There's a catch, the MAN is part of a WAN. I don't control the WAN. Our MAN is just one domain, one "Tree" in the Active Directory "forest". Our AD servers are controlled by the people who control the WAN. We don't have access to GPOs. I've sent several GPO requests up to the people who control the WAN. They've added synchonous logon, and disable Windows XP fast logon optimization to the GPO at my request, but haven't added a few others I would like to see.

There isn't a GPO (that I know of) that will log a user off 14 hours after they log on. Don't want to set logon hours, due to shift work, and sheer number of users and workstations.

I'd post the script so you could understand what I'm doing, but it's 35 files, and over 3000 lines of code.

Thanks for the link to that thread. After reading that, it looks like this has been a problem since KiX 4.02, maybe even before that. I guess we have to do what Les said and "bend Ruud's ear" to get this fixed. Unless someone has another idea.