Offline Domain Join via Cached VM Snapshots

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for domain joining and security configuration of computing devices in enterprise environments often require local connectivity to the corporate network, which can be inconvenient for remote users, and previous solutions have been incomplete or reliant on unavailable technologies like VPN or DirectAccess.

Innovation Solution

A process that allows for offline domain join and login by starting a virtual machine on a local network, performing a domain join and login using cached credentials, and delivering the necessary configuration changes to the user's device over a remote network connection, enabling access to corporate resources without local access to the domain controller.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If domain join and security configuration is performed using conventional methods, then security is ensured through proper domain integration, but local connectivity to the corporate network is required which is inconvenient for remote users

Engineering Contradiction:
Improveease of domain join for remote usersVSAvoidsecurity configuration reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs domain join and security configuration actions in advance by capturing a snapshot of the virtual machine after successful domain integration. This pre-configured snapshot can then be deployed to remote users without requiring them to perform domain join locally, thus improving ease of operation while maintaining security configuration reliability through the pre-captured authenticated state

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention creates a copy of the domain-joined virtual machine state through snapshotting. The snapshot captures the configured security settings and domain credentials, allowing remote users to obtain a pre-configured copy that works offline. This copying mechanism enables remote users to access domain resources without local connectivity while maintaining the security posture of a properly domain-joined machine

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If solutions like VPN or DirectAccess are used to enable remote domain join, then connectivity is provided, but these technologies are not always readily available or increase system complexity

Engineering Contradiction:
Improveadaptability to remote work scenariosVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The invention extracts the domain join and security configuration process from the requirement for continuous network connectivity. By capturing the configured state in a snapshot and transferring it offline, the solution removes the dependency on VPN or DirectAccess technologies, reducing system complexity while maintaining adaptability to remote work scenarios

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the domain join process into two distinct phases: (1) initial domain integration performed on a locally connected machine, and (2) snapshot capture and transfer to remote users. This segmentation allows the complex domain join operations to be performed once in a controlled environment, while remote users receive a simplified pre-configured state without requiring complex connectivity solutions

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If a virtual machine is downloaded over a remote network connection, then remote access is enabled, but the virtual machine lacks domain credentials and security configuration without local connectivity

Engineering Contradiction:
Improveremote VM deploymentVSAvoidsecurity configuration completeness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system introduces a snapshot as an intermediary carrier that transfers domain credentials and security configuration from a locally connected environment to remote users. The snapshot acts as a mediator that encapsulates the authenticated state, allowing the virtual machine to be deployed remotely with complete security configuration without requiring the end user to have local network connectivity

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10419426B2Cached credentials for offline domain join and login without local access to the domain controller
Publication Date: 2019.09.17 OMNISSA LLC
  • US10419426B2 patent drawing
  • US10419426B2 patent drawing
  • US10419426B2 patent drawing

AI summary

Techniques are described for performing an offline domain join and login on behalf of a computing device in order to enable the device to access corporate resources without local access to the domain controller. A slave service is described that can start a virtual machine on a local network of the enterprise, perform an offline domain join of the virtual machine, perform a first login to the virtual machine using credentials of a remote user and then capture the changes made on the virtual machine and deliver those changes to the remote user's device. These changes can then be applied on the user's device to add the credentials and configuration changes necessary for the user to access the private enterprise resources remotely.