Solved

Certain PCs are promted for a password when opening Office attachments in OWA

Posted on 2012-03-21
12
421 Views
Last Modified: 2012-04-01
A couple of my users are being prompted for their password when they attempt to open up Office documents in Outlook Web Access.  If you enter the username and password several times you can view the document but it only does this for Office types; PDFs, TXTs, etc. open up just fine.  Oddly, if you hit 'Cancel' when prompted for your password you can open Word documents.

Most of the PCs in the office have no problems opening up Office documents in OWA regardless of whether they only have Office 2003 or Office 2010 or the Word and Excel Viewers.

I've removed and re-added the PC to the domain, re-installed IE8, run the MS registry fix that's supposed to set the file types (it's never had a problem opening up a document locally or from the network though), and then also did a number of OWA server fixes like adding the MIME types to IIS, adding the MIME types to Internet Message Formats in Exchange System Manager, and setting the authentication types on the Exchange Virtual Server.

So, because it only affects a few machines, I think it's a local thing, but I can't figure it out either way.

Ideas of what else to try?

It's Exchange 2003 running on Server 2003 SR2 and the workstation in question is running XP SP3 with IE 8.
0
Comment
Question by:kcorbinakc
  • 6
  • 5
12 Comments
 
LVL 17

Expert Comment

by:xtermie
ID: 37750090
You should probably check that the client machines with this behavior, dont have the IE security setting that requires to prompt for username and password.
0
 
LVL 17

Expert Comment

by:xtermie
ID: 37750098
Or also ensure the integraded authentication is set on IIS and that the firewall is set properly so users can connect. Also make sure that those setting are ported to Exchange
0
 
LVL 17

Expert Comment

by:xtermie
ID: 37750104
I also find another answer on a similar issue here, if you want to take a look in case the above suggestions dont work
http://itknowledgeexchange.techtarget.com/itanswers/why-does-owa-prompt-user-continually-for-credentials/
0
 
LVL 8

Expert Comment

by:stevepcguy
ID: 37750117
Just out of curiosity, have the user passwords expired, or close to expiration? We had a situation where expired passwords were the culprit.
0
 

Author Comment

by:kcorbinakc
ID: 37750211
No, the setting 'Prompt for user name and password' is not checked in IE Settings.

Integrate authentication is enabled in IIS and the firewall is fine.  The affected machines are on the local intranet checking other users mailboxes like so: http://exchange/exchange/username

The user's mailboxes they are checking haven't expired their passwords, in fact they are set to never expire.

I do think it's possibly related to anonymous authentication actually.  I did some testing logging in into OWA when logged into the local machine as the user who owns the mailbox, and then as a different user.  When logged in as the actual user (so it's using Windows authentication) I was able to open Office documents in OWA just fine.  When logged in as a different user and then opening OWA I was prompted for the username and password again when trying to open the Office docs.  If I put the username and password in I am able to open the documents though.  If I simple click 'Save' rather than 'Open' I can save the document though without additional prompting.
0
 
LVL 17

Expert Comment

by:xtermie
ID: 37750229
As it seems this is not an OWA issue but rather an issue with opening any Office attachment where it is accessed via a URL. It may happen to Office 2003 and later version.  There's related KB 838028 talks about the reasons why Office is prompting for credentials. The explanation is under the "Identifying known drawbacks that are caused by Office Protocol Discovery" section (second paragraph).

You can try getting the latest service packs and hotfixes for office 2003 and
office 2007.

You are prompted for credentials every two weeks when you try to view
a Web resource in Office 2003
http://support.microsoft.com/kb/916658

Description of the 2007 Office system hotfix package: June 26, 2008
http://support.microsoft.com/kb/954573

How documents are opened from a Web site in Office 2003
http://support.microsoft.com/kb/838028
0
Are end users causing IT problems again?

You’ve taken the time to design and update all your end user’s email signatures, only to find out they’re messing up the HTML, changing the font and ruining the imagery. What can you do to prevent this? Find out how you can save your signatures from end users today.

 
LVL 17

Expert Comment

by:xtermie
ID: 37750231
I also found this on a discussion on the same problem, a while back:
Workaround (it can pose some security risk):
1.       Added the registry values to the "KnownContentTypes" (server)
HK_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSExchangeWEB\OWA
+ application/msword
+ application/vnd.ms-excel
 
Related KB:KnownContentTypes registry entry
http://support.microsoft.com/?kbid=873138
 
2.       Added the registry values (server)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSExchangeWEB\OWA"
a.       Remove "application/octet-stream" from the Level2MIMETypes value
b.      Add "application/octet-stream" to the KnownContentTypes value
c.       restart the Microsoft Exchange System Attendant
0
 
LVL 17

Expert Comment

by:xtermie
ID: 37750237
One more article that may have the solution
http://support.microsoft.com/kb/955375

and this comment
I was able to correct my continuous credential request issue by adding the exchange server under trusted sites and then customizing the security for Trusted sites to use the same username and password every time.
Worked like a charm!  Just wanted to say THANKS!!
0
 

Author Comment

by:kcorbinakc
ID: 37750308
I did already try adding it to the KnownContentType to the OWA Admin interface with no success.  I'll have a chance to look at the others more in-depth tomorrow when I get back in the office.
0
 

Author Comment

by:kcorbinakc
ID: 37753866
I already have the local subnet and domain names specified in Intranet sites through Group Policy.

I also tried resetting the IUSR and IWAM system account passwords and synchronizing them in IIS Manager.

I tested another couple of machines, and so far the problem only seems to exist on the machines with Office 2010 installed.  The one's with Office XP or only the Word and Excel  2007 viewers don't have the problem.  This may be coincidental, but I think it's a key to the issue.

People with the same issue: http://social.technet.microsoft.com/Forums/en-US/officeappcompat/thread/91a1708d-4ae6-450e-a9b9-32f1e872c629/

The only thing that throws this off is that my PC has 2010 installed but doesn't have the same problem.
0
 

Accepted Solution

by:
kcorbinakc earned 0 total points
ID: 37754913
Well, I never figured it out and expediency made me find a work-around.

I even wiped and then re-imaged a machine and it didn't work.  It almost makes me think the PCs that work really *shouldn't* be working.

To get around the problem, I gave the users that need to access the additional mailboxes rights to the mailboxes in question.  Then, it uses Windows pass through permissions and doesn't prompt for a password again when opening up the documents.

I do think it's an intersection of OWA, Office 2010, and the IE registry setting that allows usernames/passwords in URLs.
0
 

Author Closing Comment

by:kcorbinakc
ID: 37792678
Found a work-around
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

Suggested Solutions

Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
The view will learn how to download and install SIMTOOLS and FORMLIST into Excel, how to use SIMTOOLS to generate a Monte Carlo simulation of 30 sales calls, and how to calculate the conditional probability based on the results of the Monte Carlo …

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now