Domain – prepare a domain user account without the user’s password

domainuser-accountswindows-8.1

We have a 2012R2 domain and have configured many GPO settings for our users based on the team they are working for. In the near future, we will replace our existing laptops with new ones and move to Windows 8.1 Enterprise.

Our problem is that several of our users are abroad and not working on a company network (e.g., working from home). We want to ship their new laptops such that they can simply unbox it and start with it immediately using their (existing) domain credentials.

However, as they are not on the company network, their laptops cannot connect to the Active Directory when they try to log on the first time. They will get the "no logon servers available" if the user's domain account isn't known/cached on that laptop…

Setting up a VPN connection before log on is also not feasible in our scenario as the laptop will need an active network connection before log on, but a WiFi connection can only be set AFTER log on as far as I know. A wired network is not a possibility for most of our users…

Currently, we asked for the user's password (I know…), we use it to log on to the laptop when it's still on the corporate network such that the GPO's and other settings would apply. Next, we shutdown the laptop and ship it to the user and he can work with it immediately using that password as the user domain account has been created and cached on the laptop (no longer needing to contact the AD).

However, for obvious reason we no longer want to ask the user his password.

Is there a way we can create the user's domain account on the laptop and apply all GPO settings and cache the domain credentials without actually logging on to the computer as that specific user? (In such a way, that the user is able to log with his domain credentials even if the laptop is completely offline).

regards

Best Answer

If you use a public VPN (VPN with checkbox for all users) you can connect to a VPN server at logon time. When you select this option, you will also be able to establish a WiFi connection. This really is the way to go for this kind of scenario.