Can not that be done by anyone who knows someone else's password? If I know user A's password, I log in as user A and change it. What's the difference? Douglas Jensen Douglas.Jensen@xxxxxxxxxxxxx <mailto:Douglas.Jensen@xxxxxxxxxxxxx> Voice (952) 402-9821 Fax (952) 402-9815 Network Administrator Scott Carver Dakota CAP Agency, Inc. 712 Canterbury Road Shakopee, MN 55379 www.capagency.org <file:///C:/Documents%20and%20Settings/djensen.SCDCAP/Application%20Data /Microsoft/Signatures/www.capagency.org> ________________________________ From: Robert Lawson [mailto:rlawson@xxxxxxxx] Sent: Friday, February 17, 2006 3:09 PM To: [ExchangeList] Subject: Soka|OWA 2003|Change Password feature Hello All, We are looking at the OWA 2003 "Change Password" feature for our production environment. The odd thing is it allows "User A" to change the password of "User B", if "User B"'s password is known by "User A". This seems to be a security loophole we don't want to open. Is anyone using the "Change Password" feature that can share their experiences? We are Exchange 2003 SP1 Enterprise shop. 1FE/2BE configuration. Thanks, Robert Robert Lawson Senior Database Administrator/email administrator Soka University of America 1 University Drive Aliso Viejo, CA. 92656 USA main: 949.480.4000 fax: 949.480.4258 direct: 949.480.4224 rlawson@xxxxxxxx