We help IT Professionals succeed at work.

exchange 2007 New machines added to domain cannot use outlook it keeps requesting authentication

BroadSurf62 asked
windows 2003 sp2 exchange 2007 server
When I add a new machine to domain and install outlook we cannot login to outlook it keeps asking for username and password.
Old machines work fine.
Recent change was removing AD and DNS service from exchange server and putting in on a separate win2k3 server.

Only warning on Exchange server

source: MSExchange ADAcess
category: Validation
eventId: 2159

Process edgetransport.exe (Transport) (PID=4360). Configuration object CN=Interop RGC,CN=Connections,CN=Exchange Routing Group (DWBGZMFD01QNBJR),CN=Routing Groups,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN="ourdomain",CN=Microsoft Exchange,CN=Services,CN=Configuration,DC="our domain",DC=an read from "new PDC" failed validation and will be excluded from the result set. Set event logging level for Validation category to Maximum to get additional events about each failure.  

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

On the workstation I see a error

Source: Kerberos Error
Category: none
EventID: 4

The kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/"our PDC". This indicates that the password used to encrypt the kerberos service ticket is different than that on the target server. Commonly this is due to identically named machine accounts in the target realm(dour Domain"), and the client realm.

However I can attach to shared folder on the exchange server with no problem. The only thing that does not work is outlook.
I can even acces Exchange via OWA on this machine.

Checked DNS no error.
All servers and workstations have DNS pointing to DNS/AD server.

Watch Question

AkhaterSolutions Architect

The event you are receiving on the workstation means that the workstation needs to be disjoined/joined to the domain.

Regarding your exchange dcpromo in/out a server running exchange is known to break exchange. I'd suggest you build a new one on a separate server and move everything to it then decomission the one you are using now.


Hello Akhater,

I did joing/disjoin many times with same name or other name still same error.

Are you sure creating new exchange server is the only solution?

AkhaterSolutions Architect

Both issues don't seem to be related. if you just log on the workstation machine without opening outlook can you see the error ?


No the error shows up when the workstation open outlook and tries to connect to exchange server.

As I said before the workstation can use shared folders on the exchange server.

AkhaterSolutions Architect

No I am not sure that only a new exchange server will solve this issue but I know that dcpromo out / in a server running exchange will break the latter and the following technet article confirms it


You can, of course, wait a longer on this forum for others' input or open a PSS ticket but that's what I would have done.
I'm still at a loss with this issue. It keeps creeping up whenever I add a new machine to the domain.
I have to input the full servername that is reported by the DNS a couple of times while attempting to connect to Exchange. And if I'm lucky it comes in.
I verified my DNS server and it is ok. I think I will have to buy anew server to move create a new exchange server.


Did not get satisfactory solution. Still searching