Article ID: 152526 - Last Review: July 7, 2008 - Revision: 6.1 Changing the Default Interval for User Tokens in IISThis article was previously published under Q152526 We strongly recommend that all users upgrade to Microsoft Internet Information Services (IIS) version 7.0 running on Microsoft Windows Server 2008. IIS 7.0 significantly increases Web infrastructure security. For more information about IIS security-related topics, visit the following Microsoft Web site: http://www.microsoft.com/technet/security/prodtech/IIS.mspx
(http://www.microsoft.com/technet/security/prodtech/IIS.mspx)
For more information about IIS 7.0, visit the following Microsoft Web site: http://www.iis.net/default.aspx?tabid=1
(http://www.iis.net/default.aspx?tabid=1)
SYMPTOMS
Internet Information Server (IIS) has a default delay of 15 minutes before
users tokens are updated. For example, if you change the password on a user
account, you will be able to connect to the server with both the old
password and the new password.
CAUSE
For performance reasons, user tokens are cached by IIS and updated at 15
minute intervals.
RESOLUTION
The token cache can be refreshed manually by stopping and restarting ALL of
the IIS services (Gopher, FTP, and WWW). For performance reasons, this is
the preferred method if updates are infrequent.
The default interval for the token cache can also be changed in the Microsoft Windows registry. WARNING: Using Registry Editor incorrectly can cause serious, system wide problems that may require you to reinstall Windows to correct them. Microsoft cannot guarantee that any problems resulting from the use of Registry Editor can be solved. Use this tool at your own risk.
APPLIES TO
| Article Translations
|
Back to the top
