IWA automatically re-enables on OWA folders.



This is a bit of a strange one.

We're running OWA on an E2k3 cluster in support of a large client base
of mixed Win2k and XP Pro clients. Our site is SSL secured and
therefore we have manually DISABLED Integrated Windows Authentication
on the Exchange virtual directory within Exchange System Manager,
leaving only basic enabled.

The system has been running fine for months but recently we ran into a
problem where none of our Win2k clients could log on. After a whole
hunt, we found that this was because Integrated Windows Authentication
had mysteriously switched itself back on!

Microsoft say our UPN logons were failing because of the 2k version of
credui.dll which cannot process UPN logons through IWA whereas the XP
version can. Sure enough, when we manually disabled IWA again, the
problem disappeared.

However, this doesn't explain why that setting switched itself on.
This wasn't a once off either and has happened several times since
then - with nothing obvious in the event logs, no failover, servers
just sitting there...

Bizarro; anyone got any ideas?
.