Solved

User can log into OWA using old password if username entered as user@domain

Posted on 2014-10-20
2
399 Views
Last Modified: 2014-10-21
A user just came to me to say he changed his password and then noticed that he can log into OWA using both the old and new password.

I had him try it on my computer and it would not allow him to do it, so I just told him to go clear his cache, thinking it was just strange voodoo that would go away.

He came back to me again and said if he logged in user domain\user then it would only work with his new password, but if used user@domain as the username, then he could log in with both passwords.

I had him show me on my machine and sure  enough, it was true.  I assume he was using his old and new password and have no reason to not believe him.

The only thing I could think was that he was authenticating using 2 different DCs that hadn't synchronized, but we only have one mail server and I can't see the browser going out through a remote site VPN to authenticate and then come back here to access the exchange server.

Any thoughts on this?
0
Comment
Question by:Sys_Admin1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 29

Accepted Solution

by:
becraig earned 500 total points
ID: 40393665
There is a cache setting in IIS / OWA
http://support.microsoft.com/kb/152526

When the user authenticates, he or she is given a token that is valid for a certain window.
So you have two potential things here:
1. A Global Catalog that has not yet caught up
2. The Token has not yet expired on the OWA server.

Here is some additional reading on this which should help.


http://www.techrepublic.com/article/why-does-my-old-password-work-via-activesync/
0
 
LVL 1

Author Closing Comment

by:Sys_Admin1
ID: 40394258
Thanks.  Here is another KB I found, which seems to be the same information.  http://support.microsoft.com/kb/267568

I'm currently running Exchange 2013 running on server 2012R2, with IIS 8.5
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Windows Server 2012 & 2000 Network HELP 55 91
local resources on a virtual host 8 61
Windows Server 2012 unable to backup to shared folder 3 28
BgInfo help 5 59
Every now and then, Microsoft does something that totally impresses me. It doesn't happen often, but in this case I must say I am thoroughly impressed with Windows Server Backup. One of the long time issues with Windows Backup has been the ability t…
Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
This tutorial will walk an individual through the process of configuring basic necessities in order to use the 2010 version of Data Protection Manager. These include storage, agents, and protection jobs. Launch Data Protection Manager from the deskt…
This tutorial will walk an individual through the process of installing the necessary services and then configuring a Windows Server 2012 system as an iSCSI target. To install the necessary roles, go to Server Manager, and select Add Roles and Featu…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question