Exchange 2013 ECP 503 error

I have a problem with my two Exchange 2013 servers. There are no mailboxes on the servers, because we are just beginning our migration from Exchange 2007. We are running Exchange 2013 SP1 on Server 2012R2

When I try to access ecp/owa on ex01 (https://localhost or https://ex01.domain.local), I am presented with a login page, but after entering my credentials, I get a 503 error:

Service Unavailable HTTP Error 503. The service is unavailable

On ex02, I can RDP to the server and log into ecp/owa just fine. However, if I log in (https://ex02.domain.local) from another computer (like my PC), I get the same credential page and 503 error.

I verified the following:

  • All of the application pools and Exchange services are started
  • I do not have any instances of event 2280 in the Application log
  • I have also restarted the server
  • Local security policy shows that Administrators and Backup Operators have "Allow log on locally" permission

This feels like a permissions issue in IIS, but I'm not sure.

My ECP virtual directory settings (both servers) look like this:

  • InternalAuthenticationMethods : {Basic, Fba}
  • BasicAuthentication : True
  • WindowsAuthentication : False
  • DigestAuthentication : False
  • FormsAuthentication : True
  • LiveIdAuthentication : False
  • AdfsAuthentication : False
  • OAuthAuthentication : False
  • ExternalAuthenticationMethods : {Fba}

Why won't ex01 let me log in and why would the login on ex02 work from the server, but 503 from my machine? Thanks.

April 21st, 2015 11:00am

https://ex02.domain.local/ecp/?ExchClientVer=15 (and ex03) work from my machine, and from the individual servers. Shouldn't I get redirected to the more specific URL when I log into https://ex02.domain.local/ecp?
Free Windows Admin Tool Kit Click here and download it now
April 21st, 2015 5:51pm

You may not necessarily be redirected to a more specific URL. You can also input that into your browser and see if it changes anything. I checked my lab 2013 server and your authentication looks correct. Have you done any customization of the ECP web.config file? Does the account you are logging in with have a mailbox? If so which server does it currently reside on? You can look at the IIS logs for the "Exchange Back End" site.

April 21st, 2015 8:48pm

Hi,

From your description, I would like to clarify the following things for troubleshooting:

1. Make sure that the services are running under the Local System account.

2. Ensure that the mailbox database that you want to access are mounted. Besides, the account you use to access ECP should have a mailbox in the Exchange server you are accessing.

Hope my clarification can be helpful to you.

Best regards,

Free Windows Admin Tool Kit Click here and download it now
April 22nd, 2015 12:46am

I have not customized the web.config file and all services are using Local System. The account I am using to log in does not have a mailbox. Are you suggesting that adding a mailbox will allow me to log into https://ex02.domain.local/ecp instead of having to use https://ex02.domain.local/ecp/?ExchClientVer=15?
April 22nd, 2015 9:12am

I had to add '?ExchClientVer=15' to the URL.
  • Marked as answer by mhashemi 13 hours 26 minutes ago
Free Windows Admin Tool Kit Click here and download it now
April 30th, 2015 2:01pm

I had to add '?ExchClientVer=15' to the URL.
  • Marked as answer by mhashemi Thursday, April 30, 2015 5:59 PM
April 30th, 2015 5:59pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics