Correct, you have to logon. The other quirk with it is it must be a cached domain account for it to work. I tried to invoke the feature with a local account and it just puked. This is a work around solution developed according to JTAC for Vista. GINA Enabled NC on XP is a good solution, but it is not perfect. I was not able to deploy it at our company becuase for some reason it must be the only "GINA" Chained app on the computer and I ran into conflicts with another application. I added gpupdate /force to the NC start up script to make sure the GPO's are updated. We also are going to start notifying users via email that their passwords are about to expire so they can manually change them via ctrl-alt-dlt. Hate to put it back on my users, but I have not found a better solution. Still looking for a good solution that does not feel like a "bandaid" for the same problem you are dealing with.
... View more