From: wildgoosed on
I need some confirmation on something.

Normally if an domain account is going to expire, the "change password
on next login" bit is set and the user is forced to change their
password.

With OWA users, they do not login to the domain so this bit never gets
set. Correct?

If correct, what if I had a script that enabled this "change password
on next login" bit ?

On Nov 28, 1:11 pm, wildgoosed <david.wildgo...(a)gmail.com> wrote:
> We are set to use forms-based authentication. No ISA server here.
>
> On Nov 28, 12:56 pm, "Ed Crowley [MVP]" <cursp...(a)nospam.net> wrote:
>
>
>
> > Are you set to use forms-based authentication?  Are you authenticating
> > through an ISA server?  I'm not sure that will work if ISA is doing the
> > forms-based authentication.
> > --
> > Ed Crowley MVP
> > "There are seldom good technological solutions to behavioral problems."
> > .
>
> > "wildgoosed" <david.wildgo...(a)gmail.com> wrote in message
>
> >news:9d38596a-c786-45e3-be89-ac1e7a2b656d(a)g26g2000yqe.googlegroups.com....
>
> > > Hey everyone, I have a question regarding Exchange 2007 OWA.
>
> > > I have several users who have not changed their passwords and they
> > > have expired. According to this technet article, OWA should allow them
> > > to change their password if it is expired, yet it does not allow them
> > > to login.
>
> > >http://technet.microsoft.com/en-us/library/bb684904.aspx
>
> > > These users access OWA outside the office and do not have access to
> > > computers connected to our domain. Any idea how or if I can have OWA
> > > allow them to login but forward them to the change password page?
>
> > > Thanks!

From: Rich Matheisen [MVP] on
On Sun, 29 Nov 2009 10:47:37 -0800 (PST), wildgoosed
<david.wildgoose(a)gmail.com> wrote:

>I need some confirmation on something.
>
>Normally if an domain account is going to expire, the "change password
>on next login" bit is set and the user is forced to change their
>password.

Passwords expire whether you log on or not.

>With OWA users, they do not login to the domain so this bit never gets
>set. Correct?

Many OWA users log on to their desktop machines with a domain account.
However, using OWA isn't the same as logging on, which I think is what
you're assuming.

>If correct, what if I had a script that enabled this "change password
>on next login" bit ?

How would they authenticate (not "log on") if the password is expired?

If you set that condition manually on a user's account can they change
their password through OWA if their password's expired?
---
Rich Matheisen
MCSE+I, Exchange MVP
From: wildgoosed on
Hey Rich, thanks for your comments.

On Nov 29, 12:58 pm, "Rich Matheisen [MVP]"
<richn...(a)rmcons.com.NOSPAM.COM> wrote:
> On Sun, 29 Nov 2009 10:47:37 -0800 (PST), wildgoosed
>
> <david.wildgo...(a)gmail.com> wrote:
> >I need some confirmation on something.
>
> >Normally if an domain account is going to expire, the "change password
> >on next login" bit is set and the user is forced to change their
> >password.
>
> Passwords expire whether you log on or not.
>
> >With OWA users, they do not login to the domain so this bit never gets
> >set. Correct?
>
> Many OWA users log on to their desktop machines with a domain account.
> However, using OWA isn't the same as logging on, which I think is what
> you're assuming.

I understand that.

>
> >If correct, what if I had a script that enabled this "change password
> >on next login" bit ?
>
> How would they authenticate (not "log on") if the password is expired?

Well, they would authenticate normally if they were on a domain
workstation, but they would be forced to change their password. I was
hoping OWA would do the same, but its not.
>
> If you set that condition manually on a user's account can they change
> their password through OWA if their password's expired?

Nope I just tested that and authenticate fails. So I guess my script
idea is not going to work.

Rich or Ed, do you have any suggestions? I'm leaning towards an
automated email warning my users that their account password is about
to expire.

> ---
> Rich Matheisen
> MCSE+I, Exchange MVP

From: Rich Matheisen [MVP] on
On Sun, 29 Nov 2009 12:40:24 -0800 (PST), wildgoosed
<david.wildgoose(a)gmail.com> wrote:

[ snip ]

>Rich or Ed, do you have any suggestions? I'm leaning towards an
>automated email warning my users that their account password is about
>to expire.

That's what we do.

I find it easier to change my password every 30 days.
---
Rich Matheisen
MCSE+I, Exchange MVP
From: "Lee Derbyshire [MVP]" email a on
"wildgoosed" <david.wildgoose(a)gmail.com> wrote in message
news:9d38596a-c786-45e3-be89-ac1e7a2b656d(a)g26g2000yqe.googlegroups.com...
> Hey everyone, I have a question regarding Exchange 2007 OWA.
>
> I have several users who have not changed their passwords and they
> have expired. According to this technet article, OWA should allow them
> to change their password if it is expired, yet it does not allow them
> to login.
>
> http://technet.microsoft.com/en-us/library/bb684904.aspx
>
> These users access OWA outside the office and do not have access to
> computers connected to our domain. Any idea how or if I can have OWA
> allow them to login but forward them to the change password page?
>
> Thanks!

I think that for a user whose password has already expired, they will never
be able to log into OWA in order to change the password, and must go
directly to the IISADMPWD directory. Or is this what you are already
trying?

Lee.

--
______________________________________

Outlook Web Access For PDA , OWA For WAP
www.leederbyshire.com
lee a.t leederbyshire d.o.t c.o.m
______________________________________