Event ID 2008 warning from Event Source MSExchange OAuth appearing randomly

Allen Terry 16 Reputation points
2020-10-14T15:48:03.247+00:00

The following two event log entries are appearing once or twice a month seemingly at random. They will spam us with hundreds of warnings for about a day and then stop. It has happened on 10/14/2020, 10/6/2020 and 9/15/2020 – 9 /16/2020. It has happened a couple other times also, but I don’t have the dates. They started after we configured our Exchange Organization in a hybrid configuration and enabled OAuth. Our Microsoft Exchange Server Auth Certificate is valid.

Log Name: Application
Source: MSExchange OAuth
Date: 10/14/2020 10:42:30 AM
Event ID: 2008
Task Category: Configuration
Level: Warning
Keywords: Classic
User: N/A
Computer: <Exchange_Server>
Description:
When retrieving metadata from the url 'https://login.windows.net/<Our_Domain_Name>/federationmetadata/2007-06/federationmetadata.xml', different certificate(s) have been found.

Log Name: Application
Source: MSExchange OAuth
Date: 10/14/2020 10:42:30 AM
Event ID: 2008
Task Category: Configuration
Level: Warning
Keywords: Classic
User: N/A
Computer: <Exchange_Server>
Description:
When retrieving metadata from the url 'https://accounts.accesscontrol.windows.net/<Our_Domain_Name>//metadata/json/1', different certificate(s) have been found.

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,357 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,896 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Lydia Zhou - MSFT 2,371 Reputation points Microsoft Employee
    2020-10-15T04:12:11.52+00:00

    @Allen Terry

    Do you have other partner applications that have the certificate imported? You may have to remove the partner application and re-configure it.

    Get-PartnerApplication  
    Remove-PartnerApplication <application name>  
    .\Configure-EnterprisePartnerApplication.ps1 -AuthMetadataUrl '<url>' -ApplicationType <type>  
    

    Here are similar issues for your reference:
    Exchange 2016 / Skype for Business - MSExchange OAuth Error,
    Exchange 2013 Partner Applications and Error 2008.
    Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

  2. Andy David - MVP 142.2K Reputation points MVP
    2020-10-15T11:32:37.82+00:00

    Hi @Allen Terry

    I see this all the time and now just ignore them. There doesnt seem to be an actual issue.
    Sometimes this clears it for awhile and its perfectly safe to run:
    Get-Federationtrust | Set-FederationTrust –RefreshMetadata

    Others have seen this as well:

    https://techcommunity.microsoft.com/t5/exchange/exchange-oauth-different-certificate-s-have-been-found/m-p/1450541