FIX: You may be redirected to the password change page when your password has not expired or is not near expiration when you use Forms Based Authentication in Forefront Threat Management Gateway 2010

Article ID: 2591279 - View products that this article applies to.
Expand all | Collapse all

SYMPTOMS

When you use Forms Based Authentication (FBA) in a Microsoft Forefront Threat Management Gateway (TMG) 2010 environment, you may be redirected to the password change page even when your password has not expired or is not near expiration. This behavior may occur when the password expiry policy is controlled by a Fine-Grained Password Policy (FGPP) or by Password Settings Objects (PSOs).

CAUSE

This problem occurs because TMG does not check the PSOs object class for the user and relies on the Domain Security policy. This may cause TMG to incorrectly calculate the password expiration time.

RESOLUTION

To resolve this problem, install the service pack that is described in the following Microsoft Knowledge Base article:
2555840 Description of Service Pack 2 for Microsoft Forefront Threat Management Gateway 2010

STATUS

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

REFERENCES

For more information about software update terminology, click the following article number to view the article in the Microsoft Knowledge Base:
824684 Description of the standard terminology that is used to describe Microsoft software updates

Properties

Article ID: 2591279 - Last Review: October 31, 2011 - Revision: 2.0
APPLIES TO
  • Microsoft Forefront Threat Management Gateway 2010 Enterprise
  • Microsoft Forefront Threat Management Gateway 2010 Standard
  • Microsoft Forefront Threat Management Gateway 2010 Service Pack 1
Keywords: 
kbfix kbbug kbexpertiseinter kbsurveynew KB2591279

Give Feedback

 

Contact us for more help

Contact us for more help
Connect with Answer Desk for expert help.
Get more support from smallbusiness.support.microsoft.com