There is a local policy on the Windows machine (I'm assuming Windows XP/Vista) that you can set so that if it cannot contact the domain controller, it will not allow the user to logon until the domain controller is back up. By default, Windows caches user credentials in case the domain is down.
|