Maybe I am missing something but I think this is what I already have in place... Basic and Windows are enabled in IIS on the OWA directory.
Main Topics
Browse All TopicsI am logging into OWA on my Exchange 2007 server and it is working...however, it is asking for me to login twice. The first page looks like the ISA Server form and the second looks like the Exchange OWA form. I am guessing that something is wrong with ISA passing the Auth to Exchange but I am not sure exactly where it is breaking down. In ISA, under Auth Delegation it is set to "No Auth - but the client can Auth Directly" and in the listener, it is set to HTML form Authentication with Windows (AD) selected below that. Any advice?
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Hi, please check http://www2.cit.cornell.ed
or either reset from AD
Please check configuration as below http://www.msexchange.org/
OPEN IIS Console
Expand your "Web Sites"
2) Right click on "OWA" => "Properties" and select the "Directory Security Tab". Click on "Edit" under "Access control and authentication control" (Should be the first box)
3) Make sure ONLY anonymous access is selected.
4) Expand "OWA"virtual directory.
5) Right Click on the "bin" => "Properties" and select "Directory Security" tab. Click on "Edit" under "Access control and authentication control" (Should be the first box)
6) Make sure ONLY anonymous access is selected.
Let me know what you find and if this helps. You may need to restart IIS after making the changes...
from cmd iisreset
Not sure if this makes a difference but I acctually have another ISA Server and another Exchange server in another site on another IP address. It is working fine. This one, for some reason, has all the same settings (that I can tell) (I moved my Exchange Server back to forms based Auth since that is what the one that is working is as well) but it is prompting for two loggins. Something have to be different.
No...the mailbox is on the server I am going to. I am having an issue where the CAS server is not working so I can't get to mailboxes on the other servers. But if I go to the external URL associated with the ISA / Exchange config, it works. I just have to log in twice on the one pair that I am trying to fix.
May be and you may add it in OWA publishing rule :
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"><meta name="ProgId" content="Word.Document"><m
You can remove roles without rebuilding. http://technet.microsoft.c
If it's a mailbox server I would suggest removing the CAS role and creating a new server with the CAS role only and then publish this with ISA
please
What happens when you do this:
Test-OwaConnectivity URL https://url.com/owa -MailboxCredential (Get-Credential domain\user) -TrustAnySSLCertificate -Verbose
and
Test-WebServicesConnectivi
+ The mailbox that we are trying to access is that a E2K3 mailbox?
+ When we try to browse OWA do we use /owa or /exchange to browse?
+ FBA should be enabled on any one of the servers ISA/E2K7
+ Do you have any E2K3 servers in your ORG??
+ If yes, check with the authentication setting for ExchWeb as well it should be Anonymous
Please check with the above questions and let us know
Does this tell you anything:
[PS] C:\Windows\System32> Test-OwaConnectivity https://tismail.ldichina.c
-Mai
VERBOSE: Test-OwaConnectivity : Beginning processing.
VERBOSE: The TrustAnySSLCertificate flag has been set. The task will not verify
that the server certificate is valid before it sends the user requests and
credentials to this server.
User credentials will be used for user: ldi\test1
Do you want to test Outlook Web Access connectivity on Client Access server
LDI-MSG-02.LDi.LDiCh
VE
test instance for URL 'https://tismail.ldichina.
-URL argument.
VERBOSE: Test-OwaConnectivity : Starting test. Target URL =
'https://tismail.ldichina
VERBOSE: Test-OwaConnectivity : The TrustAnySSLCertificate flag was specified.
Therefore, any certificate will be trusted.
VERBOSE: Test-OwaConnectivity : The Test-OwaConnectivity cmdlet is sending an
HTTP GET logon request without credentials for authentication type
verification.
VERBOSE: Test-OwaConnectivity : The HTTP request succeeded with result code 200
(OK).
VERBOSE: Test-OwaConnectivity : The logon page is from Microsoft Internet
Security and Acceleration (ISA) Server, not Outlook Web Access.
VERBOSE: Test-OwaConnectivity : Microsoft Exchange reported that it supports
authentication method FBA.
VERBOSE: Test-OwaConnectivity : This virtual directory URL type is External or
Unknown. Therefore, the authentication type will not be checked.
VERBOSE: Test-OwaConnectivity : The Test-OwaConnectivity cmdlet is sending an
HTTP request for logon page
'https://tismail.ldich
VERBOSE: Test-OwaConnectivity : Trying logon with method 'Fba'.
VERBOSE: Test-OwaConnectivity : The HTTP request succeeded with result code 200
(OK).
WARNING: The test was unable to log on to Outlook Web Access because of an
authentication failure.
WARNING: The test for URL 'https://tismail.ldichina.
WARNING: column "Error" does not fit into the display and was removed.
ClientAccessServer MailboxServer URL Scenario Result Laten
cy (m
s)
------------------ ------------- --- -------- ------ -----
https://tismail.ldichin Logon Skipped -1
a.com/owa/
VERBOSE: Test-OwaConnectivity : Ending processing.
ahmedabdelba -- not sure I understood what you were saying. I may need more detail.
saakar_rao -
+ The mailbox that we are trying to access is that a E2K3 mailbox? No, everything is Exchange 2007 running on Windows Server 2008 (execpt ISA 2006 running on Windows Server 2003 R2)
+ When we try to browse OWA do we use /owa or /exchange to browse? I have an automatic redirect to /owa. Either way I access it is the same result.
+ FBA should be enabled on any one of the servers ISA/E2K7 - I think it is enabled on both
+ Do you have any E2K3 servers in your ORG?? - No
+ If yes, check with the authentication setting for ExchWeb as well it should be Anonymous
If you have just AIO server and NO exchange 2003 and you are trying to access OWA using /owa and not /exchange then you don't need to have CAS on a different server it is suppose top work.
The only concern that I can find is the FBA enabled on both you just have to make sure that FBA is enabled on one of the servers either ISA or Exchange
Check with Scenario 4 & 5
http://technet.microsoft.c
When you will access an Exchange 2007 mailbox using /exchange it will prompt you for password twice, and redirect to /owa. If you have just E2K7 in your domain why you want /exchange to work?? do you have any Entourage clients?? If not then you don't need /exchange.
/exchweb is also a legacy VDIR.
/public >> what is the error that you get when u try to access /public??
I do have Entourage Clients...
Public says:
Testing URL https://XXX.XXX.com:443/pu
Categ
Error details: The authentication delegation method defined in the rule does not match the authentication method selected for the published directory on the server hosting the site. Publishing rule authentication delegation method: Basic. Published server authentication methods: Forms-Based Authentication.
Action: You can change the authentication method on the published server or select "No delegation, but client may authenticate directly" in the Authentication Delegation tab of the publishing rule.
Check the below TechNet link
Authentication in ISA Server 2006
http://technet.microsoft.c
Business Accounts
Answer for Membership
by: ahmedabdelbasetPosted on 2009-09-16 at 00:21:42ID: 25342782
Hi,
Use basic authentication/integrated on Exchange server and Form based on ISA server .