Solved

forefront tmg 2010 sp2 rollup 3 enforce password change from AD not working

Posted on 2013-02-04
4
1,022 Views
Last Modified: 2013-04-22
Hi all,

We have installed Forefront tmg 2010 sp2 rollup 3 and it is being used by Sharepoint and OWA.

We applied this Cscript EnableHotfix957859.vbs /webListener:<listener name> /Value:true for the OWA and Sharepoint Listeners.

Now we are enforcing a user to change the password from AD and if you enter correct username and any password a prompt will follow and ask you to change password. If we remove the enforce password from AD and test again with any password it says incorrect password.

Can you please inform us what the problem might be?
0
Comment
Question by:casscar
  • 2
  • 2
4 Comments
 
LVL 51

Expert Comment

by:Keith Alabaster
ID: 38853813
That is a very old hotfix which I used to use with ISA server, wasn't aware it also applied to TMG. The TMG is domain joined? Only the one TMG node?

What traffic are you seeing in the TMG realtime viewer during the password challenge stage?
Have you run a net monitor capture during the same stage to check the activity?

Keith
0
 

Author Comment

by:casscar
ID: 38853993
Hi Keith,

Do you have an idea what was the hotfix? No the TMG is not a member of the domain.
0
 
LVL 51

Accepted Solution

by:
Keith Alabaster earned 500 total points
ID: 38856302
Sure, this is a link to the text - and I note that it now includes TMG - but i guess this is what you have already applied.
http://support.microsoft.com/kb/957859

So you are connecting TMG to ad how for the pass through? LDAP? LDAPS?
If TMG is not domain-joined, I assume TMG is deployed with a single NIC in the DMZ? If so, what is between TMG and the AD controller(s) on the inside?

Feedback on my questions from earlier?
0
 

Author Closing Comment

by:casscar
ID: 39099957
Thanks all
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Forefront is the brand name for Microsoft's major security product. Forefront covers a number of specific security areas and has 'swallowed' a number of applications under this umbrella including Antigen, ISA Server, the Integrated Access Gateway (t…
In all versions of ISA Server and the current version of FTMG, the default https protocol uses TCP port 443 and 563 only. This cannot be changed within the ISA or FTMG GUI and must be completed from a Windows cmd prompt on the ISA Server itself. …
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now