<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.1 with Outlook Web Access in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725517#M350378</link>
    <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a weird issue which i am troubleshooting. I just wanted to see if anyone had a different view on this.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an AD User, lets call them work\auser and there password just expired, so next logon to the domain they need to change there password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They decide while at home to connect to Outlook Web Access, which authenticates to via ACS 5.1 to AD, when they try and connect they are denied with the following message in ACS -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://10.240.101.200/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Fadminbordner%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=24407+User+authentication+against+Active+Directory+failed+since+user+is+required+to+change+his+password&amp;amp;__locale=en_US&amp;amp;iportalID=XOSCZFUIMZKCQ&amp;amp;__masterpage=false&amp;amp;__newWindow=false" style="color: red; margin-top: 0pt;" target="_self"&gt;24407 User authentication against Active Directory failed since user is required to change his password&lt;/A&gt;&lt;/P&gt;&lt;P&gt; : &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Authentication failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS also says this as resolution -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the password expiry under Account options in the properties of an&amp;nbsp; external database user. If the password is expired and the Enable Change&amp;nbsp; Password is turned on in the Users and Identity Stores: External&amp;nbsp; Identity Stores &amp;gt; Active Directory page, then the password will be&amp;nbsp; changed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, our OWA is not configured to allow password resets, so they must call in to have there password reset, or they can connect via VPN and our ASA allows them to change there password as configured under Identity Stores &amp;gt; Active Directory &amp;gt; Enable Password Change&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This VPN password change is successful although OWA still will not work. The only way to fix it is to select passwsord does not expire within AD. Let it replicate, then de-select password does not expire and let it replicate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is pointing to a OWA issue in my opinion, although ACS is somehow involved, is it possible that ACS caches authentication, or because OWA does not allow password resets, it keeps responding with user required to change his password?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts or different ways to look at this from a troubleshooting perspective would be greatly appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 01:11:26 GMT</pubDate>
    <dc:creator>bradleyordner</dc:creator>
    <dc:date>2019-03-11T01:11:26Z</dc:date>
    <item>
      <title>ACS 5.1 with Outlook Web Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725517#M350378</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a weird issue which i am troubleshooting. I just wanted to see if anyone had a different view on this.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an AD User, lets call them work\auser and there password just expired, so next logon to the domain they need to change there password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They decide while at home to connect to Outlook Web Access, which authenticates to via ACS 5.1 to AD, when they try and connect they are denied with the following message in ACS -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://10.240.101.200/avreports/servlet/GenericRedirector?command=submit&amp;amp;__requesttype=immediate&amp;amp;invokeSubmit=true&amp;amp;__executableName=%2Fhome%2Fadminbordner%2FFailure_Reason%2FAuthentication_Failure_Code_Lookup.rptdesign&amp;amp;rptFailureReason=24407+User+authentication+against+Active+Directory+failed+since+user+is+required+to+change+his+password&amp;amp;__locale=en_US&amp;amp;iportalID=XOSCZFUIMZKCQ&amp;amp;__masterpage=false&amp;amp;__newWindow=false" style="color: red; margin-top: 0pt;" target="_self"&gt;24407 User authentication against Active Directory failed since user is required to change his password&lt;/A&gt;&lt;/P&gt;&lt;P&gt; : &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Authentication failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS also says this as resolution -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the password expiry under Account options in the properties of an&amp;nbsp; external database user. If the password is expired and the Enable Change&amp;nbsp; Password is turned on in the Users and Identity Stores: External&amp;nbsp; Identity Stores &amp;gt; Active Directory page, then the password will be&amp;nbsp; changed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, our OWA is not configured to allow password resets, so they must call in to have there password reset, or they can connect via VPN and our ASA allows them to change there password as configured under Identity Stores &amp;gt; Active Directory &amp;gt; Enable Password Change&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This VPN password change is successful although OWA still will not work. The only way to fix it is to select passwsord does not expire within AD. Let it replicate, then de-select password does not expire and let it replicate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is pointing to a OWA issue in my opinion, although ACS is somehow involved, is it possible that ACS caches authentication, or because OWA does not allow password resets, it keeps responding with user required to change his password?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts or different ways to look at this from a troubleshooting perspective would be greatly appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:11:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725517#M350378</guid>
      <dc:creator>bradleyordner</dc:creator>
      <dc:date>2019-03-11T01:11:26Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 with Outlook Web Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725518#M350487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have any patches installed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i think you may be encountering the following issue:&lt;/P&gt;&lt;P&gt;CSCtd99822: AD users with expired passwords fail authentication&lt;/P&gt;&lt;P&gt;Description of the issue from the bug is as follows:&lt;/P&gt;&lt;P&gt;1. Create a user account, set the password lifetime to be short, wait for the password to expire&lt;/P&gt;&lt;P&gt;2. They try to authenticate with the expired password.&lt;/P&gt;&lt;P&gt;3. ACS 5.1 does an AD lookup and finds the password is expired.&lt;/P&gt;&lt;P&gt;4. Manually reset the password.&lt;/P&gt;&lt;P&gt;5. Attempt to authenticate.&lt;/P&gt;&lt;P&gt;6. ACS 5.1 still sees their account/password as expired.&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;1. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This issue is solved in Cumulative patch 5.1.0.44.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the patch is relevant you may decide to download and install the latest 5.1 patch: 5.1.0.44.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The patch can be downloaded from CCO&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2011 05:33:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725518#M350487</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2011-06-28T05:33:02Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 with Outlook Web Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725519#M350528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I will have a look and see if I have any patches installed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2011 05:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725519#M350528</guid>
      <dc:creator>bradleyordner</dc:creator>
      <dc:date>2011-06-28T05:34:29Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 with Outlook Web Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725520#M350647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;mmm seems I have lost my CLi password!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You wouldn't know a password recovery process would you? It is on VMWare &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brad&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2011 06:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725520#M350647</guid>
      <dc:creator>bradleyordner</dc:creator>
      <dc:date>2011-06-28T06:14:56Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 with Outlook Web Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725521#M350684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The following is the procedure I am familiar with:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H2&gt;Resetting the Administrator Password &lt;/H2&gt;&lt;P&gt;&lt;A name="wp1078701"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you are not able to log in to the system due to loss of administrator password, you can use the ACS 5.1 Recovery DVD to reset the administrator password. &lt;/P&gt;&lt;P&gt;&lt;A name="wp1078702"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;To reset the administrator password: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;HR noshade="noshade" /&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1078703"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Step 1 &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="5" /&gt;Power up the appliance. &lt;/P&gt;&lt;P&gt;&lt;A name="wp1078704"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Step 2 &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="5" /&gt;Insert the ACS 5.1 Recovery DVD. &lt;/P&gt;&lt;P&gt;&lt;A name="wp1078705"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The console displays: &lt;/P&gt;&lt;P&gt;&lt;A name="wp1078706"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;Welcome to Cisco Secure ACS 5.1 Recovery - CSACS 1121&lt;/CODE&gt; &lt;/P&gt;&lt;P&gt;&lt;A name="wp1078707"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;To boot from hard disk press &lt;ENTER&gt;&lt;/ENTER&gt;&lt;/CODE&gt; &lt;/P&gt;&lt;P&gt;&lt;A name="wp1078708"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;Available boot options:&lt;/CODE&gt; &lt;/P&gt;&lt;P&gt;&lt;A name="wp1078709"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;[1] Cisco Secure ACS 5.1 Installation (Keyboard/Monitor)&lt;/CODE&gt; &lt;/P&gt;&lt;P&gt;&lt;A name="wp1078710"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;[2] Cisco Secure ACS 5.1 Installation (Serial Console)&lt;/CODE&gt; &lt;/P&gt;&lt;P&gt;&lt;A name="wp1078711"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;[3] Reset Administrator Password (Keyboard/Monitor)&lt;/CODE&gt; &lt;/P&gt;&lt;P&gt;&lt;A name="wp1078712"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;[4] Reset Administrator Password (Serial Console)&lt;/CODE&gt; &lt;/P&gt;&lt;P&gt;&lt;A name="wp1078713"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;&lt;ENTER&gt; Boot from hard disk&lt;/ENTER&gt;&lt;/CODE&gt; &lt;/P&gt;&lt;P&gt;&lt;A name="wp1078714"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;Please enter boot option and press &lt;ENTER&gt;.&lt;/ENTER&gt;&lt;/CODE&gt; &lt;/P&gt;&lt;P&gt;&lt;A name="wp1078715"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;boot:&lt;/CODE&gt; &lt;/P&gt;&lt;P&gt;&lt;A name="wp1078716"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Step 3 &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="5" /&gt;To reset the administrator password, at the system prompt, enter 3 if you are using a keyboard and video monitor, or enter 4 if you are using a serial console port. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2011 06:20:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725521#M350684</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2011-06-28T06:20:45Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 with Outlook Web Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725522#M350776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Sir!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2011 06:22:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725522#M350776</guid>
      <dc:creator>bradleyordner</dc:creator>
      <dc:date>2011-06-28T06:22:19Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 with Outlook Web Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725523#M350841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Last question....where can I get the Recovery CD, can I download it from Cisco?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jun 2011 23:10:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725523#M350841</guid>
      <dc:creator>bradleyordner</dc:creator>
      <dc:date>2011-06-28T23:10:36Z</dc:date>
    </item>
    <item>
      <title>ACS 5.1 with Outlook Web Access</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725524#M350906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I am not able to find an external link to download this CD. Suggest to check with account team or similar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jun 2011 05:15:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-with-outlook-web-access/m-p/1725524#M350906</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2011-06-30T05:15:56Z</dc:date>
    </item>
  </channel>
</rss>

