Changing user domain password from computer outside of Corporate network without VPN

S

SecJedi

While outside of the office and connected to the corporate VPN, I can use Ctrl-Alt-Del to change my password without issue. This appears to store a hash of my password on my laptop and I can later log into the laptop with the new password without first connecting to the VPN. Below is a small snippet from the command "dsregcmd /status"AzureAdJoined : YESEnterpriseJoined : NODomainJoined : YESGiven the above "AzureAdJoined" being "YES". Should a user, who is not connected to our corporate VPN be able to use "Ctrl-Alt-Del" to reset their password and have the hash written to the laptop? This use

Continue reading...
 
Back
Top Bottom