Solved

Outlook Anywhere Authentication Issue NTLM/Basic

Posted on 2013-07-02
13
3,154 Views
Last Modified: 2013-07-31
Hey,

I have configured Outlook anywhere to run NTLM Authentication  but the settings on the local outlook keep reverting back to basic to which point Outlook stops working. I believe I have checked all the settings and look via the exchange command shell to which all have shown the correct NTLM setting.

Any ideas why the outlook client would keep reverting back to Basic Authentication

Thanks
0
Comment
Question by:Dan130
  • 7
  • 5
13 Comments
 
LVL 2

Expert Comment

by:JayCarter82
ID: 39292981
Are the settings on the local Outlook being governed by a GPO? If so that would be where I'd start.
0
 
LVL 1

Author Comment

by:Dan130
ID: 39293294
Hi Jay,

I double checked by no GPO is controlling the local outlook config.
0
 
LVL 1

Author Comment

by:Dan130
ID: 39296170
any ideas on this ?
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39296489
Do an Autodiscover test from a client first:
http://semb.ee/adt

See what is being returned to the client by the server.
How did you change the authentication settings? In EMC, EMS or IIS? Did you run IISRESET afterwards?

Simon.
0
 
LVL 1

Author Comment

by:Dan130
ID: 39297491
Hi Simon,

I have changed the settings in the EMC and EMS, I didn't touch the IIS manager. I have not run an IIS reset recently on the exchange server. the settings appear fine in both EMC and EMS both are set to NTLM but something is setting it back to basic so user cannot then log in to outlook.

the results. I can see in XML it says <OWAUrl AuthenticationMethod="Basic, Fba">https://mydomain.local.

is this related?

ill continue to review your webpage linked but its their anything else to try.

Thanks
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39297954
No, that isn't correct.
When you run the test you should see a line for Outlook Anywhere.

It will say Protocol: Exchange HTTP and then further down Auth Package. That is what Exchange is configuring the client to use.

Simon.
0
Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

 
LVL 1

Author Comment

by:Dan130
ID: 39299268
ok thanks yes I can see that's the Auth Package is "unspecified" how would I go about changing this. if this is unspecified is this why it keeps reverting back to basic?
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39299519
That is probably the problem - it hasn't been configured correctly.
Your best option here is probably to disable and then re-enable Outlook Anywhere. You can do that through EMC. However you must wait until the event log on the server reports that it has been disabled (About 15 minute after making the change in Exchange) before enabling it again.

Simon.
0
 
LVL 1

Author Comment

by:Dan130
ID: 39299521
this is what I also got when using the command get-outlookanywhere
outlookanywhere.PNG
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39299536
Do you have the RPC virtual directory in place?
It might be that there is an issue with IIS instead.
In that case, disable Outlook Anywhere in Exchange, wait for the event log.
In Roles and Features, remove the RPC Proxy component from IIS.
Run IISRESET.
In IIS manager, remove (if present) the RPC and RPC-with-cert virtual directories.
Run IISRESET again.
Reinstall the RPC Proxy.
Finally enable Outlook Anywhere.

Simon.
0
 
LVL 1

Author Comment

by:Dan130
ID: 39299553
Ok I have disabled outlookanywhere

removed the RPC proxy
run iisreset
I have removed RPC and RPC with cert as they were both present
run iisreset

are removing the role the server needs a restart during the day i will not be able to preform this on a live server, so will need to restart exchange install the feature and then enable outlookanywhere
0
 
LVL 1

Author Comment

by:Dan130
ID: 39300320
Followed as planned but still the issue persists. the issue does look related to IIS rather than EMC all of the correct settings are in place.
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 260 total points
ID: 39303826
You are getting the same issue - the authentication setting is coming back as unspecified?
That is unusual, and would point at an issue with the IIS metabase. The only way I know to fix that is to remove IIS completely. That means removing the CAS role on Exchange first.

Simon.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
Local Continuous Replication is a cost effective and quick way of backing up Exchange server data. The following article describes the steps required to configure Local Continuous Replication. Also, the article tells you how to restore from a backup…
In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now