Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


Exchange 2010 OOF and Free Busy authentication from another domain

Posted on 2014-02-13
Medium Priority
Last Modified: 2014-02-23

We're in the middle of a messy migration at the moment. We have purchased another company and have brought them onto our premises. We just basically picked up their whole network and brought it on premises, but they are still in their own little bubble so to speak.

So we have 2 separate networks, with 2 separate Windows 2008 Active Directories, with 2 separate Exchange servers etc.

We have slowly been migrating people across into our environment. Domain A is our environment. Domain B is the company we bought.

We have migrated some computer accounts and domain accounts across to Domain A, whilst leaving their Exchange mailbox in Domain B.

We have also migrated some mailboxes across to Domain A whilst leaving their computer and domain and computer accounts in Domain B.

We weren't going to do a full Federated Trust thing with Cross Forest Migration. We are just exporting their PST from their Exchange 2010 server on Domain B, and importing it into their Domain A mailbox account.

So, the user is logged into a computer that is a member of Domain B, with an AD account that is a member of Domain B. When we configure their Outlook for the Domain A Exchange Server, it prompts for Domain A credentials, and they are good to go. (We have configured them with accounts in both domains).

I've just noticed though that Out of Office is not working, and neither is the Free Busy information.

For people that are logging into their computer using Domain A AD accounts and Domain A Exchange mailboxes, everything works properly. But for people that are logged in as Domain B accounts, this doesn't work.

I've done the Autodiscovery test within Outlook, and I notice that the first thing it does is look for autodiscovery information for Domain B, but then moves onto Domain A and it is successful.

I know this is a messy scenario, but it is necessary for a short period of time until we can sort some things out.

I'm just wondering if it's some sort of permissions thing in IIS for Exchange Web Services, or it's just the fact that this won't work because their AD account is still in Domain B.

I've also tried the registry hack to prefer a local XML file, and used the Autodiscover details for Domain A, but that doesn't work either.

Anyone got any ideas?


Question by:StevenAhmet
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 10
  • 6

Expert Comment

ID: 39858126
What was the exact process for PST email migration?
This has nothing to do with Autodiscover, BTW.

Author Comment

ID: 39858150
Using EMC, "new-mailboxexport request" on Domain B mail server, and "new-mailboximportrequest" on Domain A Exchange server.
Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.


Expert Comment

ID: 39858162
One more thing - how exactly you retargeted MS Outlook 2010 on computers of the migrated users? Did you delete the whole profile, of just changed server?
The setting may be cached in the profile.
Try deleting all profile configuration, then creating anew.

Author Comment

ID: 39858165
I created a new profile. I'm just having a look at that link you posted now.

Author Comment

ID: 39858184
This looks like it will only work if the domains are federated. Is that true?

Expert Comment

ID: 39858198
You should not need to create a trust between domains at this stage.
Have you created new users in the same manner as "normal" residents of Domain A?
Have you checked the Outlook error log?
Have you checked email addresses of migrated users same as residents?

Author Comment

ID: 39858225
Yes, new users are created in the exact same way.

After enabling Outlook logging, I can see when I try to access Out of Office, I'm getting a HTTP 500 error.
The response says "Unable to access an account or mailbox".

I looked at this;

The hotfix was already installed. I added the Registry entry. I had to create the "Security" key folder, then the WinhttpAuth DWORD, but still no go.

I'm still getting the same error in logging.

Author Comment

ID: 39860923
Just wanted to make sure I add that;

1) Everything works correctly using OWA, (for all users). I can see Free/Busy info for all users and set OOF correctly.
2) Out of Office/Free Busy works correctly for all users logging into the Domain A domain.

I thought for sure that MS article was going to be the ticket as it describes the situation perfectly......"You open a mailbox profile in Microsoft Outlook 2010 by using credentials that are different to the credentials that you used to log on to Windows."

But still no go. Any further help would be appreciated.


Expert Comment

ID: 39860982
If you are using an internet proxy AND it is able to reach your CAS role, try removing CAS from proxy exception list.
Try Outlook 2013. Do you have latest patched on Office And Exchange?

Author Comment

ID: 39863218
No internet proxy.
Office 2010 and Exchange are patched.

We don't have Outlook 2013 anywhere in the organisation so can't try it.

Author Comment

ID: 39863242
**Update: I've done another test;

1) Removed the computer from Domain B so it is just in a workgroup. Not added into any domain.
2) Logged in as a local administrator of the computer.
3) Configured Outlook to use the same Domain A mailbox I've been testing with.

Out of Office and Free/Busy both work. Not sure where to go from here now.

Author Comment

ID: 39863310
OK, so I added the computer back to Domain B.
Logged in as the Domain B user.
Opened up Outlook again that is configured with the Domain A mailbox.
And now it works!!

I just have to try it now with some user's actual computers.

Accepted Solution

StevenAhmet earned 0 total points
ID: 39869075
OK, I worked it out. It was working on some machines and not on others.

I was testing with a machine that I had removed from all domains so was just connected to a Workgroup.

I won't go into the series of events that led me to my answer, but it had to do with network profiles, ie Public and Work, turning Firewalls on and off, allowing Outlook through the firewall etc.

I then got to Control Panel\User Accounts\Stored Credentials. On one particular machine, it prompted me for the domain credentials of the mailbox which I know I had previously entered. So I checked in my Stored Credentials and saw a lot more entries than I was expecting.

I checked Outlook to see if OOF and Appointments were working, and lo and behold, they were.

So I removed the following from Stored Credentials;

Windows Credentials   <- This was the FQDN of the mail server
With their DOMAIN\Username and password

Generic Credentials
With their DOMAIN\username and password

Once this was removed, it stopped working.
If I added them back, it worked again.

The only thing I can think of, is that there was something firewall related that was stopping contact to the mail server, which then should have asked for authentication.

So, I can add these entries manually into the computers that I need to and it all works!

Expert Comment

ID: 39869097
I do not think this was firewall-related.
This is definitely credentials you mentioned.
Outlook+Exchange uses complex combination of protocols to different destinations, and all works great once you are in a trusted domain.
Once you are out of trusted domain, you rely sorely on user's stored or entered credentials for auth to each proto/destination pair.
not all protocols are able to detect account conditions like : password expiry, password incorrect, account locked etc.
Not all code in Outlook is able to process error codes correctly and raise appropriate GUI warnings/dialogs. Obviously this is the case in OoO and Free/Busy info.
What you found is a good solution, but you should also test what happens if user's password is expired and needs to be changed in Domain A while they are working on PCs in Domain B. Or the incorrect logins leading to account lockouts.

I have had a similar case where domain-based DFS namespace was redirecting non-domain computer/users to different individual servers but users had no stored credentials for those.
The MS DFS code was not handling redirects to file shares in the same user context as for the original DFS namespaces. I had to get rid of DFS and use a simple single file share. Joining domain was not an option since many devices were BYO and had non-Pro Windows 7/8 versions installed.

IMO you ought to focus efforts on completing the migration, at the same time let Domain B users know of possible issues and workarounds.

Author Closing Comment

ID: 39880399
None of the answers provided by the one other expert were helpful in the solution.
I got to the solution on my own.

Featured Post


Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
Want to know how to use Exchange Server Eseutil command? Go through this article as it gives you the know-how.
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
This Experts Exchange video Micro Tutorial shows how to tell Microsoft Office that a word is NOT spelled correctly. Microsoft Office has a built-in, main dictionary that is shared by Office apps, including Excel, Outlook, PowerPoint, and Word. When …
Suggested Courses

704 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question