Do Active Directory accounts ever expire

active-directorywindows 7windows-server-2008-r2

Business has issued Windows 7 laptops to users who are out in the field for long periods of time where the domain controller is not accessible. There may even be some users who never connect to the domain again since the day their laptop was issued. Would their Active Directory accounts ever expire?

There is an app in development that may require periodic reconnecting to the AD again but I am concerned is it possible AD credentials can expire?

Best Answer

User/computer passwords CAN expire, cached credentials - No (they will remain indefinitely, it doesn't matter at all if the user or computer account passwords are beyond their expiry date, as long as the credentials have been cached once, and there is no connection to a domain controller, they will never expire).

How long does Windows cache domain user passwords?

If you mean whether AD account can become disabled at some point of time in future automatically - the answer is NO, only due to some conditions listed here.