When the machine has no network connection to Policy Server (e.g. In the endpoint's next reboot even with no network connection, the user can use the new domain password to login because the cached password is already updated with the new one. Once the authentication has succesfully completed, the preboot will be updated with the new password. When the machine has a working network connection to the Policy Server and Active Directory during preboot, the user can authenticate at the FDE preboot using the new domain password. Connect to the Policy Server during preboot If a user changes a domain password in Windows, there are two (2) methods to get the password updated on the Full Disk Encryption (FDE) client preboot.