MailExchange ADFS Authentication Errors

Nguyen Thanh Tung 1 Reputation point
2021-05-30T10:17:45.987+00:00

I have issue with ADFS authentication on My exchange server. The problem encountered in the ADFS 3.0 of the window server 2012 and exchange server 2013 cu22. I followed the below instruction link to config AD FS claims-based authentication with Outlook Web App and EAC:
https://learn.microsoft.com/en-us/exchange/using-ad-fs-claims-based-authentication-with-outlook-web-app-and-eac-exchange-2013-help
In my web browser (Chrome, Firefox), I sign in OWA, response returns the http error 401. I try to sign in EAC by type my username (domain\user) and password, EAC show message "An error occurred. Contact your administrator for more information". I check event viewer of Exchange Server, there are no errors in event viewer. I check event viewer of ADFS server, the following error was reported:
ncountered error during federation passive request.

Additional Data

Protocol Name:
wsfed

Relying Party:
https://mailsrv.contoso.com/ecp/

Exception details:
Microsoft.IdentityServer.Web.InvalidRequestException: MSIS7042: The same client browser session has made '6' requests in the last '1' seconds. Contact your administrator for details.
at Microsoft.IdentityServer.Web.Protocols.PassiveProtocolHandler.UpdateLoopDetectionCookie(WrappedHttpListenerContext context)
at Microsoft.IdentityServer.Web.Protocols.WSFederation.WSFederationProtocolHandler.SendSignInResponse(WSFederationContext context, MSISSignInResponse response)
at Microsoft.IdentityServer.Web.PassiveProtocolListener.ProcessProtocolRequest(ProtocolContext protocolContext, PassiveProtocolHandler protocolHandler)
at Microsoft.IdentityServer.Web.PassiveProtocolListener.OnGetContext(WrappedHttpListenerContext context)

I already search in google about error MSIS7042 but nothing can solve my problem.
Any idea to help me?
Thank for your help.

Microsoft Security | Active Directory Federation Services
Exchange | Exchange Server | Management
Exchange | Exchange Server | Management
The administration and maintenance of Microsoft Exchange Server to ensure secure, reliable, and efficient email and collaboration services across an organization.
{count} votes

4 answers

Sort by: Most helpful
  1. Andy David - MVP 159.7K Reputation points MVP Volunteer Moderator
    2021-05-30T14:53:18.05+00:00

    My first thought is a browser add-in is causing this.
    Can you try disabling the add-ins on the one you are using?
    Also try in incognito mode.

    0 comments No comments

  2. Nguyen Thanh Tung 1 Reputation point
    2021-05-31T02:11:36.913+00:00

    I think browser add-in is not reason because chrome/firefox have just installed. I also try in incognito mode before I create this issue.
    I send SAML-Tracer image and SAML trace log.

    100905-image.png

    0 comments No comments

  3. Nguyen Thanh Tung 1 Reputation point
    2021-06-03T05:44:48.787+00:00

    can anyone help me? Thank you so much.


  4. Rohith Udupa 1 Reputation point
    2022-11-18T11:21:20.503+00:00

    @Nguyen Thanh Tung I have the exact same issue. OWA gives me 401 and ECP access loops and ends up at ADFS with an error.

    Were you able to solve this?
    Thanks in Advance

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.