Quantcast
Channel: Exchange Server 2013 - Setup, Deployment, Updates, and Migration 论坛
Viewing all 7008 articles
Browse latest View live

Public Folder Migration from two Exchange 2010 Public folder databases to Exchange 2013

$
0
0

 Hello,

 I'm trying to migrate two Public folder databases from Exchange 2010 to Exchange 2013 but the migration script accepts only one source mailbox server and after migrating first database from 2010, Exchange 2013 not accepting the other database migration

 please advise 

 thx


Exchange 2013 SP1 Installation

$
0
0

Hello

After installation on windows domain server/controller 2012 R2.

I got this message:

VERBOSE: Connecting to GolfServer.GOLFKLUB.local.
New-PSSession : [golfserver.golfklub.local] Connecting to remote server golfserver.golfklub.local failed with the follo
wing error message : The WinRM client cannot process the request. The WinRM client tried to use Kerberos authentication
 mechanism, but the destination computer (GolfServer.GOLFKLUB.local:80) returned an 'access denied' error. Change the c
onfiguration to allow Kerberos authentication mechanism to be used or specify one of the authentication mechanisms supp
orted by the server. To use Kerberos, specify the local computer name as the remote destination. Also verify that the c
lient computer and the destination computer are joined to a domain. To use Basic, specify the local computer name as th
e remote destination, specify Basic authentication and provide user name and password. Possible authentication mechanis
ms reported by server:   Digest Negotiate For more information, see the about_Remote_Troubleshooting Help topic.

I tried to find solution on many forums and I also check other erros in Event Log and Kerberos...

I also cannot connect to Administration center.

Can anyone help me, please.

Thank you very much

Sharing contacts and calendars between Exchange Online and On-Premises Exchange Server (different domains)

$
0
0

Is it possible for 2 domains to shared Contact list / calendar items if 1 domain is using Exchange Online, while there other domain is using a On-Premises Exchange Server? Both domains will be on different forest. If it is possible, what are the versions of Exchange Server are needed, and what are the licenses needed?

Migrating to Exchange 2013 from 2007. In Coexistence and receiving routine event errors.

$
0
0
We are in the process of upgrading our Exchange environment to 2013 and are currently running 2013/2007 in coexistence. The 2013 server has only 4 mailboxes on its database that we are testing with before migrating everyone and taking 2007 offline. The server is running Mailbox and CAS roles. Currently mail flow is working, but we receive the following event errors routinely. Also, OWA works but the login is slow. I’m looking to get these ironed out before moving over users. Any insight is greatly appreciated because I'm stumped. I have managed Exchange since version 5 and this is the first time I've had issues that were not easily resolved. 
-----
Source: MSExchange Autodiscover 
Event ID: 1
Task Category: Web
Unhandled Exception "Active Directory operation failed on Global Catalog. This error could have been caused by user input or by the Active Directory server being unavailable. Please retry at a later time. Additional information: Active directory response: The operation was aborted because the client side timeout limit was exceeded. ." 
Stack trace: Microsoft.Exchange.Data.Directory.ADPossibleOperationException: Active Directory operation failed on Global Catalog. This error could have been caused by user input or by the Active Directory server being unavailable. Please retry at a later time. Additional information: Active directory response: The operation was aborted because the client side timeout limit was exceeded. . ---> 
System.DirectoryServices.Protocols.LdapException: The operation was aborted because the client side timeout limit was exceeded.     
at System.DirectoryServices.Protocols.LdapConnection.ConstructResponse(Int32 messageId, LdapOperation operation, ResultAll resultType, TimeSpan requestTimeOut, Boolean exceptionOnTimeOut)    
at System.DirectoryServices.Protocols.LdapConnection.SendRequest(DirectoryRequest request, TimeSpan requestTimeout)    
at Microsoft.Exchange.Data.Directory.PooledLdapConnection.SendRequest(DirectoryRequest request, LdapOperation ldapOperation, Nullable`1 clientSideSearchTimeout, IActivityScope activityScope, String callerInfo)    
at Microsoft.Exchange.Data.Directory.ADDataSession.InternalFind[TResult](ADObjectId rootId, String optionalBaseDN, ADObjectId readId, QueryScope scope, QueryFilter filter, SortBy sortBy, Int32 maxResults, IEnumerable`1 properties, Boolean includeDeletedObjects)   --- End of inner exception stack trace ---    
at Microsoft.Exchange.Data.Directory.ADDataSession.AnalyzeDirectoryError(PooledLdapConnection connection, DirectoryRequest request, DirectoryException de, Int32 totalRetries, Int32 retriesOnServer) 
at Microsoft.Exchange.Data.Directory.ADDataSession.InternalFind[TResult](ADObjectId rootId, String optionalBaseDN, ADObjectId readId, QueryScope scope, QueryFilter filter, SortBy sortBy, Int32 maxResults, IEnumerable`1 properties, Boolean includeDeletedObjects)   
at Microsoft.Exchange.Data.Directory.SystemConfiguration.ADConfigurationSession.GetFederatedOrganizationId(ADObjectId rootId)    
at Microsoft.Exchange.Data.Storage.ExchangePrincipalExtensions.ReadSharingPolicy(ExchangePrincipal exchangePrincipal)    
at Microsoft.Exchange.Autodiscover.ConfigurationSettings.UserSettingsProvider.GetUserSettings(HashSet`1 requestedSettings, IBudget budget)    at Microsoft.Exchange.Autodiscover.WCF.ADQueryResult.CreateResponseFromQueryResult(IBudget budget) 
at Microsoft.Exchange.Autodiscover.WCF.ADQueryResult.CreateResponse(IBudget budget)    
at Microsoft.Exchange.Autodiscover.WCF.GetUserSettingsCommandBase.Execute()    
at Microsoft.Exchange.Autodiscover.WCF.GetUserSettingsRequestMessage.ExecuteCommand(IIdentity callerIdentity, CallContext callContext)    
at Microsoft.Exchange.Autodiscover.WCF.GetUserSettingsRequestMessage.ExecuteGetUserSettingsCommand(IPrincipal callingPrincipal, CallContext callContext)    
at Microsoft.Exchange.Autodiscover.WCF.GetUserSettingsRequestMessage.Execute()
-----
Source: Perflib
Event ID: 1023
Task Category: None
Windows cannot load the extensible counter DLL ASP.NET_64_2.0.50727. The first four bytes (DWORD) of the Data section contains the Windows error code.
-----
Source: Perflib
Event ID: 1023
Task Category: None
Windows cannot load the extensible counter DLL ASP.NET_2.0.50727. The first four bytes (DWORD) of the Data section contains the Windows error code.
-----
Source: MSExchangeTransportDelivery
Event ID: 1040
Task Category: SmtpReceive
The SMTP availability of the Receive connector Default Mailbox Delivery was low (0 percent) in the last 15 minutes.
-----
Source: MSExchange ADAccess 
Event ID: 4028
Task Category: General
Process w3wp.exe (AutoDisc) (PID=16568). The budget for user 'Sid~Domain\user~Ews~false' has been unlocked.
-----
Source: MSExchange ADAccess
Event ID: 4101
Task Category: General
Process w3wp.exe (AutoDisc) (PID=16568). The following actions exceeded maximum time limit:  CostType: CAS, Key: -9223372036854767960, Limit: 00:05:00, Elapsed: 00:17:56.8142620, Actions: 6, Description: Caller: LegacyBodyWriter.OnWriteBodyContents, ThreadID: 1071, PreCharge: 0ms, Snapshot: Owner:Sid~Domain\user~Ews~false,Conn:3,MaxConn:27,MaxBurst:300000,Balance:$null,Cutoff:-3000000,RechargeRate:900000,Policy:AllUsersEWSPolicy,IsServiceAccount:False,LiveTime:04:20:38.4884143
-----
Source: MSExchange Common
Event ID: 4999
Task Category: General
Watson report about to be sent for process id: 16568, with parameters: E12IIS, c-RTL-AMD64, 15.00.0847.032, w3wp#MSExchangeAutodiscoverAppPool, M.E.Data.Directory, M.E.D.D.Budget.CheckLeakedActions, M.E.D.Directory.LongRunningCostHandleException, e70, 15.00.0847.031. ErrorReportingEnabled: False
-----
Source: MSExchange Mid-Tier Storage
Event ID: 10006
Task Category: (10)
Active Manager Client experienced an AD timeout trying to lookup object 'Exchange Server' in 00:01:00.
-----


Duplicate Contacts when migrating mailboxes to exchange 2013 SP1 CU7

$
0
0

Hello,

We started to notice that when we move a user from our legacy exchange 2007 to exchange 2013, the contact list appears twice for users.  I heard CU6 was suppose to fix this issue but we went ahead and downloaded the latest version and we are still seeing this.  Can anyone provide guidance on how to stop this for the remaining migrations?

Thanks

Exchange 2013+Wildcard SSL=External URL not working

$
0
0

Hello,

We have 1 Exchange 2013 server sitting in the company LAN.

hostname: exch.domain.com

CNAME is configured as mail.domain.com and internal clients can connect to both

External clients cannot access our OWA via HTTPS. Internally all services are working fine and users are able to access OWA.

When a client connects to 

https://mail.domain.com/owa - accessed from an Internet - does not work

https://mail.domain.com/owa - accessed from an LAN - works fine

Diagnostics so far:

Wireshark:

External client connects and sends ClientHello packet but server is not responding with ServerHello. Clients retry several times and then it's timing out. On a client's web browser, it shows "Cannot display the page"

ECP:

All  virtual directories have External URL configured with correct URL for example OWA has https://mail.domain.com/owa

"Configure external access domain" option: I cannot add my local exchange as CAS. When I click on save, it goes to blank boxes.

SSL

We use wildcard certificate from Comodo that has been regenerated already but it did not make any difference.

There are no SSL errors when exchange web services are access locally so I would assume that SSL is working fine.

Event logs

no SSL errors 

NAT/Network/Firewall

port 443 is open and mapped to the exchange server. Windows firewall is off.

I am sure that there is something obvious that I have been missing.

Any tips would be greatly appreciated.

Thanks

Konrad

Exchange Server 2013 setup to relay with external mail server

$
0
0

We've currently installed a new Exchange Server 2013 (NOC 1 internal corp mail behind firewall) however currently use an external  mail Server (NOC2) IMAP POP3/SMTP for clients to authenticate and download and relay (SMTP) their e-mail. I'm looking for advise on how to effectively maintain the current Server performing primary scanning/anti virus & RBl filtering and relay, post scanned e-mail to our internal corporate Exchange 2013 server.  Also, would like, if at all possible, best practices for over-all security hardening of IIS & Exchange.

Thank you in advance,

William

Problem Installing CU7

$
0
0

Hi,

I have the client tools (CU6) installed on one of my servers. I am trying to run the CU7 installation in order to update the server. As soon as setup finishes the Copying Files step I receive the following error message:

The Type Initializer for Microsoft.Exchange.Management.Powershell.CmdletConfigurationEntr (line is cut off)

threw an exception. Could not load file or assembly 'Microsoft.Exchange.MailboxLoadBalanceClient Version=15.0.0.0 (message is cut off).

Any ideas how to troubleshoot this?

Thanks,

I. Kinal


Promoting Member Server windows 2012 Standard to Domain controller

$
0
0

Dear all,

We currently are running Windows Server 2003 DC's in a 2003 domain/forest functional level.

Also are running Exchange 2003 Enterprise SP2 and Exchange Sever 2010 + SP3 (DAG) in coexistance

We are planning on adding 2012 ADC to the domain and Promote windows 2012 ADC to DC and commission Windows 2003 DC.

by doing my environment picture will be ;

Domain Controller = windows 2012 Std

Exchange Server 2003 and Exchange Server 2010.

and in a month or so will be moving all Exchange Server 2003 users to Exchange Server 2010 this is the plan.

So, can any one help me with Standard practice for this.


TheAtulA

Unable to add replica of database

$
0
0

Had to rebuild a server from scratch after it failed in a DAG and was unable to recover it. Added it back to the DAG after using cluster manager to evict it. I was surprised because it was not showing in the DAG manager. Now, I am attempting to add a database copy to the rebuild server and the error is "log file on a removable disk" The server that holds it had two hard drives, and the database is no drive letter "E". Not sure what to do with it now.

thanks


Ron

Public folder migration cannot complete due to StalledDueToMailboxLock status

$
0
0

I'm on one of my last steps in migrating from 2010 to 2013.  When I issue the command to  Resume the migration request after the Autosuspend happens, I get a StalledDueToMailBoxLock, and it retries but never completes.  I've removed the request and tried it again, but I get the same thing.  The requests were 24 hours apart.  I have no clients that are connecting to the 2010 server anymore, and all the user mailboxes have been migrated to 2013 successfully.  I haven't found much online about this status, so I'm at a loss.  By the way, this is during my Public Folder migration process.  Sorry for leaving that out.

Thank you.


Cant move mailbox back to exchange 2007 from 2013 ..

$
0
0

I recently configured coexistence between exchange 2007 and 2013.

I have moved some users to 2013 and they are fine.

I recently moved "BESADMIN" account to exchange 2013 while trying to integrate exchange 2013 with BES. The integration is suspended for now and I am trying to move the mailbox back to 2007. From ECP it completes successfully but running get-mailbox cmdlt shows that the mailbox is still in 2013.

I have also tried using management shell but it fails at 95%

I will appreciate all the help I can get here ..

~Richard


..forever is just a minute away*

Exchange 2013 CU6 installation hangs on step 9: Languages

$
0
0

Just had Exchange 2013 CU6 update hang on Step 9 of 18: Languages.  It was stuck at 0% for almost an hour.  I was able to get it moving forward by disabling SCEP 2012 by killing the process and deselecting check certificate for server certificate revocation in IE.  Both steps were taken nearly simultaneously and the install process for Exchange jumped up immediately. Both steps were taken based on info from:

https://social.technet.microsoft.com/Forums/exchange/en-US/2a346a37-d092-4189-8a07-e8a9971925f1/cu2-installation-hangs-on-step-9-languages?forum=exchangesvrdeploy

and

https://social.technet.microsoft.com/Forums/exchange/en-US/0975bb5e-f270-4e39-abf3-70809cd98161/exchange-2010-sp3-installation-hangs-language-pack-hell

Just wanted to post that this issue was encountered on CU6 as well.  Has anyone had a similar experience or able to tell which of these two steps (or both) is actually needed?

2013 server reporting edge server not on 2007 SP3, when it is.

$
0
0

I am attempting to put in a 2013 server in an environment that has 2007. The pre-req check fails saying one of the edge servers is not on SP3, but it is.

When doing a get-exchangeserver |fl name,admindisplayversion, The internal servers all show 8.3.6

When I do the same thing on the edge server, it shows 8.2 (build 176.2) for itself. That is the only place it shows it is 8.2. Everywhere else, including exsetup, it shows the correct 8.3 version number. I can also see that SP3 RU14 is installed on the edge server.

I have a maintenance window to redo the edge subscription this weekend, however I'm not sure if that will fix anything, since it's the edge server that is not able to identify it's own installed version.

How can I get the AdminDisplayVersion on the Edge server to show the correct SP that is installed?


http://jaworskiblog.com

Exchange Server Mailbox Migration

$
0
0

Hi All,

I just migrated a 2.2 GB mailbox  with 50k item count from Exchange 2010 to Exchange 2007 sp3. After migration the mailbox is 3.7 GB in size with 70k items.

Can anyone shed any light on this. there is no way the user got 20k mails during the move.

Thanks


Revocation check failed

$
0
0

Recently, we moved Active Directory Certificate Services off of our exchange server and onto a dedicated ADCS box. We kept the same CA name, however the server name changed. After migrating the database and configuration from the old server to the new one, we are now getting the status 'Revocation check failed' with our exchange certificates. We are on Server 2012 R2 with Exchange 2013.

PKIView.msc:
CA Certificate = OK
AIA Location #1 = OK
CDP Location #1 = OK
DeltaCRL Location #1 = OK

Netsh command shows Exchange is not behind a proxy.

Exchange 2013 SP1 - Error: Your request could not be completed

$
0
0

When trying to log into the ECP I get an:

Error

Your request could not be completed.  Please try again later.   

When I check the event viewer I get:

WebHost failed to process a request.
 Sender Information: System.ServiceModel.ServiceHostingEnvironment+HostingManager/6837052
 Exception: System.ServiceModel.ServiceActivationException: The service '/ecp/DDI/DDIService.svc' cannot be activated due to an exception during compilation.  The exception message is: This collection already contains an address with scheme http. There can be at most one address per scheme in this collection. If your service is being hosted in IIS you can fix the problem by setting 'system.serviceModel/serviceHostingEnvironment/multipleSiteBindingsEnabled' to true or specifying 'system.serviceModel/serviceHostingEnvironment/baseAddressPrefixFilters'.
Parameter name: item. ---> System.ArgumentException: This collection already contains an address with scheme http.  There can be at most one address per scheme in this collection. If your service is being hosted in IIS you can fix the problem by setting 'system.serviceModel/serviceHostingEnvironment/multipleSiteBindingsEnabled' to true or specifying 'system.serviceModel/serviceHostingEnvironment/baseAddressPrefixFilters'.
Parameter name: item
   at System.ServiceModel.UriSchemeKeyedCollection.InsertItem(Int32 index, Uri item)
   at System.Collections.Generic.SynchronizedCollection`1.Add(T item)
   at System.ServiceModel.UriSchemeKeyedCollection..ctor(Uri[] addresses)
   at System.ServiceModel.ServiceHost..ctor(Type serviceType, Uri[] baseAddresses)
   at Microsoft.Exchange.Management.ControlPanel.ServiceHostFactory.CreateServiceHost(Type serviceType, Uri[] baseAddresses)
   at System.ServiceModel.Activation.ServiceHostFactory.CreateServiceHost(String constructorString, Uri[] baseAddresses)
   at System.ServiceModel.ServiceHostingEnvironment.HostingManager.CreateService(String normalizedVirtualPath, EventTraceActivity eventTraceActivity)
   at System.ServiceModel.ServiceHostingEnvironment.HostingManager.ActivateService(ServiceActivationInfo serviceActivationInfo, EventTraceActivity eventTraceActivity)
   at System.ServiceModel.ServiceHostingEnvironment.HostingManager.EnsureServiceAvailable(String normalizedVirtualPath, EventTraceActivity eventTraceActivity)
   --- End of inner exception stack trace ---
   at System.ServiceModel.ServiceHostingEnvironment.HostingManager.EnsureServiceAvailable(String normalizedVirtualPath, EventTraceActivity eventTraceActivity)
   at System.ServiceModel.ServiceHostingEnvironment.EnsureServiceAvailableFast(String relativeVirtualPath, EventTraceActivity eventTraceActivity)
 Process Name: w3wp
 Process ID: 11124

I am trying to create a Send connector and it gets all the way through but then fails at Select Source Server.   There are no source servers listed.   Why does it not pick up itself?    

As for the error I think this is related to IIS permissions somehow and here is how i have the bindings set:

Default Web Site:

http   80  *

net.msmq   localhost

msmq.formatnamelocalhost

net.tcp808:*

net.pile)

httpsexssrv.cas.local443*    (With the SSL cert being the Microsoft Exchange built in one)

Exchange Back End 

 httpexssrv.cas.local81192.168.1.5

httpexssrv80*

net.pipe*

https exssrv.cas.local 444192.168.1.5  (Bound to Microsoft Exchange ssl)

I am connecting to the site internally from https://exssrv.cas.local/ecp

Thanks for any suggestions.. I think I am almost there on the install!   Hoping!


Mail server not working after moving the server

$
0
0

This weekend we moved our mail server. After many troubles with copying we managed to get it running on the new host (ESXi5.5).

For the mail server we opened ports 80, 443, 135 and 25. All dns records point to the new IP. I also recreated the recursive lookup zone for the new internal ip.

Yet, mail flow is not working while I can connect and login on owa and connect with Outlook from both inside and outside the network. Internal mail, even from and to the same address is not working.

This is the first time we moved a mail server and we might have missed something. Any ideas where to look?

RPC Proxy doesn't work: 2013/2010 Co-Existence with Outlook Anywhere

$
0
0

ISSUE: Can't RPC Proxy Outlook Anywhere requests for Exchange 2010 mailbox users via the Exchange 2013 CAS.

SYMPTOMS: Externally with TestExchangeConnectivity.com, I get 'RPC Proxy Can't Be Pinged' with 'An HTTP 401 Unauthorized response was received from the remote Unknown server'.

SETUP:

Exchange 2013 CU2
Get-OutlookAnywhere Details:
ExternalHostname: webapp.mydomain.com
InternalHostname: ex2013.mydomain.local
ExternalClientAuthenticationMethod: Basic
InternalClientAuthenticationMethod: Ntlm
IISAuthenticationMethods: Basic, Ntlm, Negotiate
SSLOffloading: False

Certificate on 2013 server contains the names: ex2013.mydomain.local, webapp.mydomain.com, AutoDiscover.mydomain.local, AutoDiscover.mydomain.com, mydomain.local, mydomain.com

Exchange 2010 SP3 update rollup 1
Get-OutlookAnywhere Details:
ExternalHostname: webapp.mydomain.com
ClientAuthenticationMethod: Basic
IISAuthenticationMethods: Basic, Ntlm
SSLOffloading: False

Certificate on 2010 server contains the names: ex2010.mydomain.local, webapp.mydomain.com, autodiscover.mydomain.local, autodiscover.mydomain.com

Outlook providers:
EXCH  CertPrincipalName: msstd:webapp.mydomain.com
EXPR  CertPrincipalName: msstd:*.mydomain.com    (as I use an external reverse proxy with a public wildcard certificate)

ADDITIONAL DETAILS:
- With the above settings, Outlook 2010 doesn't seem to be able to proxy RPC through Exchange 2013.

Testing manually with RPCPING utility:
- Requests for port 6001 directed to Exchange 2010 for people with mailbox on Exchange 2010: works correctly
- Requests for port 6001 directed to Exchange 2013 for people with mailbox on Exchange 2013: works correctly
- Requests for port 6001 directed to Exchange 2013 for people with mailbox on Exchange 2010: error 401.1 Unauthorized

OWA and Activesync through Exchange 2013 for people with mailbox on Exchange 2010 are working fine.
Only RPC over HTTP seems to have problems.

- Here are some pertinent lines from the 2010 CAS server's IIS logs for a 2013 to 2010 RPC access:
2013-10-10 13:02:16 10.62.6.56 RPC_IN_DATA /rpc/rpcproxy.dll ex2010.mydomain.local:6001 443 - 10.62.6.50 MSRPC 401 1 2148074248 624
2013-10-10 13:02:16 10.62.6.56 RPC_OUT_DATA /rpc/rpcproxy.dll ex2010.mydomain.local:6001 443 - 10.62.6.50 MSRPC 401 1 2148074248 624
2013-10-10 13:02:16 10.62.6.56 RPC_IN_DATA /rpc/rpcproxy.dll - 443 - 10.62.6.50 HttpProxy.ClientAccessServer2010Ping 401 2 5 780

- Here are some pertinent lines from the 2013 CAS server's IIS logs for the same 2013 to 2010 RPC access:
2013-10-10 13:02:14 10.62.6.50 RPC_IN_DATA /rpc/rpcproxy.dll ex2010.mydomain.local:6001&RequestId=b6464f37-a9fe-4f84-a32b-ff9af689607c&cafeReqId=b6464f37-a9fe-4f84-a32b-ff9af689607c; 443 - 10.62.7.15 MSRPC - 401 1 2148074254 4726
2013-10-10 13:02:14 10.62.6.50 RPC_OUT_DATA /rpc/rpcproxy.dll ex2010.mydomain.local:6001&RequestId=4acc0118-7fac-49db-976d-152a4a6839b2&cafeReqId=4acc0118-7fac-49db-976d-152a4a6839b2; 443 - 10.62.7.15 MSRPC - 401 1 2148074254 0
2013-10-10 13:02:16 10.62.6.50 RPC_OUT_DATA /rpc/rpcproxy.dll ex2010.mydomain.local:6001&RequestId=a591fb11-98c3-44e6-90c7-f719c7047fe4&cafeReqId=a591fb11-98c3-44e6-90c7-f719c7047fe4; 443 dom\2010user 10.62.7.15 MSRPC - 401 0 64 1544
2013-10-10 13:02:16 10.62.6.50 RPC_IN_DATA /rpc/rpcproxy.dll ex2010.mydomain.local:6001&RequestId=fbb94579-8d0b-41d7-8103-45c945141bd7&cafeReqId=fbb94579-8d0b-41d7-8103-45c945141bd7; 443 dom\2010user 10.62.7.15 MSRPC - 200 0 64 1700

Any thoughts or comments are highly appreciated. Let me know if additional details are needed.

Migration to Exchange 2013 from 2010 - Client side issues

$
0
0

Hi Everyone, 

   I've been having issues with clients connecting to an existing Exchange server (Getting login prompt- but not usual reason).  

We currently run Exchange 2010 with approx 200 mailboxes on the server.  Last night I renewed the certificate on the 2010 server (go daddy SAN cert, all ok) and added the cert to my new Exchange 2013 server.  I tested it with my account, and a test account approx 12 times, and had not login prompt when launching Outlook. All seemed ok, until this morning.....

This morning, most (not all) users are getting the login prompt.  We are able to get by this by inputting domain\username and Outlook opens fine and is able to connect.  No users are on the Exchange 2013 server yet (only 1 test account) 

I've been googling all morning and I'm not seeing anything directly relating to my issue.  I've read about the Anon vs Negotiate issues (KB2834139) - But - the strange thing is all clients are set to negotiate network security (And encrypt data) This is opposite of what the MS article says.  CLients are all Outlook 2010 

Here are my outlook anywhere settings: 

ServerName               : exchange2010
IISAuthenticationMethods : {Basic}

ServerName               : exchange2013A
IISAuthenticationMethods : {Basic, Ntlm}

ServerName               : exchange2013B
IISAuthenticationMethods : {Basic, Ntlm}

Identity                          ClientAuthenticationMethod IISAuthenticationMethods
--------                          -------------------------- ------------------------
exchange2010\Rpc (Default Web Site)                        Basic {Basic}
exchange2013a\Rpc (Default Web Site)                       Ntlm {Basic, Ntlm}
exchange2013b\Rpc (Default Web Site)                       Ntlm {Basic, Ntlm}

If I change the Exchange 2010 server to NTLM, will this resolve what I'm seeing? And do I need to restart RPC Client Access and Transport Service to make changes take effect? Or reboot the whole server? 

If you need more info or logs please let me know

Thank you for any help! 

-Jeff

Viewing all 7008 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>