I hope this doesn't come across as an idiotic question, but here is the scenario:
We have a server 2008R2 domain, using PKI authentication managed through safenet. For a few systems within our domain, due to design restrictions, several users must use a single shared account. That is easily managed by adding the shared account to their smart card, but this raises the question of non-repudiation. Essentially:
Is there a way to keep track of what card logged into the shared account? or some other way to differentiate user usages to track who was actually using the account at a given time?
Under these conditions, no card would have only the shared account, all cards would also have a designated user account assigned to them, the shared account would be secondary.