Assume that you have a client computer that has a cached locked-out account in a Windows Server 2008 R2-based Active Directory Domain Services (AD DS)environment. When you try to log on to the computer by using a smart card, the behavior differs from the behavior that occurs if you log on by using your username and password.
Consider the following scenarios.
Scenario 1
Scenario 2
Consider the following scenarios.
Scenario 1
- You use a smart card to log on to the cached locked-out account. The logon fails, and you receive the following error message:The system could not log you on. Your account has been disabled. Please see your system administrator.
- You disconnect the computer from the AD DS environment, and then you try to log on again.
The system could not log you on. The domain specified is not available. Please try again later.
Scenario 2
- You use your username and password to log on to the cached locked-out account. The logon fails, and you receive the following error message:The reference account is currently locked out and may not be logged on to.
- You disconnect the computer from the AD DS environment.