Are you asking if he can log in without being on the network?
He should be able to, granted that his account has been logged onto already on that laptop.
Also, should his password change policy occur on the domain and he logs into the VPN several days after that, he should be prompted to log in during the VPN session when he logs into your domain network.
Or am I getting what you are asking wrong.
|