userPrincipalName with IIS security?

From: Dave Williams (davewilliams29_at_yahoo.com)
Date: 09/16/05

  • Next message: paulp: "Re: CGI Problem on MS IIS 5.0 - Trying to access files on other machines"
    Date: Fri, 16 Sep 2005 12:11:13 +0100
    
    

    Hi all, I have an odd issue...

    I have an IIS 6 server (actually running Exchange OWA) and two users, one of
    whom is allowed full access and the other is denied all access. The denied
    user is a member of domains admins and exchange admins, and can log onto a
    mailbox fine using Outlook but not with OWA, the allowed user is just a
    normal domain user but can access their mailbox in OWA no problem.

    Looking through the AD properties of the two users, I found the only
    distinction (apart from one being more administrative) is that the allowed
    user has a 'userPrincipalName' set whereas the failing user doesn't. Is
    there any configuration setting that might be in force on IIS that might
    cause this to happen?

    I'm aware that userPrincipalName is used for Kerberos authentication, but
    not sure what happens if a user doesn't have one (I've done the same thing
    in other environments for users without a userPrincipalName many times).
    Could it be that the IIS/OWA configuration is disallowing NTLM as its
    'integrated' authentication method, so forcing Kerberos and that's failing?

    I've looked around the other configuration options, and can see nothing that
    would explain why one user would connect and the other be refused.

    Any ideas?
    Thanks,
    Dave


  • Next message: paulp: "Re: CGI Problem on MS IIS 5.0 - Trying to access files on other machines"

    Relevant Pages

    • Re: userPrincipalName with IIS security?
      ... My next question is perhaps predictable - what object might have a DENY ACE ... The primary failure was of the OWA website, but the per-user configuration ... I see there's a 'permissions' menu option on the IIS 'default web ...
      (microsoft.public.inetserver.iis.security)
    • Re: 404 (substatus 0) on mail with special chars
      ... The problem is with my OWA, ... is a configuration issue for sure, not a bug in OWA. ... IIS throwing the error, not Exchange. ...
      (microsoft.public.inetserver.iis)
    • IIS web site access
      ... I have an IIS 5 server on windows 2000 and also running exchange OWA ... I have a domain name I would like to use to access OWA with over the ...
      (microsoft.public.inetserver.iis)
    • OWA not working.
      ... under IIS .After configuration of the new website i am able get it from ... If i come under IIS -->default website ... If i stop the new website, the OWA is ...
      (microsoft.public.exchange.admin)
    • RE: no OWA
      ... I understand that you unable to access OWA ... If you do not want to install all the IIS tools on your computer, ... To restart the Microsoft Exchange System Attendant service, ...
      (microsoft.public.windows.server.sbs)