Go Back   { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Microsoft > Windows Server

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-23-2008, 07:36 PM
Chad Bailey
 
Posts: n/a
AD password syncing, replication, & Exchange

Here's the problem....

We have one 2003 domain spread over multiple physical sites. Each site
is connected to the main site by WAN links and has a local domain
controller. The main office site has an Exchange server which hosts all
client mailboxes, including the ones for the remote site users.

The problem we have is with password synchronization timing. For
example, if a user's password expires and they have to change it on
their client, and they are in the home site where the Exchange server is
located, there are no issues.

BUT!... if a user at one of the remote sites changes their password, the
synchronization is such in AD across the remote links that Exchange does
not get the updated information until the next replication time which at
the shortest is 15 minutes. So this person is locked out of exchange
until the AD replication is sent to the home site.

In AD, I have defined individual subnets and sites for these remote
locations. As best I can tell, when you define different sites, it is
impossible to reduce the replication time under 15 minutes. And that is
what presents the password syncing issues for us.

Is there anyway around this problem?

Thanks for any advice.

Chad
Reply With Quote
  #2 (permalink)  
Old 07-24-2008, 02:11 PM
Meinolf Weber
 
Posts: n/a
Re: AD password syncing, replication, & Exchange

Hello Chad,

If a DC other than the PDCemulator receives an authentication request with
a bad password, before it rejects the authentication request outright it
will refer the authentication request to the PDCemulator.

So make sure the Exchange has the PDCEmulator under the ESM "recipient update
service".

See here about the passwored replication, scroll down to "Replication of
Password Changes":
http://technet2.microsoft.com/window....mspx?mfr=true

http://www.microsoft.com/technet/abo...ps_060805.mspx

Do you use OWA from Exchange?

Also check this document about, search it for Exchange:
http://www.microsoft.com/downloads/d...displaylang=en

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm

> Here's the problem....
>
> We have one 2003 domain spread over multiple physical sites. Each site
> is connected to the main site by WAN links and has a local domain
> controller. The main office site has an Exchange server which hosts
> all client mailboxes, including the ones for the remote site users.
>
> The problem we have is with password synchronization timing. For
> example, if a user's password expires and they have to change it on
> their client, and they are in the home site where the Exchange server
> is located, there are no issues.
>
> BUT!... if a user at one of the remote sites changes their password,
> the synchronization is such in AD across the remote links that
> Exchange does not get the updated information until the next
> replication time which at the shortest is 15 minutes. So this person
> is locked out of exchange until the AD replication is sent to the home
> site.
>
> In AD, I have defined individual subnets and sites for these remote
> locations. As best I can tell, when you define different sites, it is
> impossible to reduce the replication time under 15 minutes. And that
> is what presents the password syncing issues for us.
>
> Is there anyway around this problem?
>
> Thanks for any advice.
>
> Chad
>



Reply With Quote
Reply

  { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Microsoft > Windows Server


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 12:42 PM.


Powered by vBulletin, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.
© 1999-2008 mindfrost82.com v11.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109