Consider the following scenario in a domain environment:
Note This issue does not occur when you log on to the client computer by using smart card credentials.
The following is the detailed scenario table:
- You enable the Lock Workstation Group Policy setting for the Interactive: Smart Card Removal Policy in the domain.
Note In this case, any client computers in the domain are locked after smart cards are removed. - You use a VPN connection to connect to a client computer that is running Windows 7 or Windows Server 2008 R2.
Note You can successfully log on to the client computer by using smart card credentials. - You log on to the computer after the VPN connection is connected.
- The smart card is removed.
Note This issue does not occur when you log on to the client computer by using smart card credentials.
The following is the detailed scenario table:
Scenario | Smart Card Removal Policy | Credentials that are used for VPN logon before Windows logon | Credentials that are used to log in to the computer | Current behavior after smart card removal if the hotfix is not installed | Expected behavior after smart card removal if the hotfix is installed |
---|---|---|---|---|---|
1 | Started | Smart card | Smart card | Does not log off | Log off |
2 | Started | User name password | User name password | Does not log off | Does not log off |
3 | Started | User name password | Smart card | Does not log off | Log off |
4 | Started | Smart card | User name password | Does not log off | Does not log off |