Outlook login issues after Exchange 2019 cu13 and KB5026261 updates. Gone when “Cached Exchange mode” is turned off

Justin Mann 0 Reputation points
2023-07-13T14:12:17.9166667+00:00

Hi,

We were asked to post our question from different MS forum to here,
as this would be the correct place?
(see https://answers.microsoft.com/en-us/outlook_com/forum/all/outlook-login-issues-after-exchange-2019-cu13-and/493916bf-4133-4ebd-820e-e807eaf126c6 )

We have an On-premises Exchange server 2019 running on server 2022, which we last weekend updated from cu12 to cu13. Then we added the June exchange server Security Update For Exchange Server 2019 CU13 (KB5026261) onto the Exchange server.
The server 2022 is at the latest patch level.

Since the update of the Exchange server (with these two patches), sporadic Outlook 2016, 2019 (and a old test system with Outlook 2013) get a login screen directly when starting Outlook, making it unusable.

We 1st fixed this issue by creating a new Outlook profile.
Outlook for the first time starts without any issues.
Though after the user exists Outlook and starts Outlook, the login screen reappears.

Second, we renamed the “Outlook” directory located in
c:\Users<username>\AppData\Local\Microsoft
Then Outlook will start without a login screen.
Until all folders are synched and Outlook is closed ……
The temporary fix was to delete the Outlook folder again (and again …)

In both cases, it takes a while until the user sees all of the emails, because “cached exchange mode” is enabled within the domain.

When the user gets the unexpected login on the German client system, we get the following event log entries, some in Italian ???

Event Type: Information
Event Source: Outlook
Event Category: None
Event ID: 19
Date: 11.07.2023
Time: 11:04:10
User: N/A
Computer: computer.test.domain
Description:
Chiamata RPC (EcDoConnectEx) durante il trasporto (unknown) al server (https://mail.test.domain/mapi/emsmdb/?MailboxId=aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee@test.domain)
non riuscita con codice di errore (80040413) dopo un'attesa di (6078) ms; eeInfo (none).

Event Type: Information
Event Source: Outlook
Event Category: None
Event ID: 19
Date: 11.07.2023
Time: 11:04:10
User: N/A
Computer: computer.test.domain
Description:
Chiamata RPC (NspiBind) durante il trasporto (unknown) al server (blocked-by-it-https://mail.test.domain/mapi/nspi/?MailboxId=aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee@test.domain)
non riuscita con codice di errore (80040413) dopo un'attesa di (8235) ms; eeInfo (none).

Event Type: Information
Event Source: Outlook
Event Category: None
Event ID: 19
Date: 11.07.2023
Time: 11:04:10
User: N/A
Computer: computer.test.domain
Description:
Chiamata RPC (EcDoConnectEx) durante il trasporto (unknown) al server (blocked-by-it-https://mail.test.domain/mapi/emsmdb/?MailboxId=aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee@test.domain)
non riuscita con codice di errore (80040413) dopo un'attesa di (6766) ms; eeInfo (none).

Event Type: Information Event Source: Outlook Event Category: None Event ID: 63 Date: 11.07.2023 Time: 11:04:10 User: N/A Computer: computer.test.domain Description: Die Exchange-Webdienstanforderung "GetAppManifests" ist fehlgeschlagen. Fehlercode: 0 HTTP-Antwortcode: 401 Zusätzliche Fehlermeldung: Es ist ein unbekannter interner Fehler aufgetreten. Fehlercode: 80004005

We checked DNS, Dhcp and Wins settings and could not find any issues.

Then we went into the GPO settings and disabled the
“Use Cached Exchange mode for new and existing Outlook profiles”
in Policies -> Windows Settings -> Administrative Templates -> Microsoft Outlook 2016 -> Account Settings -> Exchange -> Cached Exchange Mode

After this setting was disabled within the domain, the Outlook login problems disappeared.
All users who reported the problem can now use Outlook without a login dialog blocking access to outlook.

I wonder,
what does the “Cached Exchange mode”
have to do with the login to the Exchange server, this does not make any sense.
Also, that I cannot find any KB Articles related to this very strange behavior.

We alco received complaints, that the Exchange server based search is also no longer working correctly since the Exchange Server was updated (the search never ends and displays an error that “we have problems accessing results from the server, search on local computer instead?).

This is all very strange,
I wonder if MS is aware of these issues and if a fix is available (this cannot be by design?).
We cannot find anything on the Internet which can fix this issue.

We also have the option “ExcludeExplicitO365Endpoint" set to 1 in HKEY_CURRENT_USER\SOFTWARE\Microsoft\office\16.0\outlook\autodiscover
within our network.

Best Regards,
J.Mann

Outlook
Outlook
A family of Microsoft email and calendar products.
3,096 questions
Outlook Management
Outlook Management
Outlook: A family of Microsoft email and calendar products.Management: The act or process of organizing, handling, directing or controlling something.
4,939 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,386 questions
{count} votes

6 answers

Sort by: Most helpful
  1. Szabó László 5 Reputation points
    2023-07-18T07:08:09.18+00:00

    Hi @Justin Mann ,

    If you use NTLM authentication, try this:

    https://www.stephenwagner.com/2017/11/05/mapi-over-http-outlook-password-prompt-external-users/

    Regards:

    Szabó László

    1 person found this answer helpful.
    0 comments No comments

  2. Shaofan Lv-MSFT 6,840 Reputation points Microsoft Vendor
    2023-07-14T07:29:22.2666667+00:00

    Hi @Justin Mann ,

    This indeed sounds weird that the login issue only occurs in Cached Exchange mode. As regards to your concern about the recent update, I tried searching around but so far haven’t seen similar reports. I also checked the known issues related to Exchange2019CU13, but didn't seem to find the problem you mentioned. In the following blog about the security updates, it seems that no related issues have been posted in the discussion area.

    Blog: Released: June 2023 Exchange Server Security Updates

    In addition, to understand your problem more intuitively, can you provide us with a screenshot when the problem occurs?

    Regards

    Shaofan


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment". 

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.  


  3. Justin Mann 0 Reputation points
    2023-07-17T12:43:13.65+00:00

    We are now continuously able to reproduce the login error with an old Office 2013 (latest version, no longer supported by MS) on a server 2012 r2 terminal server.

    We tried to reproduce the error with Office 2016 and 2019 without success, because the error happens too sporadic. We had users report that the could not log in, when we checked, then the error was gone.

    The login screen is slightly different to the 1st screenshot, office is stuck with a "wird verarbeitet (is beeing processed)" at the bottom of the Outlook dialoge wthen the login appears.grafik


  4. Justin Mann 0 Reputation points
    2023-07-17T12:46:22.3666667+00:00

    This is what the connection status looks like, when

    1st, after the Outlook profile is created, where Outllok starts without issues,
    then
    2nd, Outlook is started a 2nd time, with log screen.
    (screenshot is very wide!), Authentication indicates Fehler* (error*)

    grafik

    0 comments No comments

  5. Justin Mann 0 Reputation points
    2023-07-19T10:25:52.9366667+00:00

    We reviewd the Article from Szabó László, which didn't quite help.

    Also compared the server virtual directory settings

    • between a Exchange 2019 which we patched in Japan, which is working,
    • and our patched exchange server 2019.
      We found the one difference:

    grafik

    If I turn on "Windows Authentication - Negotiate",
    then nobody can work with the Exchange server,
    everybody with Outlook 2013, 2016 and 2019 will then get the login dialog
    preventing access to the server, even if Outlook Exchange Caching is disabled,
    so we turned it off again for now.

    Best
    Justin