Share via


Active Directory Domain Connection over the Internet

Question

Thursday, March 28, 2013 9:03 PM

Is there a way to keep a laptop joined and connected to my Active Directory domain with network login accounts still available over the Internet?

All replies (4)

Thursday, March 28, 2013 9:15 PM ✅Answered

You can, but i would think it wouldn't be safe to open up your AD to the world.

Note that - during logon - a lot of traffic flows between the server and client (if i'm correct there's a lof of stuff running over random ports) I guess the best option is still to use a VPN client that connects to your network prior to the actual user login.

Also, you should make your AD DNS globally available. There are ofcourse again good reasons not to.

Kind regards,
Peter


Thursday, March 28, 2013 9:15 PM ✅Answered

You can use techniques like direct access (DA) or VPN to handle laptops that are not connected to the lan, to get them connected to AD.


Thursday, April 25, 2013 4:17 PM

hi

i was actually wondering the same... most vpns are only able to dial out once a local profile is loaded and internet connetivity is established to wifi hotspot etc

so how would we be able to implement above mentioned ways? is there any guide or some example which we can follow?

thanks!!!

Just a lowly techie..


Tuesday, April 30, 2013 9:51 PM

Once a laptop is domain-joined user credentials will be cached so they will be able to login using their domain account even if they do not have network connectivity. Once logged in they could use a VPN client to authenticate into your domain and then access resources in the same way as they would if they were connected to the LAN.