Link to home
Start Free TrialLog in
Avatar of Panda 5888
Panda 5888

asked on

POP3 authentication problem - Exchange 2003

Environment:
- AD 2003 SP2
- Exchange 2003 SP2
- Outlook 2003 SP3

IT happened many months ago where a few users can't login to their POP3 account, via Outlook, mobile phone, tabletPC, etc. The issue was never resolved, those users switched to RPC/HTTPs/OWA

And more and more users are having the problem.

If I create a new user, the new users will not have this problem

 User generated image
There is no event error logged on the Exchange server, AD server or the PC.

I have no clue what is going on.

Please help.
Avatar of Mike Thomas
Mike Thomas
Flag of United Kingdom of Great Britain and Northern Ireland image

What format are the users typing their user names? if just "username" try username@domain.local (where domain is the Domain name where the user account belongs not the email domain name)
Avatar of Panda 5888
Panda 5888

ASKER

I have tried <user_id>@domain.com, domain\user_id and also just user_id ... all doesn't work.
it used to work with just user_id ...

FYI I have actually installed a new Exchange 2003 server, move all mailboxes over to the new server and remove the old Exchange 2003 server, yet some of our users still have this problem ...
Have you actually started the default POP3 virtual server on the new exchange box? and set the authentication type that the users should use? and are the users connecting to the new server? check these things next.

yep ... POP3 virtual server is on, authentication set to basic ... we have been using that same setting for years. But now 2 out of 10 users can't login to POP3.   8 will have no problem...
Then there must be something about these 2 out of 10 users, cached credentials? try password resets, double check details, double check connectivity to the new exchange servers, try to find the common denominator really. Check the obvious as we sometimes dismiss that without reason.
The only thing that I think is consistent is the user_id(AD) itself ... ..  because the same user can't access POP3 from any PC, mobile phone(Android, Iphone, etc), tabletPC ....  but another user can access POP3 from those same PC, mobile phone(Android, Iphone, etc), tabletPC. But there is no event viewer error, I have no idea where to drill into. ..
I just read this tip

Try loggin in with the username "DOMAIN\ACCOUNT\ALIAS"

If the mailbox alias is not the same as the domain account name this might be the issue here...so check that for a user after you test.

amazing ... .yr suggestion actually resolved 1 user's problem, he has a different alias, so I have changed his alias to be same as his user_id, it is working for him now..

but another 2 users aren't so lucky, both of them has a user_id = alias .... they still have POP3 problem.
I remember changing their alias to something else sometimes ago, but I have changed it back to be the same as their user_id back then....
Well that's a start, you possibly have a few issues here so it might be worth checking the alias thing out for all the users and seeing what's is left to fix then we can deal with that after, also have any of these users been migrated to or imported to the domain?
thanks...
hmm no, we only have 1 forest, 1 domain .. it is a fairly simple environment here. I'll get that 2 users to try DOMAIN\ACCOUNT\ALIAS later....
the 2 users tried DOMAIN\ACCOUNT\ALIAS, it didn't work. .... .weird !!

My mailbox Account ID and Alias is different, but I can just login with account_id@domain.com ...
I found that if I do not enable "Anonymous" authentication on Exchange 2003 front-end SMTP virtual server, the 2 users cannot send emails via SMTP. All other users can...
Error as such  
User generated image
User generated image
I don't think enabling  "Anonymous" authentication on Exchange 2003 front-end SMTP virtual is a good idea..... any ideas?
haha.jpg
No do not enable anon, is it just these 2 users who are havng issues now?
yes 2 users .... when I enable anon, everything can go thru the SMTP virtual server ....including the 2 problem users. .... if I disable anon, the 2 problem users will not be able to send emails via the front-end server .... I tried connecting them to the back-end server, they are able to send emails via the back-end server.
So I guess something is wrong between the front-end and back-end server, for these 2 users.. ..

Try just a password reset for this users? might go as far as recreating their accounts in AD, then reconnect old mailboxes to them etc, unless you can figure out what is different about these 2 users.
ASKER CERTIFIED SOLUTION
Avatar of Panda 5888
Panda 5888

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
no comment