Outlook 2007 Login Prompt on Exchange 2007
I installed Exchange 2007 and have moved several mailboxes to it from Exchange 2003. When these users open Outlook 2007 while inside our network they receive a login prompt after opening Outlook. If Outlook is closed and reopened they do not receive a login prompt so it seems to happen only after logging into the compter. They have a TCP/IP connection, hot http, and everything else is working fine. Any ideas?
October 22nd, 2007 5:05pm

You should verify if you have any Kerberos errors on the Exchange Server or Domain Controller Deli
Free Windows Admin Tool Kit Click here and download it now
October 22nd, 2007 10:09pm

Have you run the Outlook 2007 diagnostics from the Help/Office Diagnostics area?
October 25th, 2007 9:56pm

I don't seem to have any Kerberos problems. Another thing I have found is that it seems to only be happening on either Vista or Outlook 2007 users. I'm not sure if it has to be both or one or the other. I am going to do more testing on this.
Free Windows Admin Tool Kit Click here and download it now
October 25th, 2007 10:12pm

Is your Exchange server in the same Active Directory as your Clients? Deli
October 25th, 2007 10:25pm

Yes, it is in the same AD.
Free Windows Admin Tool Kit Click here and download it now
October 25th, 2007 10:27pm

Might be an authentication issue on your Autodiscover Virtual Directory in IIS http://technet.microsoft.com/en-us/library/bb201695.aspx Deli
October 25th, 2007 11:10pm

It looks like everything is configured correctly as far as authentication. The login prompt is only happening with users running Outlook 2007. Outlook 2003 users connecting to the Exchange 2007 server do not receive a login prompt.
Free Windows Admin Tool Kit Click here and download it now
October 29th, 2007 4:58pm

You might want to check the Outlook profiles and check if Outlook uses cached mode and connects to the Exchange server using HTTP and check Authentication settings there Outlook can also be configured to allways request authentication Deli
October 29th, 2007 5:38pm

I am experiencing the same thing. We implemented Exchange 2007 on Friday. All XP/2003 clients work fine, but all 2007 Outlook clients prompt for login when Outlook is opened. What is more frustrating is that it continues to prompt until you hit cancel. Once you do that, it stops prompting, and works fine--provided you did enter correct credentials on the first login request. No errors reported on the Exchange server.
Free Windows Admin Tool Kit Click here and download it now
October 29th, 2007 6:25pm

It doesn't seem to matter if cached mode is used or not, I still get the login prompt. It is not using HTTP and it is not set to always request authentication. The only thing I see is that the default Outlook 2003 installation does not check the box next to "Encrypt Data between Microsoft Outlook and Microsoft Exchange" on the Security tab and the Outlook 2007 installation does check this box. However, unchecking the box in Outlook 2007 only delays when the login box appears.
October 29th, 2007 7:08pm

If you cancel the login box do you still have access to your mailbox? If that is the case then I am pretty sure that it is Autodiscover problems Deli
Free Windows Admin Tool Kit Click here and download it now
October 30th, 2007 1:51am

Yes, when I cancel the login box everything works fine. A message appears on the right side of the status bar that says "Need Password" and the login box will appear every few minutes but everything works normally. -Dennis
October 30th, 2007 3:21pm

I see this behavior as well. I am sure we are dealing with the same problem.
Free Windows Admin Tool Kit Click here and download it now
October 30th, 2007 9:14pm

Is this also happening when you logoff and logon again and then open Outlook? Deli
October 30th, 2007 11:10pm

I get the exact same symptom with my Exchange 2007 and Outlook 2007 setup. Previously it was working but we installed Exchange 2007 SP1 Beta 2 during a re-install and since then, its been behaving this way. Are you all who are facing this also on E2k7 SP1 Beta 2?
Free Windows Admin Tool Kit Click here and download it now
October 31st, 2007 12:15pm

Yes. Logging off and logging back on causes another login prompt.
October 31st, 2007 2:25pm

No, I am on not on SP1 beta 2.
Free Windows Admin Tool Kit Click here and download it now
October 31st, 2007 2:26pm

I don't think there can be many explenations Outlook works fine if you cancel the login box Every few minutes the popup comes back to authenticate I still think this is Autodiscover related Integrated authentication is selected on the IIS server Autodiscover virtual directory? Deli
October 31st, 2007 4:06pm

Yes, Integrated Authentication is selected. It wasn't originally but nothing changed after I selected it.
Free Windows Admin Tool Kit Click here and download it now
October 31st, 2007 4:13pm

Integrated Authentication is indeed selected on that virtual diretory at my site. I am not using any beta products.
October 31st, 2007 5:48pm

Hi All, Strangely enough, I do not see the same symptom when I am connected remotely over RPC/HTTP from Home. This only happens when OUtlook 2007 is connected to E2k7 on the local LAN. Are you all seeing the same symptom too? We've checked the autodiscover service configuration and it looks fine. Not sure where else to look. Any sharing ofprogressmade for this issue is appreciated
Free Windows Admin Tool Kit Click here and download it now
November 5th, 2007 5:08am

I can confirm the same. Worked without prompting me from home using RPC/HTTP. Back to the office this morning and still getting prompted. I have looked at my autodiscover service as well and all seems fine. We are about to open case with MS through a support partner. I'll share if we come up with a solution.
November 5th, 2007 4:55pm

You have probably a problem with your Service Connection Point in AD Get-ClientAccessServer | fl Look at AutoDiscoverServiceInternalUri You must set this value to the correct server http://technet.microsoft.com/en-us/library/bb125157.aspx Deli
Free Windows Admin Tool Kit Click here and download it now
November 5th, 2007 6:57pm

It looks correct to me, but maybe I am missing something. Here is the result form the Get-ClientAccessServer | fl command:Name : EXCHANGEOutlookAnywhereEnabled : TrueAutoDiscoverServiceCN : exchangeAutoDiscoverServiceClassName : ms-Exchange-AutoDiscover-ServiceAutoDiscoverServiceInternalUri : https://exchange.mydomain.local/Autodiscover/Autodiscover.xmlAutoDiscoverServiceGuid : 7xxxxxx6-2xx6-4xx9-axx6-3xxxxxxxxxx6AutoDiscoverSiteScope : {Default-First-Site-Name}IsValid : TrueOriginatingServer : server4.mydomain.localExchangeVersion : 0.1 (8.0.535.0)DistinguishedName : CN=EXCHANGE,CN=Servers,CN=Exchange Administrative Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=mydomain,CN=Microsoft Exchange,CN=Services,CN=Configuration,DC=mydomain,DC=localIdentity : EXCHANGEGuid : 4xxxxxx7-exx0-4xxa-axxe-8xxxxxxxxxxbObjectCategory : mydomain.local/Configuration/Schema/ms-Exch-Exchange-ServerObjectClass : {top, server, msExchExchangeServer}WhenChanged : 10/26/2007 3:47:19 PMWhenCreated : 10/24/2007 4:26:34 PM*Actual domain names and guids obscured.
November 5th, 2007 7:12pm

I would try to connect to the url with Internet Explorer https://exchange.mydomain.local/Autodiscover/Autodiscover.xml Verify that exchange.mydomain.local is in the intranet domain in IE settings so that you have integrated authentication So you should be able to connect to the url without being promted for authentication Deli
Free Windows Admin Tool Kit Click here and download it now
November 5th, 2007 8:15pm

When I initially browsed, I was prompted for logon. I added the url to the intranet domain in IE and was then able to browse the site without being prompted for login. This is the results shown, which I believe is correct: <?xml version="1.0" encoding="utf-8" ?> - <Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/responseschema/2006"> - <Response xmlns="http://schemas.microsoft.com/exchange/autodiscover/responseschema/2006"> - <Error Time="12:24:36.9716616" Id="3007185755"> <ErrorCode>600</ErrorCode> <Message>Invalid Request</Message> <DebugData /> </Error> </Response> </Autodiscover>This change in IE settings has no affect on the Outlook login prompts issue.
November 5th, 2007 8:26pm

You do have a certificate for the domain mentioned in the output, correct? either a Subject Alternate Naming certificate of an SSL cert with the name of the autodiscover service? if not, that would be why it is prompting you.
Free Windows Admin Tool Kit Click here and download it now
November 5th, 2007 10:15pm

I think I am out of suggestions now as everything seems fine. Allthow I think Outlook does work with IE settings Maybe you can do a test with an IE with no proxy server configured and start outlook? Deli
November 6th, 2007 2:03am

Are you by chance using ISA server to publish Exchange? I have the same symptoms and from what I can tell the problem is ISA somewhere along the line. If i Setup my Outlook 2007 email clients to by pass the ISA server and got Directly to the CAS I get no login prompt. As soon as i re-configure to send traffic through ISA, the prompts come back. I think, you'll find that when you cancel the login prompt, that free/busy data is unavailable when using the scheduling component in outlook. Aside from this information being unavailable, all else seems to work fine. I've been working on this for a week or two now and haven't got too far. I've used my ISA server to monitor traffic and have found that for some reason, Outlook 2007 clients are denied http connecting to the CAS when the prompt occurs. Where this really seems to get odd is that, if you use microsoft, communicator, and login to that before starting outlook 2007, the prompts go away and the free/busy data begins to work properly. On top of that ISA no longer picks up http traffic, from what i can see.Anyways, I'm currently working with a support call and microsoft to resolve this. I'll let you know that I find out.
Free Windows Admin Tool Kit Click here and download it now
November 6th, 2007 2:53am

Just another bit of information about this. I can get this to work properly if i change the internal uri for autodiscover to the default (from install) however we do not own the internal domain name and thus can not use the name since we serve many users with and without domain joined machines (we need to use a purchased cert). This again, though, bypasses the ISA server (and generates a certificate error).
November 6th, 2007 3:02am

I have no doubt that this is autodiscover related. In exchange 2003, free/busy data was retrieved using public folders and in exchange 2007 autodiscover retrieves this information. And free/busy data is what causes the login, from what i can tell.
Free Windows Admin Tool Kit Click here and download it now
November 6th, 2007 3:07am

And do we have a certificate for the autodiscover services? I have had this issue in the past where the internalURi is pointing to a non secure location with an SSL request.
November 6th, 2007 3:12am

Another observation: My Exchange 2007 server is currently co-existing with my legacy Exchange 2003 server in the same Exchange organization (diff server of course) through the connector. My mailbox was migrated to E2k7, but the Public Folder store is still on E2k3 server. I get the entire list of PFs in Outlookbut when I drill down to the folder I see an error "Cannot Display the Folder. Network Problems are preventing connection to Microsoft Exchange" error message. I suspect the login prompts in Outlook 2007 which I get is related to connectivity to E2k3 PF, as the rest of the "services" I get in oulook is working such as out of office attendant, addressbook etc. Do you guys have similar co-existence setup as I do? Also do you see the same problem with the Public Folder?
Free Windows Admin Tool Kit Click here and download it now
November 6th, 2007 12:41pm

Ok I double checked. When I go to outlook and select Send/Receive -> Offline Address Book, I get the same annoying login prompts until I hit cancel. So I think what some of you suggested is correct, that this is Autodiscover related. Do the rest of you having this issue have problems Downloading Offline Addressbook on the LAN environment as well?
November 6th, 2007 1:07pm

Hi Funj is it possible for you to start another thread? This was originally a problem we were discussing forDennisW To much confusion in this thread right now Thanks, Deli
Free Windows Admin Tool Kit Click here and download it now
November 6th, 2007 1:19pm

Ok I think my case is solved. My URL for the OABUrlwas not correct for internal. For some reason it was: http://cas.domain.local instead of https://cas.domain.localwhich I fixed via the Exchange Management Console -> Server Configuration ->Client Access Server -> Offline Address Distribution tab. I can download OAB now and this also fixed my PF connectivity (for some reason!). And I have lost the annoying Outlook 2007 prompts! How I found this was: 1) In the task tray, hold down CTRL Key and right click the Outlook icon and select Test Email Auto Configuration 2) Uncheck Use Guessmart and Secure Guessmart Authentication 3) Click Test 4) Upon completion of the test, view the XML tab results. You should see something like the report below. 5) I noticed that for my Internal LAN connectivity, the URL for OAB was starting with HTTP instead of HTTPS. 6) I made the change from the Management Console as discribe above 7) Did a iisreset 8) Ran the steps 1-4 again and verified that the change highlighted in RED is reflected. Download of OAB now works from Outlook on the LAN. Send/Recieve also completes 100% without Login Prompts. I hope this helps solve the issues that the rest of you are facing too! -------------- *note the details of the domain and server have been masked: <?xml version="1.0" encoding="utf-8"?><Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/responseschema/2006"> <Response xmlns="http://schemas.microsoft.com/exchange/autodiscover/outlook/responseschema/2006a"> <User> <DisplayName>Fun Jin Lim</DisplayName> <LegacyDN>/o=ISAT/ou=First Administrative Group/cn=Recipients/cn=Funj</LegacyDN> <DeploymentId>1e1f75eb-c6dd-4a20-b730-94a002a13b33</DeploymentId> </User> <Account> <AccountType>email</AccountType> <Action>settings</Action> <Protocol> <Type>EXCH</Type> <Server>cas.domain.local</Server> <ServerDN>/o=ISAT/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/cn=Configuration/cn=Servers/cn=CAS</ServerDN> <ServerVersion>720180B1</ServerVersion> <MdbDN>/o=DOMAIN/ou=Exchange Administrative Group (FYDIBOHF23SPDLT)/cn=Configuration/cn=Servers/cn=CAS/cn=Microsoft Private MDB</MdbDN> <PublicFolderServer>cas.domain.local</PublicFolderServer> <AD>cas.domain.local</AD> <ASUrl>https://cas.domain.local/EWS/Exchange.asmx</ASUrl> <EwsUrl>https://cas.domain.local/EWS/Exchange.asmx</EwsUrl> <OOFUrl>https://cas.domain.local/EWS/Exchange.asmx</OOFUrl> <UMUrl>https://cas.domain.local/UnifiedMessaging/Service.asmx</UMUrl> <OABUrl>https://cas.domain.local/OAB/6dfc505f-c54b-4abc-ac63-dfb8e2f06156/</OABUrl> </Protocol> <Protocol> <Type>EXPR</Type> <Server>cas</Server> <SSL>On</SSL> <AuthPackage>Ntlm</AuthPackage> <ASUrl>https://www.domain.com.my/EWS/Exchange.asmx</ASUrl> <EwsUrl>https://www.domain.com.my/EWS/Exchange.asmx</EwsUrl> <OOFUrl>https://www.domain.com.my/EWS/Exchange.asmx</OOFUrl> <OABUrl>https://www.domain.com.my/OAB/6dfc505f-c54b-4abc-ac63-dfb8e2f06156/</OABUrl> </Protocol> <Protocol> <Type>WEB</Type> </Protocol> </Account> </Response></Autodiscover>
November 6th, 2007 2:11pm

I am configured exactly the same way you are - Exchange 07 co-exisiting with Excahnge 03 and my mailbox is on the E07 server. However, I don't have any problem seeing Public Folders. I am still getting the Outlook login prompts.
Free Windows Admin Tool Kit Click here and download it now
November 6th, 2007 3:39pm

Have you tried following the steps to check the contents of the Autodiscover.xml results? There was a problem with the URL for OAB, which had to be rectified. The SCP was configured correctly to reference to the right autodiscover service, but the service had inaccurate information for OAB. Hence when we checked if Autodiscover service was running and Outlook referencing it, it seemed like it was, just Outlook was being fed wrong URL references for the OAB. I've been running Outlook 2007 on E2k7 without the Login Prompts for over 12 hours now.. and it feels great to get rid of the pesky problem which I was facing as well. I am now curious if there was an issue/bug in the installer, as, based on what I remember I did not manually key in the HTTP (instead of HTTPS)parameter for OAB but it was auto populated. IF the cause of your issue is identical - i.e related to http for OAB, then I suspect it's a bug in the installation process. Do keep us updated on your progress.
November 7th, 2007 4:33am

Run test-OutlookWebServices | fl Disable the loopback check Follow these steps: 1. Click Start, click Run, type regedit, and then click OK. 2. In Registry Editor, locate and then click the following registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa 3. Right-click Lsa, point to New, and then click DWORD Value. 4. Type DisableLoopbackCheck, and then press ENTER. 5. Right-click DisableLoopbackCheck, and then click Modify. 6. In the Value data box, type 1, and then click OK. 7. Quit Registry Editor, and then restart your computer.
Free Windows Admin Tool Kit Click here and download it now
November 9th, 2007 10:57am

I paid a little more attention to the login prompts, and I noticed that it tries to authenticated to the following: exchange.mydomain.local, 3 times mydomain.net, 3 times autodiscover.mydomain.net, 3 times Even with the correct creditials entered, it goes through all 9 prompts and continues to prompt periodically.
November 12th, 2007 5:17pm

Anyone come up with a solution? I have a the same problem.
Free Windows Admin Tool Kit Click here and download it now
November 16th, 2007 12:38am

I was having the same problem. I did have my OAB configured to http instead of https (I think I may have been the one to do that) and fixed that. It still wasn't working until I tried doing a send/receive of just the address book and then provided my credentials. It seems to be working now... hopefully it will stay that way
November 23rd, 2007 11:10pm

We solved this problem for us anyway. In our case, we had created the host name autodiscover.domain.com with a CNAME instead of an A record. When we fixed that, the login prompts went away. STRIKE THIS. WE ARE STILL HAVING THIS PROBLEM.
Free Windows Admin Tool Kit Click here and download it now
April 30th, 2008 2:01am

I am now having this same issue. Has anyone figured out how to resolve this issue.
May 7th, 2008 6:29pm

OK I have hopefully just fixed this I followed the steps by Funj as mine was set to http. The other main step needed is to go into IIS on exchange server and enable integrated security and restart IIS. When I did this on the OAB virtual directory it fixed the problem for myself. Someone else who was using cached mode was still getting prompted though. So I went back to IIS and enabled integrated security on most of the other directories then restarted IIS and the problem is now completely solved. Can someone else try and let me know if this works for them too.
Free Windows Admin Tool Kit Click here and download it now
May 8th, 2008 8:52am

I'm using IIS7 and verified Windows Authentication is enabled, no help.
May 8th, 2008 3:38pm

For those using a proxy server for Internet:I was finally able to resolve this problem by adding mail.domain.net and mail.domain.local to the proxy exclusions list and using split-brain DNS. The problem was that request to the exchange server were first going out the firewall/proxy and then trying to come back through--something the firewall did not allow.
Free Windows Admin Tool Kit Click here and download it now
May 8th, 2008 6:27pm

This URL has the fix that worked for me. Now to get the OAB to update for my remote clients and I'll be finished with this. At least Outlook doesn't prompt me anymore. http://www.microsoft.com/communities/newsgroups/list/en-us/default.aspx?dg=microsoft.public.exchange.admin&mid=00d4a681-f588-4eed-b4f8-5c3645e7376c&sloc=en-us
May 9th, 2008 7:14pm

We were having the same problem, "Outlook 2007 Login Prompt on Exchange 2007" and Funj's posts help me track down my issue. My problem was a little different then other's I've read here so here's my fix: Situation: A couple weeks after migrating from Exchange 2003 to Exchange 2007 people started being prompted to logon to repeatedy in Outlook 2007. In Funj's post on 06 Nov 2007, 3:11 AM he explains how to test E-mail AutoConfiguration. I followed his instructions but my XML tab showed: <OABUrl></publicfolder> instead of a URL. Fix: My offline address book had not been migrated to Exchange 2007, it was still on my Exchange 2003 server.Here is the technet article the explains how to move the OAB: http://technet.microsoft.com/en-us/library/bb123917(EXCHG.80).aspx.It tooksome time forthe logon promptsto stop so be patient.Now myE-mail AutoConfiguration test, XML tabshows the proper URL for<OABUrl>. Thank you Funj!
Free Windows Admin Tool Kit Click here and download it now
October 3rd, 2008 7:47pm

I had this problem after Exchange 2007 sp1 Roll Up 4 update. OWA login was okay, only Outlook 2007 could not authenticate. I checked domains with dcdiag - was okay. All other domain authentication was ok. I checked DNS records, nothing had changed and all was good. I rebooted a couple more times after the update. What finally fixed it was looking at Properties for Autodiscover in IIS manager. The Virtual Directory, Directory Security and Certificates were all okay and nothing had changed. Under ASP.NET the version of asp.net was unselected and blank. I Selected the 2.0.50727 version from the drop down box, which is the only version available. When I applied that, the w3svc restarted inself but failed the restart (asp.net 2.0.507277 as the Source in the Event log) I manually restarted the Default Web Site from within IIS mgr. Immediately all Outlook 2007 clients could connect with Integrated Security and not be prompted for a password. I hope this helps someone
November 7th, 2008 12:10am

I have this problem with only one user.It happens no matter what client she logs in on. With a roaming profile it seems like there is a setting in her ntuser.dat. Any suggestion on this version of the Logon Prompt problem?
Free Windows Admin Tool Kit Click here and download it now
December 10th, 2008 11:19pm

We have the exact same symptom with Exchange 2007 Serverand Outlook 2007/2003 clients. I selected Integerated authentication on IIS server Autodiscover virtual directory and users do not receive login prompt any more. Gorazd
December 23rd, 2008 11:23am

Did you set all the virtual directories? Set-ClientAccessServer -Identity CASSERVER -AutodiscoverServiceInternalUri https://url.domain.com/autodiscover/autodiscover.xmlSet-WebServicesVirtualDirectory -Identity " CASSERVER \EWS (Default Web Site)" -InternalUrl https://url.domain.com/ews/exchange.asmx Set-OABVirtualDirectory -Identity " CASSERVER \oab (Default Web Site)" -InternalUrl https://url.domain.com/oabSet-UMVirtualDirectory -Identity " CASSERVER \unifiedmessaging (Default Web Site)" -InternalUrl https://url.domain.com/unifiedmessaging/service.asmxTest your connectivity?How may Sites in your evnironment? How many exchange servers?How are you routing to the CAS server?what a bout your security certs? I had an issue with ISA and bridging to 07 which actually was fixed by deploying an internal cert between the ISA and Exchange box.What about external users, does autodiscover work? Is it configured? How do users log into the network? wireless or cabled? BP
Free Windows Admin Tool Kit Click here and download it now
December 26th, 2008 5:03am

Had exactly the same problem. The solution was: I had a proxy server configured in Internet Explorer. I put the three addresses that the login prompt was complaining about in the exceptions field under Advanced next to the proxy settings under Connections and the prompts disappeared.
January 22nd, 2009 7:02pm

Thank you DNG-INC !! I followed the link, followed the directions and no more password prompting!! http://www.microsoft.com/communities/newsgroups/list/en-us/default.aspx?dg=microsoft.public.exchange.admin&mid=00d4a681-f588-4eed-b4f8-5c3645e7376c&sloc=en-us Excellent !! M.E.Matthew E. Newman
Free Windows Admin Tool Kit Click here and download it now
January 28th, 2009 10:16pm

http://cas.domain.local instead of https://cas.domain.localwhich I fixed via the Exchange Management Console -> Server Configuration ->Client Access Server -> Offline Address Distribution tab. Thank you very much for this help.I got the same problem (With Exchange 2007 SP1, Office 2007 SP2). I just changed http to https (and also add the external url) and everything is working fine now (no more annoying login prompt when starting Outlook 2007).Regards,Fred
May 20th, 2009 9:27am

We just had one user experiencing this error after he changed his domain password. I checked out the event log for that user's workstation, and saw a Kerberos/14 error: "There were password errors using the Credential Manager. To remedy, launch the Stored User Names and Passwords control panel applet, and reenter the password for the credential domain.local\user."I had the user do this, and it resolved the issue.
Free Windows Admin Tool Kit Click here and download it now
November 26th, 2009 3:54am

First, Thank You Funj for pointing me in the right direction. I ran the Outlook connection test, and noticed some strings had failed to authenticate even though all URL's were correct. Checked the server and found DCOM errors pertaining to the computer in question. I determined it was Norton Internet Security 2009 blocking a port. Cant remember which port, but I think it was whatever COM+ uses. (COM+ Network Access (DCOM In) I was making it more difficult for myself by looking at all these posts for the issue, and skipped the obvious troubleshooting steps. I hope this helps someone. Thanks Again Funj. I never had a reason to run the connection test before........ Now I know:)
January 5th, 2010 5:59am

It is an autodiscover issue. You either have to configure autodiscover or if you install Rollup 9 for Exchange 2007 it will remove the issue alltogether. Rollup 9 changes the behavior of exchange 2007 so it does not require autodiscover configuration for internal users. You can read more about it here http://blogs.technet.com/SBS/ look on the page for Outlook 2007 prompts.
Free Windows Admin Tool Kit Click here and download it now
February 10th, 2010 1:12am

Very easy to solve Start >> Administrative Tools >> IIS >> (your server name) >> Authentication >> Windows Authentication >> Enable Pop up goes awayLet me know if it works for u.Joggie Claassen
March 3rd, 2010 9:50pm

Joggie - half an hour and no popups... I've tried loads of fixes so far and nothing has worked. Hopefully this has nailed it! Will update you if it comes back again. Thanks...
Free Windows Admin Tool Kit Click here and download it now
March 10th, 2010 12:21am

My two cents worth... lots of good advice here and you may need to apply more than one solution. I did most if not all of the above tweaks, and finally got the problem to go away for good with one final change: Start the IIS Manager on your CAS server, go to Default Web Site > Autodiscover (virtual directory) > properties > Security. I added the "Authenticated Users" group. Permissions: read/execute, list folder contents, read. Then restart IIS. Many thanks for MS Support's help with this; it took us about 7 hours on the phone to get to this solution!
April 2nd, 2010 1:58am

I think it as a kerberos error. could you please check by setting NTLM authentication on the outlook side.
Free Windows Admin Tool Kit Click here and download it now
April 4th, 2010 7:41pm

Santhos is probably correct. I work as IT system consultant and have many Exhange using companies as my customers. A few of them had this problem. Seeing through all the suggestions here, some of them are correct for their problem. But i wanted to post here to explain something very important. I solved this issue where i had checked everything stated here, pluss more. From the symptoms i always thought it was some autodiscover issue, and that it had to be related to authentication. Here is a worklist of what you need to check if you have this issue. See abowe post for more details on each step. 1. Make sure that your SSL certificate is working. Test Outlook Web Mail. If SSL is working as intended go to step 2. 2. Check all internal and external URL. Also the SCP (Get-ClientAccessServer | fl) 3. Verify if you get a result from https://mail.domain.com/autodiscover/autodiscover.xml (swap mail.domain.com with your AutoDiscoverServiceInternalUri - see step 2.). 4. Dobbel check that you got Windows authentication = enabled, on the Autodiscover site in IIS. Also the main fix for my issue was to ensure that under advanced settings of Windows Authentication you have kernel mode authentication enabled!!! On my customers server it was off. And it was standard install with no modifications in IIS. Hope this helps those that still struggle with this issue.
May 11th, 2010 12:17am

Kennet Many thanks after following all of the above, it was the little nugget of information about enabling kernal mode that solved my problems
Free Windows Admin Tool Kit Click here and download it now
June 23rd, 2010 5:28pm

Ok looking at the checklist from Santhos when I get to setp 3 and get the ISA Forms Based Authentication. It is set up that way so we can use the same url internally or externally. I have a redirect rule written for OWA 2007 on ISA to enable this to happen. Yes if I remove the redirect rule everything seems to work just fine. Any ideas what the best way to do this would be for both internal and external resolution of OWA?
June 30th, 2010 12:42am

Ok After much searching again here is a site I found that answered my specific question from above. http://www.messagingtalk.org/exchange-2007-owa-url-redirection-using-isa-2006 Had to work out the issues with all traffic being redirected from the common url vs just OWA traffic internally.
Free Windows Admin Tool Kit Click here and download it now
July 9th, 2010 8:48pm

This is what fixed my problem which had to do with the proxy settings in my IE. Once I put my exchange server DNS in the Exceptions field the prompt stopped ie https:\\jh002.companyname.com, see link for further explaination.... http://trycatch.be/blogs/pdtit/archive/2008/01/30/outlook-2007-autodiscover-authentication-popup-mistery.aspx
October 15th, 2010 10:00pm

My outlook 2007 cred. pop-up issue was fixed when i disabled basic authentication for the autodiscover site. Only Windows Authentication Enabled
Free Windows Admin Tool Kit Click here and download it now
November 26th, 2010 1:30pm

My environment is SBS 2008 using Exchange 2007 with XP Professional and Windows 7 Professional clients, all using Outlook 2007. My problem appears to be the same as the rest of you, but none of the fixes suggested above solve the problem. When my clients, all of which are on the same network as the SBS 2008 server, open their Outlook they get the popup depicted a title of Connect to Server001.companyname.local and stating Connecting to remote.companynameprofession.com. Once they have provided their credentials (domain\username and password), the popup will reappear several times. If they click on cancel after having provided the correct credentials the first time, it connects, and it will be a few minutes before the popup starts happening again. You may wish to note that the internal domain is companyname.local, and the server name is server001. The outside domain is companynameprofession.com, and all default email addresses are username@companynameprofession.com. Exchange 2007 is set up to receive email addressed to users at companyname.local and users at companynameprofession.com, and remote.companynameprofession.com is the FQDN assigned by SBS 2008/Exchange in the initial configuration process. I have tried most of the fixes suggested in this link to no avail. I’m pretty sure this is an autodiscover problem. The autodiscover DNS entry does exist as does all of the A records for companyname.local. Both the autodiscovery DNS entry and the A record for server001.companyname.local point to the same IP address. If I run the Get-ClientAccessServer |fl command; I get: [PS] C:\Users\user\Desktop>Get-clientaccessserver |fl Name : SERVER001 OutlookAnywhereEnabled : True AutoDiscoverServiceCN : SERVER001 AutoDiscoverServiceClassName : ms-Exchange-AutoDiscover-Service AutoDiscoverServiceInternalUri : https://remote.companynameprofession.com/Autodis cover/Autodiscover.xml AutoDiscoverServiceGuid : 77378f46-2c66-4aa9-a6a6-3e7a48b19596 AutoDiscoverSiteScope : {Default-First-Site-Name} IsValid : True OriginatingServer : SERVER001.companyname.local ExchangeVersion : 0.1 (8.0.535.0) DistinguishedName : CN=SERVER001,CN=Servers,CN=Exchange Administra tive Group (FYDIBOHF23SPDLT),CN=Administrative Groups,CN=First Organization,CN=Microsoft Exc hange,CN=Services,CN=Configuration,DC=companyname ,DC=local Identity : SERVER001 Guid : b7219d3b-3df6-4a32-b054-d49a5834498c ObjectCategory : companyname.local/Configuration/Schema/ms-Exch-Ex change-Server ObjectClass : {top, server, msExchExchangeServer} WhenChanged : 11/16/2010 1:57:48 PM WhenCreated : 11/10/2010 2:52:01 PM [PS] C:\Users\user\Desktop> If I try to browse from a client PC to https://remote.companynameprofession.com/Autodiscover/Autodiscover.xml, I get a credentials challenge: I enter my credentials (which, by the way, have administrative rights), and after telling it OK 3 times I get: HTTP Error 401.1 - Unauthorized You do not have permission to view this directory or page using the credentials that you supplied. If I look at the certificate, which is self issued, I see the following Subject Alternative Names: DNS Name=companynameprofession.com DNS Name=remote.companynameprofession.com DNS Name=SERVER001.companyname.local I would kill for a solution. I cannot find anything that is wrong, and I can’t make the problem go away. Anyone able to kelp??
December 1st, 2010 3:28am

GreyFox, I have exactly same issue as you have/had. I have tried all the fixes suggested to no avail. Did you ever solve your issue? Thanks in advance for any help!
Free Windows Admin Tool Kit Click here and download it now
January 19th, 2011 6:07am

Follow FUNJ's instructions about OAB and also uninstall Microsoft Outlook Update KB2412171 which causes the email address for Autodiscover not show correctly.
March 8th, 2011 10:06am

Finally!!! I think I found a sollution for my problem with SBS 2008/Exchange 2007/Outlook 2007 authentication system, both over RPC and regular. Just keeps asking for password! Tried a million things just like the others, no joy. Went into IIS Manager, opened SBS Web Applications, Select Owa, double click SSL settings, check Accept instead of ignore or require, and Apply. I repeated for remote, Rpc, RpcWithCert. leave Autodiscover on Ignore in order to make it continue to work. Add Basic Authentication on RPC and RPC with Cert. Restarted Web Publishing and IIS Admin, and YES!!! Finally I got rid of Outlook 2007 continously asking for password! Joy Joy Joy!!!
Free Windows Admin Tool Kit Click here and download it now
March 29th, 2011 1:52am

I thought I had, but it came up again after about 30 minutes. I searched and found this site. It seems to have worked. http://www.thesystemsengineer.com/technical/outlook-2007-logon-prompt-on-exchange-2007/ Hope this helps out anyone else.
August 18th, 2011 7:59am

What worked for me. Control Panel > Mail > Email Accounts > Microsoft Exchange | Change... > More Settings > Security > Password Authentication (NTLM) Change from Negotiate Authentication My problem was when I installed Office 2007 and attempted to setup a mail profile, constant prompting would occur while setting up the mail profile. It would not let me even create it. Once the changes above were made, prolem went away. The connect is strictly used on the internal LAN and is used to backup mailboxes.
Free Windows Admin Tool Kit Click here and download it now
September 21st, 2011 6:39pm

I resolved by changing to ignore Client Certificates in the SSL Settings for the autodiscover site in the IIS.
October 14th, 2011 10:25am

I resolved by changing to ignore Client Certificates in the SSL Settings for the autodiscover site in the IIS. Yes, this works. Moreover, you're probably have to do the same for EWS directory. In our environment we set up a private CA and used it to issue certificate for Exchange services. As far as for users. But in case of users certificates we provide only disk encryption purposes. What is the actual meaning of "Client certificates" settings in IIS? How to interpret them? Which client certificates does it talking about? And what about credentials promts in this case? Does it concern private CA? Could somebody clarify the situation?
Free Windows Admin Tool Kit Click here and download it now
March 7th, 2012 10:18am

This article from MS did the trick for me. Perhaps it's the same one referenced earlier in the thread but wasn't working. http://support.microsoft.com/kb/956531
March 26th, 2012 5:11pm

Im having the a similar problem as well, first thing I checked was the autodiscover url at https://exchsrv.company.com/autodiscover/autodiscover.xml and discovered that integrated windows authentication wasnt logging me in but the weird thing is when I use https://exchsrv/autodiscover/autodiscover.xml, it works fine, it seems it doesnt like FQDNs, im using a UCC certificate for my exchange server, even my OWA doesnt like FQDN, anyone can point me in the right direction ? thanks
Free Windows Admin Tool Kit Click here and download it now
April 18th, 2012 2:35am

Edit the registry key on the client machines like so: [HKEY_CURRENT_USER\Software\Microsoft\Office\12.0\Outlook\RPC] "UseWindowsUserCredentials"=dword:00000001 This is what we did under each profile that was having the issue. Resolved. If I remembered where we found the fix I would link to it. Good luck!
June 4th, 2012 4:03pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics