I have Exchange 2003 Enterprise running on a Win2k3 server in a Win2k3
domain. I enabled the OWA change password option this morning and tried it
out - it worked fine. HOWEVER, I did some testing and found out that a
regular domain user CAN CHANGE THE PASSWORD of another domain user. It just
worked. I just typed in the username of another account that I knew the
password for and reset their password. I then logged in to the domain from
another computer to verify that the password had been changed.
What is going on??!?!?!
I have disabled the owa change password option for now, but it is
something I would like to be able to use.
Thanks,
Mike
That sounds normal, you will always be able to logon and change passwords of
users if you know their passwords. You can do exactly the same from a
workstation.
Leif
"Mike55" <Mik...@discussions.microsoft.com> wrote in message
news:A94EDD5C-39AD-44DE...@microsoft.com...