Ex2007 CMS hand-off = Outlook login prompt?
When we hand-off or manually fail-over our Clustered Mailbox Server to the passive node, Outlook 2007 users are prompted for their password when they reconnect to the CMS. Can this be prevented or is this by design?
June 15th, 2010 10:03pm

This should *not* be the default behavior if they are using integrated windows authentication. Do the users have to provide a user name and password when they initially open Outlook? Jim McBee - Blog - http://mostlyexchange.blogspot.com
Free Windows Admin Tool Kit Click here and download it now
June 16th, 2010 3:46am

On Tue, 15 Jun 2010 19:03:50 +0000, Mike Erter wrote: > > >When we hand-off or manually fail-over our Clustered Mailbox Server to the passive node, Outlook 2007 users are prompted for their password when they reconnect to the CMS. > >Can this be prevented or is this by design? Is outlook configured to use the "Exchange Proxy Settings..."? If the "On slow networks..." is checked what may be happening is that Outlook is switching to RPC-over-HTTPS. If the CAS is configured to use basic authentication then you'll get that logon dialog box. --- Rich Matheisen MCSE+I, Exchange MVP --- Rich Matheisen MCSE+I, Exchange MVP
June 16th, 2010 5:00am

How do I check if they are using Integrated Windows Authentication? They do not have to provide their credentials when they initially open Outlook.
Free Windows Admin Tool Kit Click here and download it now
June 17th, 2010 10:48pm

I notice in Outlook in my Microsoft Exchange Proxy Settings the "Use this authentication when connecting to my proxy server for Exchange:" is set to Basic Authentication.
June 17th, 2010 10:53pm

Where do I check if the CAS is configured to use Basic Authentication?
Free Windows Admin Tool Kit Click here and download it now
June 17th, 2010 10:54pm

On Thu, 17 Jun 2010 19:54:16 +0000, Mike Erter wrote: >Where do I check if the CAS is configured to use Basic Authentication? Use "get-outlookanywhere". --- Rich Matheisen MCSE+I, Exchange MVP --- Rich Matheisen MCSE+I, Exchange MVP
June 18th, 2010 5:38am

Thanks for answering. I see the output from that cmdlet says: ClientAuthenticationMethod : Basic IISAuthenticationMethods : {Ntlm} Do you suggest I change that so that they both say "Basic"? I wonder if that will break my Threat Management Gateway Outlook Anywhere Publishing Rule?
Free Windows Admin Tool Kit Click here and download it now
June 18th, 2010 8:29pm

On Fri, 18 Jun 2010 17:29:49 +0000, Mike Erter wrote: > > >Thanks for answering. > >I see the output from that cmdlet says: > >ClientAuthenticationMethod : Basic > >IISAuthenticationMethods : {Ntlm} > >Do you suggest I change that so that they both say "Basic"? No. Set them so they look like this: ClientAuthenticationMethod : Ntlm IISAuthenticationMethods : {Basic, Ntlm} >I wonder if that will break my Threat Management Gateway Outlook Anywhere Publishing Rule? Do you use FBA on the TMG publishing rule? If you do then the TMG will proxy the credentials using "basic" authentication. --- Rich Matheisen MCSE+I, Exchange MVP --- Rich Matheisen MCSE+I, Exchange MVP
June 19th, 2010 6:09am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics