this post was submitted on 19 Apr 2024
341 points (97.2% liked)

Technology

34971 readers
186 users here now

This is the official technology community of Lemmy.ml for all news related to creation and use of technology, and to facilitate civil, meaningful discussion around it.


Ask in DM before posting product reviews or ads. All such posts otherwise are subject to removal.


Rules:

1: All Lemmy rules apply

2: Do not post low effort posts

3: NEVER post naziped*gore stuff

4: Always post article URLs or their archived version URLs as sources, NOT screenshots. Help the blind users.

5: personal rants of Big Tech CEOs like Elon Musk are unwelcome (does not include posts about their companies affecting wide range of people)

6: no advertisement posts unless verified as legitimate and non-exploitative/non-consumerist

7: crypto related posts, unless essential, are disallowed

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] CrazyLikeGollum@lemmy.world 1 points 7 months ago

There is a local Administrator account in an AD environment (just like on all Windows systems), but that may be disabled.

As for the domain users, you have a locally created profile and because it caches your credentials you can sign in offline, but your account isn't local in the sense that you could sign in offline (or without access to the domain) indefinitely. For on-prem AD, at least with 2012R2, 2012, and 2008R2 (the last versions I worked with, so can't speak for newer) by default the length that clients held onto that cache was 30 days, but it was configurable in Group Policy. If your device was away from the domain for longer than that you would no longer be able to sign in.

Depending on how your domain is configured you might even have your profile redirected to a network share somewhere, making the account even less local.

Microsoft accounts on personal devices function in basically the same way. If they're offline for too long you stop being able to logon, but you won't lose data in your user folder (unless you've setup profile redirection to One Drive or an SMB share on a NAS).

In neither of those scenarios would I say your account is local, because a network connection is required for initial sign in and then periodically afterwards to be able to use the device with your account.