TMG not logging correct authentication

Hello,

I have rather a strange issue where I cant seem to find any logs on any of my servers including TMG. I can log in using AD credentials to various sites we have which rely on the same TMG servers and AD servers perfectly fine with all accounts. However when I have an account which the password is going to expire in a month (4 weeks) the users are unable to log in to the OWA site and get a message stating:

"You could not be logged onto the Forefront TMG. Make sure that your domain name, user name, and password are correct, and then try again."

However if I use the same credentials on one of the other sites the account works fine as the account is still active and has not yet expired. The users are in different physical locations and different OU's but on the same AD servers and TMG. The issue is not present with accounts which have had a recent password reset or are out of scope for a password expiration within a month. In other words if they have an expiry date longer than a month they can log in to OWA perfectly fine.

The TMG will log traffic which is authenticated on OWA and I can see this on the IIS servers and DC's as well. However with the expiring account I see nothing on the TMG, IIS or DC's. The same thing happens if I fail authentication purposefully on a live account (one not expiring in the next 4 weeks). I am not sure where to go as I have no logs to look through so I cant see the issue to resolve it.The other sites which are working as published on the TMG as well which work find regardless of expiration date approaching.

Does anyone else have this issue or any ideas on where to go?

I hope this all makes sense.

Thanks in advance

James


  • Edited by SMBC4100 Monday, March 02, 2015 4:45 PM
March 2nd, 2015 12:39pm

Hi,

What's the version of your TMG? You could check the KB below.

FIX: "You could not be logged on to Forefront TMG" error message when you try to log on to a published website after a domain name is not provided in the authentication settings for LDAP servers in the New Web Publishing Rule Wizard

https://support.microsoft.com/kb/2579940?wa=wsignin1.0

Best Regards,

Joyce

Free Windows Admin Tool Kit Click here and download it now
March 3rd, 2015 6:12am

Joyce,

Thank you for that link it is essentially describing everything with the exception of the following statement:

" Then, you leave the Type the Active Directory domain name (use the fully-qualified domain name) setting blank. "

Ours has the FQDN filled in. I have looked at the resolution and we have SP2 Rollup 4 on our server currently.

Oh and we are running TMG 2010.

Do you have any other suggestions?

Thanks

James


  • Edited by SMBC4100 Tuesday, March 03, 2015 10:45 AM
March 3rd, 2015 10:43am

Just to add some more we have found to this if we click on the change password after logging on check box and then just click continue without filling in any of the other fields it allows us to go straight into the mailbox. Yet when trying to log on with the correct credentials it doesn't.

Does anyone have any idea's on how this could be rectified?

Thanks

James

Free Windows Admin Tool Kit Click here and download it now
March 6th, 2015 8:37am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics