Solved

forefront tmg 2010 sp2 rollup 3 enforce password change from AD not working

Posted on 2013-02-04
4
1,051 Views
Last Modified: 2013-04-22
Hi all,

We have installed Forefront tmg 2010 sp2 rollup 3 and it is being used by Sharepoint and OWA.

We applied this Cscript EnableHotfix957859.vbs /webListener:<listener name> /Value:true for the OWA and Sharepoint Listeners.

Now we are enforcing a user to change the password from AD and if you enter correct username and any password a prompt will follow and ask you to change password. If we remove the enforce password from AD and test again with any password it says incorrect password.

Can you please inform us what the problem might be?
0
Comment
Question by:casscar
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 38853813
That is a very old hotfix which I used to use with ISA server, wasn't aware it also applied to TMG. The TMG is domain joined? Only the one TMG node?

What traffic are you seeing in the TMG realtime viewer during the password challenge stage?
Have you run a net monitor capture during the same stage to check the activity?

Keith
0
 

Author Comment

by:casscar
ID: 38853993
Hi Keith,

Do you have an idea what was the hotfix? No the TMG is not a member of the domain.
0
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 500 total points
ID: 38856302
Sure, this is a link to the text - and I note that it now includes TMG - but i guess this is what you have already applied.
http://support.microsoft.com/kb/957859

So you are connecting TMG to ad how for the pass through? LDAP? LDAPS?
If TMG is not domain-joined, I assume TMG is deployed with a single NIC in the DMZ? If so, what is between TMG and the AD controller(s) on the inside?

Feedback on my questions from earlier?
0
 

Author Closing Comment

by:casscar
ID: 39099957
Thanks all
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

In Africa (and potentially where you live…), reliability of ISPs is questionable.  With the increased reliance on e-mail as one of the primary forms of communication, the costs to business are significant based on interuption of ISP Connectivity.  T…
Forefront Threat Management Gateway 2010 or FTMG comes with some very neat troubleshooting tools built-in when trying to identify what is actually happening behind the scenes within the product when traffic is passing through its interfaces. To the …
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question