Note These issues also apply to Microsoft Forefront Threat Management Gateway 2010.If the user specifies a user name that uses a UPN format, the user can change the password. If the ISA Server 2006 Firewall Service is restarted, users might also be able to change a password until the connection to the global catalog server is broken again.
Issue 1:
Consider the following scenario:- You have a server that is running Microsoft Internet Security and Acceleration (ISA) 2006.
- You configured a Forms Based Authentication (FBA) listener by selecting HTML Form Authentication on the Authentication tab.
- The listener is configured to let users change their passwords.
- You used the functionality that is described in Microsoft Knowledge Base article 952675 to enable ISA 2006 to search for the user in multiple domains. For more information, click the following article number to view the article in the Microsoft Knowledge Base: 952675 You cannot log on to a local intranet site that you publish by using ISA Server 2006 when there are multiple user accounts that have the same account name in different domains
- The account for the user who tries to log on is located in a domain in a remote trusted forest.
Issue 2:
Consider the following scenario:- You have a server that is running Microsoft Internet Security and Acceleration (ISA) 2006.
- You configured a Forms Based Authentication (FBA) listener by selecting HTML Form Authentication on the Authentication tab.
- The listener is configured to let users change passwords.
- You have a web publishing rule that uses this listener to publish a website.
- You used the functionality that is described in Microsoft Knowledge Base article 952675 to enable ISA 2006 to search for the user in multiple domains. For more information, click the following article number to view the article in the Microsoft Knowledge Base: 952675 You cannot log on to a local intranet site that you publish by using ISA Server 2006 when there are multiple user accounts that have the same account name in different domains
- The connection that ISA Server 2006 opened to the global catalog server was unexpectedly closed, for example, by a firewall between the two servers.
- The user who is logging on has specified the user name in an NT4/SAM-based naming format.
- The new password that is specified by the user meets complexity requirements.
Either the user name or old password is not valid, or the new password does not meet the minimum complexity requirements. Please try again.