Users and Disjoining From a Domain
What happens if you have a computer that is part of a domain and has domain users as members of local user groups such as Power User or Administrator? Will those users be able to access the computer?
The answer is somewhat complicated as there are Local Policy Settings that specify whether Windows will cache user accounts (that is once a user logs in from the network, they will be able to login in the future even if network resources are unavailable) or not.
however, putting that Local Policy away for now, any domain users that are added to local groups will no longer be in those groups once the computer is disjoined. You may think this is obvious, but what if the support environment provides that domain level administrators use their domain admin account to access local workstations and the local administrative account is not known to the on-site tech support? It would probably be a good idea to designate a known local admin account and password prior to disjoining or you might find the computer inaccessible after the disjoin!














