Using Classic Outlook on Windows for personal email, calendar, and contact management
FINALLY A STRAIGHT ANSWER FROM MICROSOFT!
Hello Lars,
Please check this and follow the below steps and let me know of the outcome. and if you needed any help, please let me know.
What Causes Error 1001?
There are several possible causes of error 1001, such as:
- Corrupted office registry key under user configuration.
- Customer disabled WAM. (Disabling ADAL or WAM isn't recommended for fixing Office sign-in or activation issues)
- user signed out from office and try to sign-in again
https://learn.microsoft.com/en-us/microsoft-365/troubleshoot/sign-in/office-365-users-not-signed-in-office - WAM components are missing or corrupted.
- Antivirus blocks WAM.
- Wrong configured device identity.
- Using more than one user mailbox in outlook associated with the same domain in same Tenant.
https://learn.microsoft.com/en-us/office/troubleshoot/activation/another-account-already-signed-in - Cached firewall rules in windows registry.
- Missing configuration in CITRIX
How to Fix Error 1001?
Depending on the cause of error 1001, you can try one or more of the following solutions:
- Reset for office activation.
- Fix WAM component.
- Exclude required authentication component from your Antivirus.
- Correct device identity by configuring your device as hybrid join if it is a domain join device.
- Add additional mailboxes using delegated credential.
- Roaming of WAM token when using roaming profile management tools like UPD, FSLOGIX or other tools
- Rest cash for Firewall rules.
- Ask customer to apply CITRIX recommendations:
Fixed issues | Citrix Virtual Apps and Desktops 7 2203 LTSR
How to apply the Fix?
Depending on the cause of error 1001, you can try one or more of the following solutions:
-Reset for office activation.
- Make sure to close all running office desktop applications, OneDrive, and teams.
- To reset office activation, the affected user should be member of the local administrators on the device.
- To promote the user as an admin on device you can use these steps. Make sure to remove the user after troubleshooting is done.
- In Windows press Windows button + R to open the Run and type “lusrmgr.msc” for opening the windows Local user and group manager.
- you can just start CMD as admin and type same command “lusrmgr.msc”.
- Make sure you run it as an admin.
- Select Groups → then double-click on "Administrators" -> Add -> Locations -> [select domain] -> Enter Username in Box -> Check Names -> then “OK.”
- If not then running the scripts should be done twice, one time as a user and another one as an administrator.
- Scripts required to be run are:
- OLicenseCleanup.vbs
Download the OLicenseCleanup.zip file, extract the OLicenseCleanup.vbs script, and run it using the following command in CMD:
cscript OLicenseCleanup.vbs - signoutofwamaccounts.ps1
Download the signoutofwamaccounts.zip file, extract, and run the signoutofwamaccounts.ps1 script with elevated permissions.
.\ signoutofwamaccounts.ps1
make sure running scripts is allowed on the device. If not use this PowerShell command to allow it:
Set-ExecutionPolicy -ExecutionPolicy Unrestricted - WPJCleanUp.cmd
Download WPJCleanUp.zip, extract the WPJCleanUp folder, and run WPJCleanUp.cmd as user and not as admin.
-Fix WAM component.
to make sure that WAM components are present, run the two PowerShell commands in the following article:
If you use office desktop application on RDS, AVD or VDI, then make sure to have these commands as part of a logon script for the users.
-Roaming of WAM token when using roaming profile management tools like UPD, FSLOGIX or other tools
Roaming of WAM token is not supported, since these tokens are encrypted with a session key, which will be stored on the device during token acquisition, therefore roaming the token causes authentication loop for users.
Make sure to exclude the token following folders from roaming with the user profile:
%localappdata%\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC\TokenBroker
%localappdata%\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\LocalState
%localappdata%\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
%localappdata%\Microsoft\TokenBroker
%localappdata%\Microsoft\OneAuth
%localappdata%\Microsoft\IdentityCache
-Exclude required authentication component from your Antivirus.
Make sure you exclude the component listed in the following article in your Antivirus configuration.
https://learn.microsoft.com/en-us/microsoft-365/troubleshoot/authentication/cannot-sign-in-microsoft-365-desktop-apps
%windir%\SystemApps\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
%localappdata%\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
%windir%\SystemApps\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
%localappdata%\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
%localappdata%\Microsoft\TokenBroker
%localappdata%\Microsoft\OneAuth
%localappdata%\Microsoft\IdentityCache
-Correct device identity by configuring your device as hybrid join if it is a domain join device.
- The preferred device identity for a domain join device is hybrid join.
- Workplace Join is not supported on RDS, AVD or VDI.
- You need to instruct customers to block it using registry.
- You can run this command as admin in PowerShell on affected RDS server:
Set-ItemProperty HKLM:\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin -Name BlockAADWorkplaceJoin -Type DWord -Value 1 - You can make it available to all organizational devices.
https://learn.microsoft.com/en-us/entra/identity/devices/how-to-hybrid-join
- or apply it to a specified set of devices.
https://learn.microsoft.com/en-us/entra/identity/devices/hybrid-join-control
-Add additional mailboxes using delegated credential.
Add a shared mailbox as an additional account in Outlook Desktop - Outlook | Microsoft Learn
-Cached firewall rules in windows registry.
Use the following commands to reset Firewall rules:
Remove-Item "HKLM:\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\AppIso\FirewallRules"
New-Item "HKLM:\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\AppIso\FirewallRules
-Missing configuration in CITRIX
Confirm that issue is not reproducible outside CITRIX or in full desktop versions and only to published applications.
Use the following commands to create required registry entry as per CITRIX recommendations:
Set-ItemProperty "HKLM:\SOFTWARE\Citrix\Citrix Virtual Desktop Agent" -Name Shellbridge -Type DWord -Value 1
**Note:**If the issue can’t be reproduced when logging directly to the server, and the configuration for CITRIX did not help, the customer needs to involve CITRIX support in this situation
Scop and logs required for escalation:
- Affected application (only Outlook, all Office Apps);
- Number of affected users.
- Number of affected devices.
- How does it happen? Is it when they sign in for the first time? When they open a new session? When they open specific files?
- Is it reproducible or sporadic?
- Windows(server/client) version and build.
- Office version and build.
- Physical or virtualized environment.
- Details on their networking including Antivirus/Proxy/Firewall
- How are they managing users' profiles: UPD, FSLogix, Citrix,…?
- Details on their network include Proxy/Firewall.
- MSOAID logs
https://learn.microsoft.com/en-us/microsoft-365/troubleshoot/diagnostic-logs/use-msoaid-for-authentication-issues - Output for the command “dsregcmd /status” in CMD as user