Solved

Change password with OWA

Posted on 2011-03-01
17
574 Views
Last Modified: 2012-08-13
Hi All,

Im running Exchange 2010

Some of my mobile users are trying to change password over OWA but it will not let them change. Saying that minimal requirements have not been met even tho password entered are really complex.

Thanks
0
Comment
Question by:aucklandnz
  • 8
  • 7
  • 2
17 Comments
 
LVL 13

Expert Comment

by:AustinComputerLabs
ID: 35014095
What version of server?
Were these users migrated from an older version since they last set their password?
0
 
LVL 3

Author Comment

by:aucklandnz
ID: 35014103
Version 14.1 (build 218.15) yes the user was migrated from exchange 2007

thanks
0
 
LVL 13

Expert Comment

by:AustinComputerLabs
ID: 35014130
The Migration will allow passwords that do not meet the requirements but if you change it must meet the folllowing:

•Passwords cannot contain the user’s account name or parts of the user’s full name that exceed two consecutive characters.
•Passwords must be at least six characters in length.
•Passwords must contain characters from three of the following four categories:

1.English uppercase characters (A through Z).
2.English lowercase characters (a through z).
3.Base 10 digits (0 through 9).
4.Non-alphabetic characters (for example, !, $, #, %).
0
Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

 
LVL 3

Author Comment

by:aucklandnz
ID: 35014139
the user was able to change the password while connected to domain, i have  enforce complex password policy in GP and still cannot change
0
 
LVL 13

Expert Comment

by:AustinComputerLabs
ID: 35014187
Do you have an SSL cert for that installation?
0
 
LVL 3

Author Comment

by:aucklandnz
ID: 35014193
yes
0
 
LVL 13

Accepted Solution

by:
AustinComputerLabs earned 500 total points
ID: 35014209
Check the Minimum Password Age setting in the Domain GPO. If you do not enable a minimum password age then OWA will not let you change the password.

You need to Enable the Minimum Password Age setting and set it to 0 or higher for the Change Password feature of OWA to work.
0
 
LVL 3

Author Comment

by:aucklandnz
ID: 35014253
Minimum Password Age setting in the Domain GPO is set to 28
0
 
LVL 13

Expert Comment

by:AustinComputerLabs
ID: 35014267
Try 0 as a test, and see if that changes the behavior. I had one set to 7 that did not work until I changed it to 0 (which is like disabling that requirement).
0
 
LVL 13

Expert Comment

by:AustinComputerLabs
ID: 35014273
Minimum Password Age  determines the period of time (in days) that a password must be used before the user can change it. You can set a value between 1 and 998 days, or you can allow changes immediately by setting the number of days to 0.

0
 
LVL 7

Expert Comment

by:FemSteenkamp
ID: 35014921
i think AustinComputerLabs: found the problems

outlook nearly always returns the one generic error about complexity if for any reasons the passwords cannot be updated. i think this is deliberate so that the return message does not return information that hackers can use to gues password and usernames.

the minimum password age just looks at whent he password was last changed ( it doesnt matter if it was teh uers or an admin doing a reset) and will not allow the password to be changed for the duration. checking the  box "user must change password at next logon" will overide this setting but has other problems if users dont log on to a domain with their workstations (i.e. only using AD for outlook authentication.
0
 
LVL 13

Expert Comment

by:AustinComputerLabs
ID: 35033503
Did you solve this or do you need more assistance?
0
 
LVL 3

Author Comment

by:aucklandnz
ID: 35033550
I'm off till Monday. I will make the change on Monday and post the result.

Thanks for all your comments
0
 
LVL 3

Author Comment

by:aucklandnz
ID: 35076520
hi,

I have change it but still cannot change the password

thanks
0
 
LVL 13

Expert Comment

by:AustinComputerLabs
ID: 35076536
You set the Minimum Password Age setting to 0 and then ran gpupdate /force?
0
 
LVL 3

Author Comment

by:aucklandnz
ID: 35077577
yes. Minimum and Maximum to 0, with gpupdate /force

I have edit Default Group Policy at the top level just to make sure
0
 
LVL 7

Expert Comment

by:FemSteenkamp
ID: 35108081
just some more info.

1) you can always RESET a password from the MMC, regardless  of the policy settings.
  just note that this ALSO bypass password history check etc. the ONLY thing that password reset (as opposed to change) look at is that it must meet length and complexity requirements
2) clicking the "user must change pasword at next logon" overides the policy about password age and alow the user to change the password.

0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Utilizing an array to gracefully append to a list of EmailAddresses
Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
In this Micro Video tutorial you will learn the basics about Database Availability Groups and How to configure one using a live Exchange Server Environment. The video tutorial explains the basics of the Exchange server Database Availability grou…
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question