Audit failures on Exchange 2010 and password prompts in outlook

Starting last Thursday after I patched my domain controllers and other Windows systems and rebooted my Outlook users are being prompted for username/password continuously and my Exchange security logs reflect audit failures for NTLM which I think is triggering
the prompt. The same users also have an audit success via Kerberos.
If the password prompt it cancelled Outlook can send and receive email just fine but the box continues to pop up occasionally.
I've worked on this for several days now and can't figure it out. The audit logs on the DC's are clean with no audit failures.
The issue is also affecting Visual Studio users who log into a Team Foundation Server, they are continually prompted for credentials and can't get in and the audit logs show the same thing.
I don't think this is an Exchange specific issue but more of a broader authentication problem.
Can anyone shed any light on this?
An account failed to log on.
Subject:
Security ID: NULL SID
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 3
Account For Which Logon Failed:
Security ID: NULL SID
Account Name: mart.marc
Account Domain:  AOF
Failure Information:
Failure Reason: An Error occured during Logon.
Status: 0xc000006d
Sub Status: 0x0
Process Information:
Caller Process ID: 0x0
Caller Process Name: -
Network Information:
Workstation Name: AOG-LP047
Source Network Address: 10.10.1.159
Source Port: 50075
Detailed Authentication Information:
Logon Process: NtLmSsp
Authentication Package: NTLM
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

Hi,
It is a known issue if you install the following security updates on March 10, 2015:
http://support.microsoft.com/en-us/kb/3002657
The user would be prompted with credentials when NTLM is used to authenticate these Active Directory domain users and services. 
We can remove this patch from all the DCs manually and check whether the issue persists.
Regards,
Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
Winnie Liang
TechNet Community Support

Similar Messages

  • Exchange 2003 - Continous password prompts in Outlook 2010

    Hi. 
    A customer is experiencing continous password prompts in Outlook 2010. Outlook is configured against the Exchange 2003 BE server (FQDN) and Outlook Anywhere is configured to sync.customer.com with a valid 3rd party certificate. 
    Outlook is configured with Negotitate as Logon network security, setting this to basic/NTLM does not help. Connect to Microsoft Exchange using HTTP is set and configured with sync.customer.com, and msstd:sync.customer.com. All points checked except "On
    fast networks, connect using HTTP first, then connect using TCP/IP", authentication is set to Basic. Changing authentication from Basic to NTLM seem to make the problem vanish. 
    Outlook Anywhere is functioning correctly and only prompting once for password when connecting from an external network. ISA is not configured for NTLM/Kerberos.
    Exchange 2003 is located in main site in a resource domain. The prompts occur more often in two remote sites than the main site. 
    When opening Outlook RPCDiag shows established connection to BE and Active Directory, sometimes with prompt and sometimes without. After about 5 minutes the prompt may reappear, entering password does not remove the prompt, clicking cancel puts Outlook in
    the "Need password" state, clicking this usually successfully connect Outlook to Exchange. Other times this just cause the prompt to reappear. 
    I´ve tried adding the internal and/or external IP address of the ISA server as sync.customer.com in the host-file on a client and forcing RPC/HTTPS through the DisableRpcTcpFallback, still getting the password prompts. 
    We have also been through the KB975363, changing the MaxConcurrentAPI on all domain controllers. 
    Finally, we know Exchange 2003 is in a unsupported state so there is no need to comment this. 

    Hi,
    Firstly, I'd like to explian, basic authentication requires the user to enter domain, user name, and password. Thus, it's an expected behavior that the credential prompts once when the authentication is set to basic and it disappears when it's NTLM authentication:
    http://technet.microsoft.com/en-us/library/aa996225(v=exchg.65).aspx
    For the issue that the credential keeps prompting, I'd like to confirm if Outlook 2003 works well. If yes, you can refer to the following article:
    http://support.microsoft.com/kb/927612/en-us
    If all outlook clients prompt credential, you can check the RPC over HTTP connectivity by ExRCA:
    https://testconnectivity.microsoft.com/
    http://support.microsoft.com/kb/820281/en-us
    Thanks,
    Angela Shi
    TechNet Community Support

  • Exchange 2010 and iphone calendar sync issues

    Hey,
    I know this question has been asked plenty of times before and just need a straight resolution. We have just migrated our environment to Exchange 2010 and the major issue is that when an event is created in Outlook 2011 it is not always showing up on their iphone and also vis versa. Is their a resolution to this problem so I can implement it in an emergency change. Thank you for all your help!

    Here let me explain the scenario again any user who logs in to exchange from outlook working fine password not expired and he has iphone active sync working no issues , now while all devices are working when he starts his ipad after a week or so when he
    opens his email on ipad it prompts the password on ipad and same time on iPhone , he does not want to enter the password and wants a technical justification , I told the user something to do with Exchange 2010 sp2 and ios 7 ,but that is invalid justification
    . if you have any other valid justification please let me know. or a solution to this issue. user wants to login without any password prompt while the password is saved in device and not expired , is there any feature in Exchange 2010 sp2 that would recognize
    how many days device has not logged it and would force to enter the password.

  • Error synchronizing folder [8004010F-501-8004010F-0] - Exchange 2010 and Outlook 2010, multiple users get dozens of these per day

    15:27:30 Synchronizer Version 14.0.6025
    15:27:30 Synchronizing Mailbox 'abc xyz'
    15:27:30 Error synchronizing folder
    15:27:30
     [8004010F-501-8004010F-0]
    15:27:30
     The client operation failed.
    15:27:30
     Microsoft Exchange Information Store
    15:27:30
     For more information on this failure, click the URL below:
    15:27:30
     http://www.microsoft.com/support/prodredirect/outlook2000_us.asp?err=8004010f-501-8004010f-0
    15:27:30 Done
    kbj

    Hi,
    Please try below steps:
    - Remove all organizational forms libraries (subfolders under EFORMS Registry) if they are not needed, and re-create the Outlook profile of affected users.
    - Alternatively, if the organizational forms libraries are needed, remove the replica from Exchange 2010 and re-add it
    Best Regards!

  • How do i stop an old apple ID and password prompt from always popping up on my phone during normal use ?

    How do i stop an old apple ID and password prompt from popping up on my phone screen during normal operations ?

    How to change the Apple ID on my iOS Device
    Settings > iTunes & App stores.
    Tap your Apple ID, sign out then sign back in with new AppleID.
    Settings > Facetime.
    Tap your Apple ID, sign out then sign back in with new AppleID.
    Settings > Messages.
    Turn off iMessages, wait 10 seconds, then turn it back on.  Go to 'Receive messages at' and then tap your Apple ID.  Sign out of the old ID, then sign in with new Apple ID.
    Settings > iCloud.
    Delete the account (make sure to KEEP the information on your phone), then turn it back on with new Apple ID.
    Also, delete any apps that were downloaded with the 'old' Apple ID, then reinstall them with your 'new' ID.

  • Microsoft Exchange 2010 and Outlook 2013

    My colleagues computer suddenly crashed yesterday and it wouldn't restart without a system restore.
    Now when we try to open up Outlook it says that you must connect to Microsoft Exchange at least once before you can usse your Outlook Data file (.ost)
    Also The PC has lost the trust relationship on the domain
    We have exchange 2010 and the servers OS is Microsoft Windows Small Business Server 2011 and the Client PC is running off of Windows 8.
    Can you please help me resolve this issue?
    kind regards
    Steve Bradshaw
    [email protected]

    It might be possible that the MAPI key (which enables Outlook to synchronize with Exchange) has been deleted due to the System crash. So, in order to establish the connection, you need to Reconnect the OST file to the original MAPI profile and then reconnect
    then MAPI profile to Exchange Server. 
    If the above method fails to resolve the issue, then the best option for you would be to take the help of any professional OST to PST Conversion Software, which will help you to Extract data from your OST file and convert it to PST file which you can import
    back to your Outlook to establish the connection with Exchange Server again.
    You can check this
    presentation for more info.
     

  • Cannot see AAA banner, username and password prompts on IOS switch

    Hi,
    I have configured RADIUS authentication for VTY access to a Catalyst 2960S running 15.0(2)SE2.
    The RADIUS server is a Microsoft server running the Network Policy and Access Service role (Microsoft's own RADIUS server).
    Everything is ok apart from the login prompts. I want to customise these with a banner, username prompt and password prompt. I have added the lines below to my config:
    aaa authentication banner ^Chello^C
    aaa authentication password-prompt "Enter your password:"
    aaa authentication username-prompt "Enter your username:"
    However when I ssh to the switch I just see the output below:
    login as: james.hawkins
    Using keyboard-interactive authentication.
    Password:
    ASWTRE-BF01#
    My config is shown below:
    aaa authentication banner ^Chello^C
    aaa authentication password-prompt "Enter your password:"
    aaa authentication username-prompt "Enter your username:"
    aaa authentication login default local-case
    aaa authentication login SSH group radius local-case
    aaa authentication enable default enable
    aaa authorization exec default local
    aaa authorization exec SSH group radius local
    radius server TREREC-01
    address ipv4 10.3.32.51 auth-port 1812 acct-port 1813
    key 7 08171E61K281D08461C
    line con 0
    logging synchronous
    line vty 0 4
    exec-timeout 360 0
    authorization exec SSH
    logging synchronous
    login authentication SSH
    transport input ssh
    line vty 5 15
    exec-timeout 360 0
    authorization exec SSH
    logging synchronous
    login authentication SSH
    transport input ssh
    Is there anything that I am missing?

    James:
    you use the line:
    aaa authentication login SSH group radius local-case
    are you sure that the RADIUS is reachable? if the radius is not reachable it will check the local DB for the username. I am not pretty sure if local DB auth displays the banner.
    Rating useful replies is more useful than saying "Thank you"

  • Single name space in between Exchange 2010 and 2013

    Hi,
    In my current environment I have 2 Exchange 2010 servers with DAG no CAS NLB. I installed Exchange 2013 with 2 CAS with WNLB and 2 Mailboxes with DAG. The main requirement is to configure Single name space to access in between Exchange 2010 and Exchange
    2013. On Exchange 2010 DAG there is a URL using is owa.domain.com and I also configured in Exchange 2013 all the virtual directories with this name owa.domain.com but having an issue that when I open explorer and use the owa.domain.com URL the user on Exchange
    2013 gets their mailbox but user on Exchange 2010 gets error HTTP 403 blank page.
    I observed that in Exchange Organization settings CAS settings one server OWA, ECP etc shows their internal external URL but the other server unable to open the OWA, ECP URL and give error message that "An IIS directory entry
    couldn't be created. The error message is Access is denied. HResult = -2147024891"
    Please guide how to resolve this issue and use the same name URL in Exchange 2010 and Exchange 2013
    Thanks, 

    Hi,
    See the below brief:
    User will connect to mail.contoso.com as his namespace endpoint. CAS2013 in Site1 will authenticate the user, do a service discovery, and determine that the mailbox version is 2010 and is located within the local AD site. CAS2013 will proxy the
    request to an Exchange 2010 Client Access server which will retrieve the necessary data from the Exchange 2010 Mailbox server
    Go through the full blog for better understanding of the redirection.
    Client Connectivity with Exchange 2013
    Hope you have changed your DNS records to direct connections only to your new Exchange 2013 server. You'll move the host names (for example, mail.contoso.com) users have been using to connect to Outlook Web Access, Autodiscover, and so on, from your
    Exchange 2010 server to your Exchange 2013 server. When an Exchange 2010 user tries to open their mailbox, the Exchange 2013 server will proxy their request and communicate with the Exchange 2010 server on their behalf.
    Configuring DNS includes the following:
    Change the primary host names, such as mail.contoso.com, autodiscover.contoso.com, and owa.contoso.com (if used) to point to the external, publically-accessible, IP address of the Exchange 2013 Client Access server with your public DNS provider.
    Change the primary host names, such as mail.contoso.com (or internal.contoso.com if you're using different internal host names) and owa.contoso.com (if used) to point to the internal machine name of the Exchange 2013 Client Access server on your internal
    DNS servers.
    NOTE- Go through the Exchange Deployemnt Assitant - Configure DNS Records section
    Regards,
    Satyajit
    Please“Vote As Helpful”
    if you find my contribution useful or “MarkAs Answer” if it does answer your question. That will encourage me - and others - to take time out to help you.

  • Cannot purchase songs on iTunes. After I enter Apple ID and password, Prompt says I need toed to verify my Apple ID. I enter my password again and never get the verification email.

    Cannot purchase songs on iTunes. After I enter Apple ID and password, Prompt says I need toed to verify my Apple ID. I enter my password again and never get the verification email although my Apple ID and email are correct? Whats up with that?

    from this support article:
    How do I verify my Apple ID by email? 
    Simply follow the link in the verification email that says "Verify Now." Sign in with your current Apple ID and password, then click Verify Address. You can also verify by signing in at My Apple ID.

  • Exchange 2010 and 2013 coexistence Internal and external URL

    Hi all,
    been reading alot of threads about Outlook anywhere and virtual directories in co-existence exchange 2010 and 2013.
    Still i dont get any smarter.
    Here is scenario:
    Exchange 2010
    Cas1
    Cas2
    Mailbox1
    Mailbox2
    Casarray is Exchange.casarray,com ( internal dns pointed to CAS1 in exchange 2010).Seems like by default both exchange 2013 cas servers are added to the casarray.
    Exchange 2013
    CAS+Mailbox
    Cas+Mailbox
    DNS
    mail.exchange.com pointing to VIP (kemp loadbalancer)
    Autodiscover ( pointed to same vip ,kemp load balancer)
    Outlook anywhere on all servers (2010 and 2013)
    Internal ( pointing to VIP on Kemp)
    External ( pointing to external IP,then it passes firewall that again passes to kemp)
    Problem we are having is when migrating users from Exchange 2010 - 2013.
    Users using Outlook 2010
    restart of outlook and mail  works fine.
    OWA works fine
    Active sync fails ( need to inherit permission of users AD object),wait couple of hours then mobile can sync again.)
    Users using Outlook 2013
    Outlook in disconnected status,only fix is to create new profile.
    OWA works fine
    Active sync fails ( need to inherit permission of users AD object),wait couple of hours then mobile can sync again.)
    Question is,what should be set for internal and external url (active sync,owa,ews)on 2010 and 2013 servers?
    Where is the config wrong?
    Thanks!
    Please mark as helpful if you find my contribution useful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you. Thank you! Off2work

    Hi Martina,
    did the test as mentioned,even tried both CAS 2013 servers.Flush and registerdns didnt help.
    Still Outlook is Connected to the cas.exchange.as (which again Points to 1 of Exchange 2010 servers),
    Tried repair Outlook profile,no og.Only fix is to setup New account.
    Any more tips?
    thanks!
    Please mark as helpful if you find my contribution useful or as an answer if it does answer your question. That will encourage me - and others - to take time out to help you. Thank you! Off2work

  • Mail, Exchange 2010, and certificates

    Hi.
    The company I work for just upgraded their Exchange server to 2010 and all of a sudden my email account in Mail doesn't work anymore. In sheer desperation I tried to connect using Microsoft Outlook and the only way that I could create an account there was by submitting my certificate before entering my email account credentials. I get the feeling that this might be a kind of setting on the server side that someone turned on when we were transferred to Exchange 2010.
    In Mail, when I try to set up my Exchange account there is no way of submitting my certificate, or am I missing something? If not, does anyone know a way around this (by associating Mail with my certificate somehow – I don't know...)
    Many thanks in advance!
    /Cristian

    I added back the send connector on the 2010 exchange. everything still works fine since I still have the send connector on the 2003. However...
    I connected through telnet to server2 (the exchange 2010) and was able to mail internally. however I couldn't send mail externally, it gives me a "cannot relay" error when I enter my rcpt to:... command.
    I am guessing that this may be the reason why the queue is not emptying itself through that send connector.
    Anything else I could try to test my "send connector" on the 2010 exchange?

  • Exchange 2010 and iOS 7

    I am having multiple problems across multiple devices in Exchange 2010 SP2 and devices that upgraded to iOS 7.  I have reset all the settings and re-added the accounts. Any other solutuons for this issue that apple swears is not a bug in the iOS?

    I am running Exchange 2010 and have iOS7 on my phone, and have not seen any problems. My phone is not managed by configuratior.
    What problems are you having?

  • Exchange 2010 and 2003 Co-Existence Help

    Hi All,
    Hopefully someone out there can help me out.
    As the subject says i have exchange 2010 and 2003 in a co-existence mode. I have configured public folder replications and plan to use the following guide to move the public folders:
    http://careexchange.in/moving-public-folders-from-exchange-2003-to-exchange-2010/
    I was about the use the MoveAllReplicas.ps1 powershell script when I had the idea to dismount the legacy (2003) public folder mail store as a test to ensure the public folders had replicated. I noticed under the 'Queues' of the legacy exchange emails were queuing
    up withing 'Messages awaiting directory lookup'.
    All other mail stores were dismounted, as a test I mounted a database (non public folder), did a force connection and refresh. All the emails disappeared from this list.
    So my questions are:
    1. Why would my exchange 2010 sever still be routing emails via the legacy server?
    2. Why would the legacy exchange require a mailstore to be mounted for mail flow to work coming from the 2010 server?
    Thanks

    Thanks for the feedback.
    The issue I am facing is that the emails I am seeing queued are not related to the public folder replications. Emails for the public folder replications normally have a subject line of: 'Backfill' or 'Folder Content'.
    When all mail stores are dismounted on the legacy server some of the outbound emails sent by users who reside on the primary server (2010) are being sent to the legacy server. I can then see these emails queued and they will not be sent until a remount at
    least one mail store.
    E.g. All mailbox stores are dismounted on the legacy exchagn, John Smith's account is located on primary exchange (2010). John sends an email and I see it stuck in the queue on the legacy server  'Messages
    awaiting directory lookup'. 
    NOTE: This does not happen for all users, It seems to happen at Random.
    I also attempted to fix the issue by creating a new 'Send Connector' with a lower cost and defining the 'Source server as the primary server (2010)
    So the question still remains why are some outbound emails still being sent out via the legacy server even though these users are on the primary exchange?
    With regards to the public folders, I used the following to add the replicas between the legacy and primary exchange:
    .\AddReplicaToPFRecursive.ps1 -TopPublicFolder “\” -ServerToAdd “Exchange2010″
    When i dismount the public folders all the public folders are accisable via the 2010 server so it seems the replications have worked.
    Would the above command not have added the replicas to all the public folders including the system public folders?

  • Exchange 2010 and RMS

    Hello Team,
    We are running Exchange 2010 and RMS with Autonomy app which archives older than 30 day emails.
    Parent company is in Tokyo, all incoming email goes through them and then via a hub transport service delivers email to North America.  For some reason, emails are encrypted and the Archive app cant get to them.
    I just want to find how to proceed further and what to do to exclude emails to North America from it.
    Any suggestions would be appreciated !
    Binu Kumar - MCP, MCITP, MCTS , MBA - IT , Director Aarbin Technology Pvt Ltd - Please remember to mark the replies as answers if they help and unmark them if they provide no help.

    Hi Binu 
    I have written one for Exchange 2013 
    http://exchangequery.com/2014/08/12/steps-to-configure-irms-in-exchange-2013/
    Its the same for Exchange 2010 as well 
    Also you can follow the below article for references
    https://technet.microsoft.com/en-us/library/dd351035%28v=exchg.141%29.aspx?f=255&MSPPError=-2147217396
    http://www.msexchange.org/articles-tutorials/exchange-server-2010/compliance-policies-archiving/rights-management-server-exchange-2010-part5.html
    Remember to mark as helpful if you find my contribution useful or as an answer if it does answer your question.That will encourage me - and others - to take time out to help you Check out my latest blog posts on http://exchangequery.com Thanks Sathish
    (MVP)

  • Primary mailbox (on Exchange 2010) and Personal Archive (on Exchange 2013), possible?

    Current environment is Exchange 2010 SP3 RU5 supporting 4,000 Users. Client estate is Outlook 2010 SP1 going on SP2.
    We're pulling our Archiving solution away from 3rd party and back into Exchange. Implementing a new set of Exchange 2010 Servers (old DAG or in a new Archive DAG) would be easy. But is there Exchange 2013 stepping stone potential?
    Can the Archive DAG / Archive mailboxes be on 2013? i.e. for any given User, leave their primary mailbox on Exchange 2010 and create new Archive mailbox on 2013.
    I want to avoid implementing 2010 Archive Servers and then go 2013 Archive 6 months or a year later.
    This article suggests 'no':
    http://technet.microsoft.com/en-gb/library/dd979800(v=exchg.150).aspx
    "Locating a user’s mailbox and archive on different versions of Exchange Server is not supported."
    I've found little info but the odd statement here / there.
    Is this the latest position? Is it that cut & dry? Anyone tried it? Why won't it work (or will it but it's not supported)?
    Thanks!

    <I had a response from MS>
    Below is a summary of the case for your records:
    Symptom:
    =============
    Is it possible to implement a 2013 environment to host the Archive mailboxes? i.e. for any given User, their primary mailbox is on Exchange 2010 and their Archive
    mailbox is on 2013. 
    Resolution:
    =============
    It’s not supported to have a user’s primary mailbox reside on an older Exchange version than the user’s archive. If the user’s primary mailbox is still on Exchange
    2010, you must move it to Exchange 2013 before or at the same time when you move the archive to Exchange 2013.
    http://technet.microsoft.com/en-us/library/jj651146(v=exchg.150).aspx
    as per the repro in our lab, having the archive mailbox in higher version of exchange would fail with the error above
    <the scenario isn't completely relevant, looks like he's trying to put the Primary on 2013 and not the Archive, no matter, we've established there are problems, question is whether they are looking into this area / to patch, they go on...>
    At this point in time we don’t have a conformation from the product team, if the above would change in the future exchange versions.
    <MS did say on the call that they were not looking at fixing it, naturally this isn't a "never", as per previous statement - they can't commit 100% to the future, but they've provided me the answer - they are not currently looking at resolving/providing
    this as a migration scenario, end.>

Maybe you are looking for

  • Creation of  rules index failing with ORA-01652 exception

    I am trying to create a rules index in the following way, BEGIN      SEM_APIS.CREATE_RULES_INDEX(      'APPS_RDF_IDX',      SEM_Models('SEMANTIC_SEARCH_MODEL'),      SEM_Rulebases('OWLPRIME','SEMANTIC_SEARCH_RULEBASE')); END; with semantic_search_rul

  • Enhanced Fields in IDoc Message Type CRMXIF_ORDER_SAVE_M

    Dear Experts, I have enhanced the Business Transaction with EEWB and is used in Complaint Handling scneario. Now, I need to send the IDoc for the complaints. So, I have used the Message Type CRMXIF_ORDER_SAVE_M for this. But this message type does no

  • Handling SSLHandshakeException in Tomcat 5.5.17

    Hi, How do I handle this exception, when the user clicks "Cancel" upon SSL Client authentication when prompted for a certificate. javax.net.ssl.SSLHandshakeException: null cert chain Tomcat throws this exception, but I would like to catch it and redi

  • Installing Arch on a RAID (for dummies)

    Playing with RAID's is fun for all the family, and makes things go faster. this is how I (re)installed Arch Linux, in a simple RAID configuration. Ingredients =========== 1. Two 160GB drives 2. Arch Linux CD (Dont Panic) Planning ======== 1. root par

  • Database Mirroring Scenarios

    Hi Everyone, I am doing some test for database mirroring. I come with come with these two scenarios i unable to test out. 1) The principal database server disks full. In these case is the database mirroring failover will happen? 2) The principal data