A mechanism for rapidly authenticating an interactive user in an operating
system logon session based on a shared account by using a credential
delivery application to enable permission-based access to a user's remote
session from the shared account is disclosed. The present invention
provides the ability to switch local interactive users, authenticate the
new interactive user, and switch the remote session without requiring the
client to first establish a new logon session tied to the new local
interactive user. The present invention also alters the normal locking
mechanism found in operating system logon sessions so as to restrict
access to an interactive local user's applications (both local and
remote) while still allowing the rapid switching of interactive users at
the client device.