OWA access denied

Posted on 2007-03-21
Last Modified: 2010-04-18
Some of my users periodically travel. When at some locations, not all, and they try to access thier e-mail on my Exchange 2003 server via OWA, they are repeatedly prompted for their password. Finally OWA opens with the folder list pane on the left, however the reading pane is empty and displays access denied. Can someone please tell me what is causing this? Are my users behind a Proxy or firewall at the locations where this happens? How can I get them access to thier e-mail with OWA?

Question by:harold9153
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Expert Comment

ID: 18768855
Might be that ports are blocked on the networks they they are at. Are they accessing from a hotel room or another company's intranet? Ports 80 HTTP and 443 SSL (if you are suing SSL) are required. Does this happen on another company's network only? Also, if you are usiing SSL, is it a certificate you created yourself, or one from 3rd party? If you are using SSL and have created your own certificate, have them try adding the "S" to the http. In other words, "" froman internet browser.

Good luck!  
LVL 77

Expert Comment

by:Rob Williams
ID: 18768949
Just a suggestion; When the users connect, in the logon box there is an option under Client; Premium or Basic. Try the basic option when experiencing these problems. I have found some sites, presumably ones with less than perfect Internet performance, will give you "funky" results or partial displays. Reducing to basic allows proper access, though slightly simpler interface.

Author Comment

ID: 18768994
This has happened at hotels rooms and on other company intranets. I'm not using SSL. I've tried the Basic option in the login box.
Get 15 Days FREE Full-Featured Trial

Benefit from a mission critical IT monitoring with Monitis Premium or get it FREE for your entry level monitoring needs.
-Over 200,000 users
-More than 300,000 websites monitored
-Used in 197 countries
-Recommended by 98% of users


Expert Comment

ID: 18769096
Hmmm....This may be kind of along shot, but are there any other protocols besides TCP/IP bound to the network card? Check the properties of the net card from within My Net Places to make sure that IPX/SPX isn't bound to it. If it is, remove it and restart.

Expert Comment

ID: 18769112
I digress...I guess itwouldn't matter over an Internet Exploder OWA connection.
LVL 104

Expert Comment

ID: 18775150
Any reason you aren't using SSL?
That means your usernames and passwords are going across in the clear. If the users are regularly accessing the server from hotels and the like, then there could be all sorts of things going on. HTTP traffic is also prone to interference from proxies and cache. HTTPS traffic is not treated like that so can provide a better experience.


Expert Comment

ID: 18775453
I agree with Sembee.  I've had some flaky experience running OWA exclusively through port 80.  I've also found that buying a certificate from an outside source is well worth the money.  The self-signed certificates that the server produces can cause problems if the device you are trying to access with cannot (or doesn't) display the "Are you sure you want to trust this site" dialogue.  Also, are your users trying to do anything else besides access OWA?  If they are using SharePoint you have to open up port 444 as well.

Author Comment

ID: 18776471
I solved this and here's how. I have a Cisco 3000 VPN Concentrator to which my users often use make a connection to the internal LAN with the Cisco IPSec VPN client. I turned on the WebVPN feature on the Concentrator.

(In a WebVPN connection, the VPN Concentrator acts as a proxy between the end user's web browser and target web servers. When a WebVPN user connects to an SSL-enabled web server, the VPN Concentrator establishes a secure connection and validates the server's SSL certificate. The end user's browser never receives the presented certificate.)

The users types the public IP of the Concentrator in their browser to connect to the WebVPN. The VPN Concentrator creates a self-signed SSL server certificate when it boots that they have to accept. They login to the WebVPN using the same credientials as when they use the regular Cisco IPSec VPN client. Another screen come up into which they enter the URL for our OWA. Now then I'm not using SSL on my OWA server (though I am taking others advice and intend to) however OWA comes up without a problem. I suppose this "fools" any proxies, caches, etc.

Any thoughts?

Accepted Solution

Computer101 earned 0 total points
ID: 19338680
PAQed with points refunded (500)

EE Admin

Featured Post


Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Check out this step-by-step guide for using the newly updated Experts Exchange mobile app—released on May 30.
Compliance and data security require steps be taken to prevent unauthorized users from copying data.  Here's one method to prevent data theft via USB drives (and writable optical media).
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit If you want to manage em…
Suggested Courses

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question