drive? Can we delete?

    I'm curious how the User and Shared folders relate to the main hard drive and if there is duplicate files in these folders and the main hard drive. Some software programs I have seemed to have loaded content/info into these folders and I'm wondering why they put files in there instead of just the regular main hard drive pathing. These 2 folders are more confusing than anything. I can see that might be of use to a family and each family member wants to keep files in a personal file, but when I'm the only one using my computer, it seems like I should have the option to remove these folders completely, but I don't because I feel like I would be deleting some important files that I wasn't aware were in these folders.
    Another thing is, when I click on User folders (at least I think it's the User and not Shared folder), it brings up my name and 'Shared' in 2 seperate subfolders. Is anything in these folders duplicates of what's on my main hard drive? Is there anything significant about these folders if I'm the only user on my computer?
    I would nice to get rid of clutter and to eliminate options for software to install things by deleting these folders and not have home/user/shared folders. Is that possible?

    stikygum wrote:
    Yeah, I'm really low on space, so I'm going about a bunch of different consolidating options. But I mainly posted my main question to help me understand what 'stuff' is in the User and Shared folders and whether or not they act like an Alias, in order to help me make an informed decision what is best for my needs.
    They are not aliases; it is a hierarchy, and there is intentional duplication at different levels. This is a feature.
    First thing is that Users and Shared are at different levels. Users is at the top level, but Shared is one level inside Users, at the same level as any other user account you have created.
    Therefore, if you delete the Users folder, you delete all user accounts, which means you delete all personal data. OS X probably won't even let you delete the Users folder unless you start up from a different hard drive, because you can't delete your user account while you are running in it.
    Now, more about the hierarchy. The intentional duplication is so that documents and software can exist for individual users or all users. For example, there are multiple Applications folders:
    Hard Drive\Applications - applications any user can see, installed at the system level
    Hard Drive\Users\username1\Applications = applications only that user can see
    Hard Drive\Users\username2\Applications = applications only that user can see
    In the same way, there are multiple Preferences, Cookies, Application Support, etc. folders at different levels, for the same reasons.
    If you do not know what you are doing and you delete one of these folders that "looks like a duplicate" you could cripple some essential part of your system or your account. That is why people are telling you not to do this.
    The Shared folder is there because if you are in one user account you are prevented from seeing the files inside other user accounts. (Because you don't want other accounts to be able to see your personal data.) If you want to share files with others in your house using the same Mac, that's a problem. But the Shared folder solves this. if you want some files to be accessible to all users, like some photos or music, just put them in the Shared folder and now anyone with an account on that computer can see those shared files.
    The reason shared files are not simply stored at the top level is because everything above the Users folder is supposed to be reserved for the system. User-specific are supposed to stay in the Users folder. That is why they put the Shared folder in there.
    If you are not using the Shared folder and are just eyeing it because you want to free up some disk space, well, it probably won't help to delete it. Because if you are not using the Shared folder, it is probably not taking up much space, even though you see stuff in there. And if there is stuff in there taking up space, first figure out if someone put it there for a reason before you delete it.

  • To rename a page or folder In either the Folder List panel or the Folders view of the site, right-click the file or folder, and then click Rename. Type the new name.

    I set out to change the page name ready to publish on my hosts server after Having used a temp. name, simple so the " Expression web user guide says" I have not been able to find the "Folder List panel" of The folders view of the site,
    I have just completed an hour methodically searching for the two files listed, I would be most grateful for some simple instructions on how to find the entities listed in the Title above, which I cut and pasted to make sure that I got it right.
    Regards, 
    Robert
    Robert 1000

    If you are in the standard configuration, click "Site|Open Site," then browse to and open your site. With an open site, you will see a tab at the top labeled "Site View." Another tab at the bottom will be labeled "Folders,"
    because you are then in Folders view of the site (recognize that terminology?). At the same time, unless you have your panels hidden, in the upper left side you will see a panel labeled "Folders List." If you do not see this panel, click "Panels|Reset
    Current Workspace."
    cheers,
    scott
    Please remember to "Mark as Answer" the responses that resolved your issue. It is common courtesy to recognize those who have helped you, and it also makes it easier for visitors to find the resolution later.

  • Accessing Network Shared Folders using Wifi from E...

    I have a few computers with shared folders in the network the E72 is connected to. How can I access these folders from my mobile phone ? 

    hi,
    i already tried using Process, Runtime........ using "net view command" and parsing its OutputStream for results. Its fine and working in windows. Using that makes my program dependent to Windows...
    The program detects what OS the JVM is running on. I could make an if-else statement and add another set of command for linux(samba scripts). But doing this make things complicated.
    Is there any other way to this, like a Standard way. Like using sockets and ports and using only java native API?
    thanks,
    valcaro

  • Network shared folders appear as 'sharepoint'

    Hello
    I have 1 iMac and 2 windows 7 computers on my local small office network.
    From the Mac I can see and access all shares on one PC, on the other, when I access via finder, the shared folders appear as 'sharepoint' and I cannot see any sub folders. I have checked settings on both PCs in the network centre and they seem identical.
    Thanks if you can help. Regards

    Hi, just an update...some of the problem is related to extensions. Some files have explicit extensions and others not. When I change the file extensions to an explicit extension (eg .pdf) then the file is fine.
    However, there are no extensions on folders or folder aliases.
    I've tried using chmod -x + file location/file name but that makes no difference to the alias, meaning that the Snow Leopard does not recognize the item as a short cut to another folder. Snow Leopard will only recognize the item as an alias if it's been created on a workstation running Snow Leopard OS. Very odd.
    Phil

  • How do I watch Network Shared Folders in Organizer?

    I must be able to watch shared folders on a network share in organizer.
    Is there any way to be able to do this????
    I'm using Photoshop/Premiere Elements 12.
    Is this functionality present, or any easier, etc. if I upgrade to 13?
    For Example: One problem that comes up is, if you're able to bring up the network places, and choose the share you want, getting the error "The watch folder service returned an error: The user name or password is incorrect."
    I've investigated this before, spent some time, couldn't get this to work after some internet searching. I'm now re-visiting this trying to get it to work.
    Thanks!

    Here is the resource I find on the subject:
    Photoshop Elements 6/7/8 Frequently Asked Questions (FAQ)
    [Note, how this is a problem back with PE 6.. I had PE 6... quit using it because of this same EXACT problem. I'd think that Adobe would fix this problem by 6 (or 7) versions later?!]
    I tried changing the logon for the service the last time I worked on this and for some reason it didn't work. For whatever reason, I didn't get any errors this time.
    I think my problem is, "watching" a folder isn't doing what I would have expected it to do. I'm expecting to choose a watched folder and then it will automatically populate my entire library (and then automatically update that as I add/delete/change files/folders). But I choose the watched folder, click the 'auto-something' (can't remember what it says) option, and then... nothing...

  • So slow listing network shared folders and drives.

    Hi!!
    I'm reporting a very slow connection between my MacBook Pro 13" (snow leopard) and my MacPro 8 core (leopard). When I try to reach the macpro in finder (shared) passed 1 or 2 minutes until the system ask me user/pass, then show me the list of my shared folders and drives. Navigating through them is ok, ut when I return to the main list, SnowLeopard again waits 1 minutes or 2 to show. Before, the main list always remain there.
    Any help??

    Same sort of problem here. Screen Sharing also doesn't work.
    Pretty sure it's DNS, as if I temporarily remove my router from the equation (by, say, using a manual IP address instead of DHCP on the machines and leaving DNS blank) everything works and is instant - except of course for the internet. Put it back to DHCP (which uses the router for DNS) and it's slow again (and screen sharing doesn't work at all).
    However, OpenDNS hasn't helped (probably because it's a private address range?)
    The network is 192.168.0.0/24 with gateway and DNS server 192.168.0.1, which is a Draytek Vigor 2600G ADSL router.
    This has only happened recently, I guess Snow Leopard or one of its updates has forced reverse DNS lookups for everything.
    As I understand it, AFP is supposed to use Bonjour for hostnames ending in .local and bypass DNS altogether, but despite checking that they end in .local (an automatic thing) in System Preferences it doesn't seem to do this any more.
    Any way to turn off these reverse DNS lookups?

  • Can't see my network shared folders(on PCs)

    I have a home network with D-Link router with 3 other computers (2 WinXP and a Vista). The computers are all on the same subnet 192.168.0.10X and all use DHCP from the Router.
    The Macbook is getting an IP from the router but it doesn't see the other computers in the Finder. and when I go to the Network utility an ping to the other computers or even to the router it doesn't receive any packets back.
    I have no Idea what to do. I would really appriciate help in the matter

    Activate your iCloud email address, then copy the folders and content from the Hotmail account to the iCloud account, do them one at a time and ensure that each one is completely copied before starting the next. This will take time as you are moving the mail across the internet.

  • Share folders, browse network / shared folders, m...

    On my computer shared drives and folders. But in the Nokia N8 no function to view them. I also can not see the shared  files and folders on phone from PC. For s^1 phones was a program SymNC It allows listen music and video directly on phone from computer. Copy, delete and move files and folders shared  on computer from the phone, and vice versa.
    Unfortunately SymNC not compatible with Nokia n8
    http://www.telexy.com/Products/ProductInfo.aspx
    http://betalabs.nokia.com/apps/nokia-play-to/suggestion/38193/share-drives-and-folders-browse-networ...
    This function is primarily to Android, iOS and wp, but it is not available in symbian 

    Pages ’08 and Pages v5+ documents are special Package bundle file objects. When they reside on the Mac, they appear in Finder as ordinary files. When they reside on external storage, they will appear as directories. Pages ’09 documents also appear as regular files, but are in fact a compressed zip of a folder.
    Your Mac server is likely running an older version of OS X than Maverick, and does not understand the exclusive new Pages v5 document format, or its proper presentation to end users, as would Mavericks.
    Choices:
    Export all Pages v5 documents to Pages ’09 v4.3 document format.Resume use /Applications/iWork ’09/Pages
    Before saving Pages v5 documents to server, compress them first.
    Right-click on the .pages document on your machine, then select Compress menu item.
    Creates foo.pages.zip which appears on remote server as this name
    Upgrade OS X Server to Mavericks Server
    Despite its progressive version number, Pages v5+ lacks substantial functionality from its Pages ’09 v4.3 antecedent, including an entire incompatible document format with other versions of Pages. You should consider it early beta software, and not a viable production release (as Apple marketing would have you believe).

  • Local Networking - Sharing Folders, Bonjour iChat, Screen Sharing...

    Hello and Good Day
    I have posted the link to a question that I have asked as I think they are related and I am not sure where to post.
    http://discussions.apple.com/message.jspa?messageID=8847797#8847797
    If you have any ideas... please let me know!
    Thank you
    Adam

    Hi
    First have you set the Quicktime streaming setting, goto sys prefs/quicktime/streaming/streaming speed, set to 1.5mbps
    In ichats prefs click on video and change bandwidth limit to none.
    Restart iChat.
    Tony

  • HT1549 Can anybody tell me how to enable shared folders regardless of the number of sub folders?

    Rather than having th "get info" and enable file sharing of every sub folder how can you enable file sharing in any depth ( number) of sub folders in one easy way? Any help appreciated.
    Best regards, BAGBOY1

    You will not find a serial number with the CD if the product is Educational version or Volume License ( Enterprise) version. For Educational version, you need to submit the Proof of Eligibility for the serial number. Contact Customer support for detail. For Volume License serial number, you need to login to the Adobe Licensing Website (LWS) then login using your email address that is used to place the order. If you do not have a password, you can create a new one from the login screen. Login to LWS and you can find the serial number there.

  • Was the network sharing feature removed from the latest version of iphoto?

    After upgrading to the latest version of iphoto (9.5.1) it seems I can no longer share my photo library to other computers on my home network.  Does anyone know if this feature was removed?  And if it was, is there a work around?  This feature is very useful to me.
    Thanks in advance...

    no i do not - there is an Aperture forum - give it a shot - I've not seen that posted here though
    LN

  • How to access to network shared folder from in-house web application mozilla firefox?

    We are trying to access network shared folder from our in-house application but its not possible. The reason we found was because of security model. Please can you provide solution for this issue.
    Incident Details for shared folder access issue
    Expected behaviour:
    Network shared folders should be opened via all versions of Internet Explorer from an in-house web application.
    Actual behaviour:
    Works fine in IE but not in Mozilla firefox. Refer snapshot.
    Server configuration:
    Web server: Apache
    Operating System: Windows Server 2008 R2
    Image uploaded:
    Network Shared Folder doesn’t open in Mozilla. Uploaded image is from IE it allows to access to network shared folder but not Mozilla.
    No warning or error message is shown.

    Hi,
    If its a shared folder on windows drive with access permission to all, you might get your work done using simple GUI_UPLOAD.
    Have you checked this. Just a thought.
    thnx,
    Ags.

  • Can not edit file on network shared folder after upgrading to windows 7

    Merry Christmas and happy new year,
    Due to some configuration changes on a specific application, I have forced to upgrade OS of a few number of workstations from Windows XP to windows 7. After upgrading I am facing a strange problem on WIN7 workstations. These workstation are member of a Windows
    2008 R2 Active Directory domain which also has a Windows 2003 advanced server additional domain controller. Also there are a number of shared folders on some member servers (all windows 2003) which are mapped as network drives at user logon. Before upgrading
    mentioned workstations to WIN7, users was able to edit his/her files on all of mapped network drive according to his/her permissions without any problem on their WINXP workstations, But after installing windows 7 they begin facing problem on one of these mapped
    network drives and the problem exactly is when they edit a file, in more specific word an excel file, and then try to save, the excel returns an error message of "document not saved" and exit the excel program. It becomes more strange when you learn
    that the edited excel file is disappeared and replace with some "tmp" file. If user copy the excel file to his/her own desktop, edit it and then copy it back to its original place on mapped network drive, it will be replaced normally with its older
    version. In other words if user wants to edit an excel file on that specific network drive, he/she must edits it somewhere else and then replace it on the network drive. If the same user uses a WINXP box, there will be no problem.
    Can anybody help me to fix the issue?
    TIA
    Bijan

    Thank you Karen,
    The problem is fixed, but my case was none of what you suggested. In fact I have
    another problem which I described in another question and it was of the root of this excel file issue. I describe what I have done to fix the latter problem hope to help fixing similar issues to mine.
    Okay, as it is described in the
    question, I was not able to open a shared folder with its UNC address while it could be mapped as a network drive without any problem. I examined what I was replied and some other ways, came to no result. I decided investigate a similar shared folder in
    permissions to problematic one to see if the problem is repeated. So I created a folder and shared it with similar permissions and examined it. Surprisingly there was no problem. It was wise to remove sharing of the problematic folder and share it again to
    see if the problem resist. But when I tried to remove sharing I received an error message saying that
    the shared folder is related to a DFS root. When I took a look at the DFS roots of domain there was no sign of the problematic folder (that made me recall that I created a DFS root with problematic folder mistakenly and removed that DFS root).
    After little searching, I found out that the problem could be caused by traces of the removed DFS root. Yep! I found the suspect! The registry key
    HKLM\Software\Microsoft\DFS\Domain\problematic shared folder. I removed the key restarted DFS service and log off and on and Bingo!
    This problem pops up a few more questions:
    1) Why is not the registry key related to removed DFS root deleted from the registry of windows 2003 server?
    2) Why was I able to browse this ex-DFS root shared folder without any problem in windows XP while it was problematic in windows 7?
    3) As there is no special client service for DFS and user can access DFS root targets like other shared folders what is the deference between shared resource access mechanisms in windows XP and windows 7 that caused the problem?
    Bests,
    Bijan

  • Can I set new shared folders to inherit permissions from the parent folder?

    Am running file sharing on an OS 10.9.5 machine.  This is not an OS-X Server.
    9 users connect to this machine.  They create folders and store files on it.  All the users who connect are in a group which has read and write permissions on the volume in which they store files.  But when they create new folders, the permissions on the new folder is 755.  I have changed the umask to 002 and this works for users who might create a folder locally but does not work for network connected users.  All users are AFP and, if it matters, are on 10.8.5.  The OS versions are held back for good reason.
    Is there a way to enable Inherited Permissions for new network created folders on the standard client OS?
    If not, can I do so on the server OS?  I have several older OS-X Server machines where this is a possibility.
    (Sorry if this is a duplicate but most posts like this seem to concern locally created files and folders and not network shared folders.)

    It can be done more easily with OS X Server, but you can do it anyway if you're familiar with the shell. See the section headed "ACL MANIPULATION OPTIONS" in the chmod(1) man page.

Maybe you are looking for