Solved

forefront tmg 2010 sp2 rollup 3 enforce password change from AD not working

Posted on 2013-02-04
4
1,034 Views
Last Modified: 2013-04-22
Hi all,

We have installed Forefront tmg 2010 sp2 rollup 3 and it is being used by Sharepoint and OWA.

We applied this Cscript EnableHotfix957859.vbs /webListener:<listener name> /Value:true for the OWA and Sharepoint Listeners.

Now we are enforcing a user to change the password from AD and if you enter correct username and any password a prompt will follow and ask you to change password. If we remove the enforce password from AD and test again with any password it says incorrect password.

Can you please inform us what the problem might be?
0
Comment
Question by:casscar
  • 2
  • 2
4 Comments
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 38853813
That is a very old hotfix which I used to use with ISA server, wasn't aware it also applied to TMG. The TMG is domain joined? Only the one TMG node?

What traffic are you seeing in the TMG realtime viewer during the password challenge stage?
Have you run a net monitor capture during the same stage to check the activity?

Keith
0
 

Author Comment

by:casscar
ID: 38853993
Hi Keith,

Do you have an idea what was the hotfix? No the TMG is not a member of the domain.
0
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 500 total points
ID: 38856302
Sure, this is a link to the text - and I note that it now includes TMG - but i guess this is what you have already applied.
http://support.microsoft.com/kb/957859

So you are connecting TMG to ad how for the pass through? LDAP? LDAPS?
If TMG is not domain-joined, I assume TMG is deployed with a single NIC in the DMZ? If so, what is between TMG and the AD controller(s) on the inside?

Feedback on my questions from earlier?
0
 

Author Closing Comment

by:casscar
ID: 39099957
Thanks all
0

Featured Post

3 Use Cases for Connected Systems

Our Dev teams are like yours. They’re continually cranking out code for new features/bugs fixes, testing, deploying, testing some more, responding to production monitoring events and more. It’s complex. So, we thought you’d like to see what’s working for us.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In all versions of ISA Server and the current version of FTMG, the default https protocol uses TCP port 443 and 563 only. This cannot be changed within the ISA or FTMG GUI and must be completed from a Windows cmd prompt on the ISA Server itself. …
Forefront Threat Management Gateway 2010 or FTMG comes with some very neat troubleshooting tools built-in when trying to identify what is actually happening behind the scenes within the product when traffic is passing through its interfaces. To the …
Along with being a a promotional video for my three-day Annielytics Dashboard Seminor, this Micro Tutorial is an intro to Google Analytics API data.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question