Share via

Preventing Outlook (Classic) Autodiscover Hijack to Microsoft 365 (AWS WorkMail)

Orion G 5 Reputation points
2025-11-27T00:59:11.6233333+00:00

Our company has used AWS workmail for years, however recently, our users, have one by one, been affected by outlook hijacking & priorizing Microsoft Exchange.

This is really painful and has caused alot of stress and wasted time.

The only "solution" we have found to solve this and force outlook to use Workmail Exchange (and not Microsoft exchange) is by following these steps:

***STEP 1
[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\AutoDiscover]
"ExcludeExplicitO365Endpoint"=dword:00000001
"ExcludeHttpsRootDomain"=dword:00000001
"DisableOffice365SimplifiedAccountCreation"=dword:00000001

Don't forget to restart your computer

***STEP 2

  • Clearing any associated (office,outlook,etc..) stored credentials in the window credential manager

***STEP 3

  • Deleting your outlook profile

***STEP 4

  • Start outlook, create a new profile when prompted and then add your email as a Exchange 2013 type.

Alternatively, we could move our emails to Microsoft / other providers but workmail has been integrated within our systems reasonably deeply so it would be a fair amount of work to migrate.


Anyway for more contect, CHAT GPT explains the following (please let me know if any of this is wrong, I'm by no way an expert on this but it does match 100% what our users are experiencing):

This procedure is required due to changes made by Microsoft to how Outlook (Classic) performs Autodiscover and account provisioning. Recent Outlook versions aggressively prioritize Microsoft 365 / Exchange Online endpoints over third‑party Exchange services such as AWS WorkMail.

As a result, even when AWS WorkMail is correctly configured and functioning, Outlook may:

  • Silently redirect the mailbox to Microsoft Exchange Online
  • Display the error: “Your mailbox has been temporarily moved to Microsoft Exchange”
  • Rewrite the Outlook profile to use outlook.office365.com

This behavior is triggered by:

  • Microsoft’s hard‑coded Autodiscover priority rules
  • Microsoft 365 shadow tenants created automatically when users sign into any Microsoft service
  • Cloud‑first identity behavior built into modern Outlook builds

This is NOT caused by:

  • AWS WorkMail
  • DNS misconfiguration alone
  • User error

Now the big question... and I'll write in big letters so no one can miss it (for clarity and not to be agressive just to be 100% clear).

** Is Microsoft planning to "FIX" this behaviour? Or provide a more viable solution?

Additionally, if anybody else has any insight/help, please let me know, it would be much appreciated.

Outlook | Windows | Classic Outlook for Windows | For business
0 comments No comments

2 answers

Sort by: Most helpful
  1. Matthew-P 11,985 Reputation points Microsoft External Staff Moderator
    2025-11-27T03:02:22.8866667+00:00

    Hi Orion G,

    Welcome to Microsoft Q&A Forum! Have a good day and I hope you're doing well! 

    Thank you for sharing the details of your situation. I completely understand how frustrating and time-consuming it can be when Outlook keeps prioritizing Microsoft 365 instead of AWS WorkMail. This issue occurs because Outlook (Classic) uses Autodiscover logic that is designed to favor Microsoft 365 endpoints, which can lead to “hijacking” the profile even though WorkMail is functioning correctly. 

    Based on my research, there is no official roadmap or announcement indicating that Microsoft will revert or change the default Autodiscover logic that prioritizes Microsoft 365 endpoints. This behavior is by design in modern Outlook builds. 

    However, I’ve researched and found a practical solution you can implement to reduce or prevent this issue. 

    Beyond manual registry edits, you can implement a more stable, organization-wide solution using Group Policy. Microsoft provides official guidance on how to control or limit Autodiscover methods through GPO, ensuring consistent application across all users and devices.  

    References: How to control AutoDiscover via Group Policy | Microsoft Learn 

    These values can also be set via GPO, either directly as a registry entry, or even more simply with "Administrative Template files for Office". The "Administrative Template files for Office" can also be used to define many other settings for the Office products. 

    1. Download and extract Administrative Template (ADMX/ADML) for Microsoft 365 Apps or Office LTSC from Microsoft. 
    2. Copy the contents of the admx folder to C:\Windows\PolicyDefinitions on your Domain Controller. User's image
    3. Create a new Group Policy in the Group Policy Editor and configure the Autodiscover settings as needed. User's image
    4. Once the GPO is applied, simply restart Outlook for the changes to take effect. 

    The Detailed Instructions: Outlook: Disable Autodiscover for Office 365 - Frankys Web 

    Note: Microsoft is providing this information as a convenience to you. These sites are not controlled by Microsoft, and Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please ensure that you fully understand the risks before using any suggestions from the above link. 

    I hope this helps partially. If you have any concern or questions, feel free to let me know. 


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".    

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread. 

    1 person found this answer helpful.

  2. Q&A Assist
    2025-11-27T01:00:20.85+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    Currently, there is no official information from Microsoft regarding plans to change the behavior of Outlook's Autodiscover process that prioritizes Microsoft 365/Exchange Online over third-party services like AWS WorkMail. The issues you're experiencing are indeed related to Microsoft's hard-coded Autodiscover priority rules and the way Outlook handles account provisioning.

    As a workaround, the steps you've outlined (modifying registry settings, clearing credentials, and creating a new profile) are valid methods to mitigate the issue. However, for any long-term solution or changes in Microsoft's approach, it would be best to keep an eye on updates from Microsoft or reach out to their support for any announcements regarding this behavior.

    If you are looking for community insights or alternative solutions, forums and user groups focused on Outlook and AWS WorkMail may provide additional support and shared experiences from other users facing similar challenges.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.