• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 451
  • Last Modified:

User can log into OWA using old password if username entered as user@domain

A user just came to me to say he changed his password and then noticed that he can log into OWA using both the old and new password.

I had him try it on my computer and it would not allow him to do it, so I just told him to go clear his cache, thinking it was just strange voodoo that would go away.

He came back to me again and said if he logged in user domain\user then it would only work with his new password, but if used user@domain as the username, then he could log in with both passwords.

I had him show me on my machine and sure  enough, it was true.  I assume he was using his old and new password and have no reason to not believe him.

The only thing I could think was that he was authenticating using 2 different DCs that hadn't synchronized, but we only have one mail server and I can't see the browser going out through a remote site VPN to authenticate and then come back here to access the exchange server.

Any thoughts on this?
0
Sys_Admin1
Asked:
Sys_Admin1
1 Solution
 
becraigCommented:
There is a cache setting in IIS / OWA
http://support.microsoft.com/kb/152526

When the user authenticates, he or she is given a token that is valid for a certain window.
So you have two potential things here:
1. A Global Catalog that has not yet caught up
2. The Token has not yet expired on the OWA server.

Here is some additional reading on this which should help.


http://www.techrepublic.com/article/why-does-my-old-password-work-via-activesync/
0
 
Sys_Admin1Author Commented:
Thanks.  Here is another KB I found, which seems to be the same information.  http://support.microsoft.com/kb/267568

I'm currently running Exchange 2013 running on server 2012R2, with IIS 8.5
0

Featured Post

Receive 1:1 tech help

Solve your biggest tech problems alongside global tech experts with 1:1 help.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now