Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

User can log into OWA using old password if username entered as user@domain

Posted on 2014-10-20
2
Medium Priority
?
435 Views
Last Modified: 2014-10-21
A user just came to me to say he changed his password and then noticed that he can log into OWA using both the old and new password.

I had him try it on my computer and it would not allow him to do it, so I just told him to go clear his cache, thinking it was just strange voodoo that would go away.

He came back to me again and said if he logged in user domain\user then it would only work with his new password, but if used user@domain as the username, then he could log in with both passwords.

I had him show me on my machine and sure  enough, it was true.  I assume he was using his old and new password and have no reason to not believe him.

The only thing I could think was that he was authenticating using 2 different DCs that hadn't synchronized, but we only have one mail server and I can't see the browser going out through a remote site VPN to authenticate and then come back here to access the exchange server.

Any thoughts on this?
0
Comment
Question by:Sys_Admin1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 29

Accepted Solution

by:
becraig earned 2000 total points
ID: 40393665
There is a cache setting in IIS / OWA
http://support.microsoft.com/kb/152526

When the user authenticates, he or she is given a token that is valid for a certain window.
So you have two potential things here:
1. A Global Catalog that has not yet caught up
2. The Token has not yet expired on the OWA server.

Here is some additional reading on this which should help.


http://www.techrepublic.com/article/why-does-my-old-password-work-via-activesync/
0
 
LVL 1

Author Closing Comment

by:Sys_Admin1
ID: 40394258
Thanks.  Here is another KB I found, which seems to be the same information.  http://support.microsoft.com/kb/267568

I'm currently running Exchange 2013 running on server 2012R2, with IIS 8.5
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
A procedure for exporting installed hotfix details of remote computers using powershell
In this Micro Tutorial viewers will learn how to restore their server from Bare Metal Backup image created with Windows Server Backup feature. As an example Windows 2012R2 is used.
This tutorial will walk an individual through the process of configuring basic necessities in order to use the 2010 version of Data Protection Manager. These include storage, agents, and protection jobs. Launch Data Protection Manager from the deskt…

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question