ECP is broken on On-prem Exchange 2016 servers for accounts with cloud mailboxes (hybrid setup)

Chris Fox 1 Reputation point
2021-08-25T02:00:50.887+00:00

Hi Pros,

This is an interesting one. I can no longer log in to the ECP on my on-prem servers using my account that has a cloud mailbox.

We have on-prem AD synched to Azure and our staff have cloud mailboxes. We have hybrid Exchange as we still maintain a lot of shared mailboxes on-prem, and our mail routes through ourt on-prem servers to use some signature software. So I log in to Office 365 using my on-prem acocunt and access resources as required. I also have an admin account that I use to administer servers etc. This account has an on-prem mailbox.

Late last week I was changing settings on our on-prem public facing servers to disable TLS 1.0 and 1.1, as well as trying to hide some server headers (as a result of a recent audit that recommended tightening security) and since then, I am unable to log in to the ECP using my account that has a cloud mailbox. I get the "This page isn't working right now - server.domain.com.au can't currently handle this request - http error 503" page, after I enter my credentials and clisk "Sign in". So I get the login page fine, but it goes no further. If I login using my admin account it logs in fine and I can work in the ECP. The only difference that I can think of is it has an on-prem mailbox (and is in the domain admins group of course, but my personal account is in the Exchange admin groups so it is the one I normally used for ECP, so not a permissions thing) where my personal acocunt has a cloud mailbox, but still exists in the on-prem Exchange as an "Office 365" user. I have rolled back all the changes that I had made last week and restarted servers but no joy.

I'd possibly leave it as is because there is no impact yet for end users, but one of the other engineer's admin acocunt has a cloud mailbox, so he isn't able to access the ECP and it impacts his ability to administer the system.

The only thing I have noticed is in the HTTPERR logs, there are lines like the below when I try and login...

2021-08-25 01:36:55 127.0.0.1 16989 127.0.0.1 443 HTTP/1.1 GET /ecp/ - - 1 Request_Cancelled MSExchangeECPAppPool

followed by this, which is my PC connected to the server (my PC is 10.0.50.33)...

2021-08-25 01:37:00 10.0.50.33 61869 172.16.84.158 443 - - - - - - Timer_ConnectionIdle -

Any ideas?

Exchange | Hybrid management
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. KyleXu-MSFT 26,396 Reputation points
    2021-08-26T01:40:16.977+00:00

    @Chris Fox

    Even an AD account without a mailbox could log in normally, it the AD permission is correct:
    126532-qa-kyle-09-37-10.png

    So, make sure the permission is correct, and make sure login ECP with "LocalDomain/user"(You need to login ECP with local AD credentials). I would suggest you try to create another admin account to check whether your ECP could working normally first.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.