Avatar of awilderbeast
awilderbeast
Flag for United Kingdom of Great Britain and Northern Ireland asked on

OAB NTLM authentication failing, all settings are set to MS recomendations

Hi All,

Some users are getting OAB prompts, ive checked the logs and have attached the event screen.
Event
I have set OAB authentication permissions as per MS recommendations
http://technet.microsoft.com/en-us/library/gg247612
and the OAB permissiosn as per
http://pkjayan.wordpress.com/2010/07/25/downloading-exchange-2010-offline-address-book-fails/

It may be worth noting that our primary email addresses are, ourdomain.com and our actual domain name is ourdomain.co.uk, could it be possible that ourdomain.com is being sent as part as the username for ntlm auth? can we make it do domain\username for OAB? that possible?

THanks
ExchangeOutlookMicrosoft IIS Web Server

Avatar of undefined
Last Comment
awilderbeast

8/22/2022 - Mon
Imtiaz Hasham

Are you using the domain on the username?  e.g. DOMAIN\Username or Username@Domain?
awilderbeast

ASKER
What do you mean using? using where?

when the user gets the prompt we put in domain\username and oab authentciates correctly until next reboot, but after reboot NTLM failures again
Imtiaz Hasham

Thanks for the update?

How do you get it working after the reboot?  I am really confused.

Also, Best Practice is not to use an external domain on an internal network.   I would've used OurDomain.Local (rather than .co.uk) but as long as you put the login credentials as "OURDOMAIN.CO.UK\Username".

The other thing you need to look at is the domain under the NTLM Authentication.
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
awilderbeast

ASKER
After the reboot we have to type credentials in again. this only happens with OAB, all other outlook features work fine.

Changing the domain name is not an option.

yes to bypass the error we use domain\user and it works, but next time the address book tries to download again after a reboot it fails and we get prompted again.

where is the domain under ntlm set?
Imtiaz Hasham

The domain under NTLM wouldnt help.

Have you got any SSL Certificate? And is it trusted root?
awilderbeast

ASKER
Yeah we have a cert installed and it is trusted. OAB doesnt use certificates anyway does it?
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
awilderbeast

ASKER
any update?
Imtiaz Hasham

Sorry for the delay in coming back to you.

Can we arrange for remote access the systems and you can show me where the problem is.
awilderbeast

ASKER
Sorry not possible, can i provide you any more info that may help?
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
Imtiaz Hasham

Please post the OAB prompts you are getting
Imtiaz Hasham

You there?
awilderbeast

ASKER
hi, yes, im just waiting for a user to report the prompt again and i will get a screen, but i can describe it in the meantime

connecting to MAIL
username@domain.com (this is the bit that makes me think its sending domain.com instead of domain.co.uk to the mail server and this is why its failing)

and as shown above you can see the NTLM fail in event viewer.

Thanks
Get an unlimited membership to EE for less than $4 a week.
Unlimited question asking, solutions, articles and more.
awilderbeast

ASKER
heres a screen cap of the prompt edited
prompt
Imtiaz Hasham

I am not sure what's happening and why.  What is the Internal URI and External URI on your exchange server?
awilderbeast

ASKER
Internal URL is: https://mail.domain.co.uk/OAB, only happening for some users, id say ~10-15%
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
ASKER CERTIFIED SOLUTION
awilderbeast

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
awilderbeast

ASKER
outlook profiles recreated