Domain Password Synchronisation



I have had trouble finding other people with similar issue probably due to
the phraseology I'm using when searching Google.

Background:
This is a Windows 2003 domain that I did not install/upgrade so I can't
vouch for it (in fact it's a bit of a mess). It was upgraded from an NT
domain with Exchange 5.5.
The W2K3 Exchange 2K3 (member) server is configured with an Active Directory
connector.
The Win2K Proxy (member) server is running ISA 2000 with a content filter
plugin called WebMarshall.
There are two Win2K3 domain controllers (there was an NT4 DC which had lost
communication with the domain months ago - I removed it's traces from Active
Directory and reinstalled it with Win2K3 as a member server - as far as I
can tell, there are no longer any Event errors relating to this server).
A lot of the XP desktops did not have SP2 installed and were, therefore, not
installing the latest updates from MS. This caused problems when users tried
to change their password at logon (they were prevented from doing so) once
it expired (due to the absence of certain security updates). That issue is
now resolved too.
There are many errors still in the Event logs of both DCs (one of the Dcs is
multihomed, which seems to be causing some authentication issues) that I am
trying to resolve.
I could spend all day describing the various problems, but I think I'll hold
off until asked.

The problem:
Essentially, after a period of time (which is possibly coinciding with the
expiration of the password - about one month) the user will login
successfully without being prompted to change their password. Once they open
IE (ISA 2000) or Outlook (Exchange 2003), they will be prompted again for
user id and password. Also if they try to access network shares, they will
be prompted for a password. Their password will not work when they try to
enter it. If they log off and log back in they will again get into Windows
without been prompted to change their password. However, Exchange and ISA
will not let them authenticate.

I used to get the users to Ctrl, Alt & Del and change their password and
the everything would work fine. However, recently, they might be told that
they do not have permission to change their password when logged into
Windows (they do, in ADU&C). If I go ahead and set their password to expire,
they log off and log on, are prompted to change their password - which they
do successfully - and then everything works fine.

Any pointers?

Thanks.
Steve.



.



Relevant Pages

  • RE: DST update for Exchange 2003 and Outlook 2003
    ... The Ldp GUI tool is included when you install Windows Server 2003 Support ... Microsoft CSS Online Newsgroup Support ... DST update for Exchange 2003 and Outlook 2003 ...
    (microsoft.public.exchange.admin)
  • RE: DST update for Exchange 2003 and Outlook 2003
    ... Majority of my users connect to Terminal Server and ... I also have users running on stand-alone PC's (Windows XP) ... run the Outlook Time Zone Data Update Tool or the Exchange calendar tool? ... 926666 Update for daylight saving time changes in 2007 for Exchange 2003 ...
    (microsoft.public.exchange.admin)
  • RE: Migrating from Win2k DCs to Win2k3 DCs; ADPrep question
    ... When you try to upgrade Windows 2000 DC to Windows 2003 while ... Exchange 2000 is installed. ... The reason is that Windows Server 2003 adprep ... 314649 Windows Server 2003 adprep /forestprep Command Causes Mangled ...
    (microsoft.public.windows.server.migration)
  • Re: upgrade from Win2k to win 2003 + exchange
    ... 842427 How to upgrade Exchange 2000 Server to Exchange Server 2003 in an ... 314649 Windows Server 2003 adprep /forestprep Command Causes Mangled ... > This is almost what I am looking for in order to upgrade our exchange 2000 ...
    (microsoft.public.exchange.setup)
  • Re: KRB Error
    ... I'm heading out the door for the day, but there is something tickling the back of my brain about differences with Authenticated Users from Windows 2000 to 2003. ... server of Domain A) as an Domain Administrator. ... Member servers on Domain A cannot access resources on Domain B. ...
    (microsoft.public.win2000.active_directory)

Loading