Lync VDI Plugin sign in credentials

I was unsure of which forum to post this is, and thought since its related to the lynv vdi plug in that the Voice forum was best suited.
I have a question related to the lync vdi plug in and non domain joined thin clients.
I have a customer with a VDI deployment. Everything is working and the vdi pairs correctly and media redirection is working.
They use HP thin clients, HP has a tool that manages the thin clients and basically reimages them upon startup.
The thin clients are not domain joined. this is by design of the customer for security purposes.
The query I have is that everytime a user logs into the virtual machine and Lync starts up. The VDI plug in will prompt the user for sign in credentials. Once entered it pairs no problem.
Is it possible to have the lync VDI plug in sign in automatically on non domain joined thin clients? Is there anything that can be placed in the registry of the thin client to allow this?
Ive read about adding a "trustModelData" entry, but it seems that is only related to other domains not on the servers certifiicate.

Hi,
Base on my understanding, for the non-domain joined computers, it is normal for Lync prompt the user to re-enter his/her credentials for pairing. It is for security and there is no method to prevent it naturally. For domain joined computers, the prompt will
not appear.
More details for Lync VDI Plug-in:
http://blogs.technet.com/b/nexthop/archive/2013/09/23/deployment-details-for-lync-vdi-plugin.aspx
Best Regards,
Eason Huang
Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]
Eason Huang
TechNet Community Support

Similar Messages

  • Lync VDI Plugin on 64bit remote computer with 32Bit Office 2010 installed

    Hi,
    We have a customer who had a number of users connecting via RDP to a Server 2008r2 based farm. A lot of the users have Win 7 x64 installed on their home computers along with Office
    2010 32 Bit. When I try to install the Lync 2013 64 Bit VDI plugin I get an error stating the product can't be installed on the computer as it already has Office 2010 Single Image installed. Is this correct
    as the TechNet install guide states only the Bitness of Office 2013 matters??
    http://blogs.technet.com/b/nexthop/archive/2013/09/23/deployment-details-for-lync-vdi-plugin.aspx
    Thanks
    Lync Tips Blog - [email protected] - If this post has been useful please click the green arrow to the left or click 'Propose as answer'

    Hi,
    As you have install Office 2010 32 Bit on the computer, you must install the same Bit version of Office software. Make sure all versions of Office are either 32-bit or 64-bit. You can’t have a mix of both.
    More details:
    https://support.office.com/en-gb/article/Install-and-use-multiple-versions-of-Office-on-the-same-PC-6ebb44ce-18a3-43f9-a187-b78c513788bf?ui=en-US&rs=en-GB&ad=GB
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

  • Lync VDI Plugin and External LyncServer only

    Hello Specialists,
    i have a small question, how the VDI PlugIn works if you have only a External Lync Server. ??We dont have an internal envirement in our Company, but on the regkey you have to give internal and external.
    Envirement:
    ThinClient: Windows 7 SP1, Lync VDI Plugin 32 bit.
    Citrix: Windows 2008 R2, Lync and Office 32bit.
    Only External Lync Server.
    Christian

    Hi,
    You need to deploy a Lync On-Premises environment to support Lync VDI environment.
    More details:
    https://support.office.com/en-ca/article/FAQs-for-Lync-in-a-Virtual-Desktop-Infrastructure-VDI-environment-763ebe41-24ba-44fa-895b-8e76e00833d4
    If you deploy a Lync On-Premises environment, you can refer to the FAQ for Lync VDI:
    http://blogs.technet.com/b/nexthop/archive/2012/07/31/microsoft-lync-2013-preview-in-a-virtual-desktop-infrastructure.aspx
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

  • Microsoft Lync 2010 continuously asks for credentials after signing in

    Hi,
    we have lync 2010 frontend server at our office, it is working fine for the all the users, but one user who will connect our network through VPN it will continuously prompts for credentials eventhough if we are providing right credentials, because of this
    user will be not able to recieve emails from his outlook. all other VPN users working fine. how to troubleshoot this issue, please any help?
    Regards
    Asha

    Hi,
    The issue may occur if the Outlook integration is not correctly on this client after connecting through VPN. What is the
    difference for the location or sign in type between this user and other working users?
    Lync generally only prompts you for credentials after you are logged in when it must connect Lync to a linked service such as the Microsoft Exchange Free/Busy service or the Calendar service.
    If Lync continues to ask for credentials after three separate dialog prompts, there is likely an issue with Outlook integration or with the Exchange services themselves. I suggest referring to the following information to check the issue.
    http://support.microsoft.com/kb/2298541
    http://support.microsoft.com/kb/2436962
    Regards,
    Kent

  • My ipod is not working at all when i plug it into my laptop i get an itunes sign and below that plugin sign

    My ipod is not working at all when i plug it into my laptop i get an itunes sign and below that plugin sign also it says new software found however it first asks me to install the software disc which i dont have it with me now can you plz check for the same and reply asap...please thanks.

    The link I and Ingo provided included:
    1. Remove iTunes and related components from the Control Panel
    Use the Control Panel to uninstall iTunes and related software components in the following order and then restart your computer:
    iTunes
    QuickTime
    Apple Software Update
    Apple Mobile Device Support
    Bonjour
    Apple Application Support (iTunes 9 or later)
    Important: Uninstalling these components in a different order, or only uninstalling some of these components may have unintended affects.
    That is more than quicktime and iTunes.  Follow all the instruction in the link for removing and reinstalling the Apple software.

  • I am trying to view videos and I keep getting blocked plugin signs. What can I do to fix this problem.

    I am unable to view videos. I keep getting blocked plugin signs. How can I fix this problem?

    What if the latest plugin is the problem? I installed the latest version and now it does not work.

  • Lync2013: Lync Web App sign in as guest

    Lync Web App sign is as guest is returning the following error:
    "There was an error in joining you into the meeting. Please contact your support team."
    & I'm seeing this error being generated on the Lync server:
    Storage Service had an EWS Autodiscovery failure.
    UnsupportedStoreException: code=ErrorIncorrectExchangeServerVersion, reason=GetUserSettings failed, smtpAddress=xyz@ .com, Autodiscover Uri=https://autodiscover. .com/autodiscover/autodiscover.svc, Autodiscover WebProxy=<NULL> ---> 

    Hi MikeMerkato,
    Please check the anonymous access settings and conference policies.
    AllowAnonymousParticipantsInMeetings:
    Indicates whether anonymous users are allowed to participate in the meeting. If set to False then only authenticated users (that is, users logged on to your Active Directory
    Domain Services or the Active Directory of a federated partner) are allowed to attend the meeting. The default value is True.
    This setting applies to the user who organizes the conference: if set to False, no conference created by a user affected by this policy will allow anonymous participants. However, the
    user can take part in other conferences where anonymous participants are allowed.
    https://technet.microsoft.com/en-us/library/gg425788.aspx
    Best regards,
    Eric

  • How do I prevent users from caching their sign in credentials on OWA page

    I am using Forms based authentication and want to prevent users from caching their credentials on the OWA page.
    Is there an easy way?

    Hi,
    Forms-based authentication enables a sign-in page for Outlook Web App that uses a cookie to store a user's encrypted sign-in credentials in the Internet browser. So this authentication method will force to cache their credentials in the Internet
    browser for some time. The workaround is what Willard Martin suggested.
    Refer from
    http://technet.microsoft.com/en-us/library/bb430796(v=exchg.141).aspx
    Best Regards.

  • Citrix XenApp 7.6 & VDI Plugin works for some users but not others

    I have a customer with XenApp 7.6 and Lync 2013 SE. They have two users homed to the same pool, both with the same VDI client policy however on one account the VDI pairing works fine over Citrix XenApp, but the other the pairing fails. On both accounts I
    get prompted for the credentials, however the second account will not authenticate. I have tried domain\username, domain.local\username and [email protected] but all fail then I get the red cross through the VDI icon.
    This is all from the same Windows 7 machine, all user accounts are within the same AD domain.
    If anyone has seen similar before any assistance would be greatly appreciated as I am banging my head against the wall!
    Lync Tips Blog - [email protected] - If this post has been useful please click the green arrow to the left or click 'Propose as answer'

    Here is some further info:
    360admin - can sign in to Lync and pair correctly
    msltest - can sign into Lync but the credentials are not accepted for pairing
    Identity                : CN=360 Admin,CN=Users,DC=localdomain,DC=co,DC=uk
    VoicePolicy             :
    VoiceRoutingPolicy      :
    ConferencingPolicy      :
    PresencePolicy          :
    DialPlan                :
    LocationPolicy          :
    ClientPolicy            : HEADSET_USER
    ClientVersionPolicy     :
    ArchivingPolicy         :
    ExchangeArchivingPolicy : Uninitialized
    PinPolicy               :
    ExternalAccessPolicy    :
    MobilityPolicy          :
    PersistentChatPolicy    :
    UserServicesPolicy      :
    HostedVoiceMail         :
    HostedVoicemailPolicy   :
    HostingProvider         : SRV:
    RegistrarPool           : LyncFEG.localdomain.co.uk
    Enabled                 : True
    SipAddress              : sip:[email protected]
    LineURI                 : tel:+44**
    EnterpriseVoiceEnabled  : True
    ExUmEnabled             : False
    HomeServer              : CN=Lc Services,CN=Microsoft,CN=1:3,CN=Pools,CN=RTC Se
                              rvice,CN=Services,CN=Configuration,DC=localdomain,DC=co,D
                              C=uk
    DisplayName             : 360 Admin
    SamAccountName          : 360Admin
    PS C:\Users\360admin> Get-CsUser -Identity "msl test"
    Identity                : CN=MSL Test,DC=localdomain,DC=co,DC=uk
    VoicePolicy             :
    VoiceRoutingPolicy      :
    ConferencingPolicy      :
    PresencePolicy          :
    DialPlan                :
    LocationPolicy          :
    ClientPolicy            : HEADSET_USER
    ClientVersionPolicy     :
    ArchivingPolicy         :
    ExchangeArchivingPolicy : Uninitialized
    PinPolicy               :
    ExternalAccessPolicy    :
    MobilityPolicy          :
    PersistentChatPolicy    :
    UserServicesPolicy      :
    HostedVoiceMail         :
    HostedVoicemailPolicy   :
    HostingProvider         : SRV:
    RegistrarPool           : LyncFEG.localdomain.co.uk
    Enabled                 : True
    SipAddress              : sip:[email protected]
    LineURI                 : tel:+44******
    EnterpriseVoiceEnabled  : True
    ExUmEnabled             : False
    HomeServer              : CN=Lc Services,CN=Microsoft,CN=1:3,CN=Pools,CN=RTC Se
                              rvice,CN=Services,CN=Configuration,DC=localdomain,DC=co,D
                              C=uk
    DisplayName             : MSL Test
    SamAccountName          : MSLTest
    PS C:\Users\360admin> Get-CsClientPolicy
    Identity                                    : Tag:HEADSET_USER
    PolicyEntry                                 : {}
    Description                                 :
    AddressBookAvailability                     : WebSearchOnly
    AttendantSafeTransfer                       :
    AutoDiscoveryRetryInterval                  :
    BlockConversationFromFederatedContacts      :
    CalendarStatePublicationInterval            :
    ConferenceIMIdleTimeout                     :
    CustomizedHelpUrl                           :
    CustomLinkInErrorMessages                   :
    CustomStateUrl                              :
    DGRefreshInterval                           :
    DisableCalendarPresence                     :
    DisableContactCardOrganizationTab           :
    DisableEmailComparisonCheck                 :
    DisableEmoticons                            :
    DisableFeedsTab                             :
    DisableFederatedPromptDisplayName           :
    DisableFreeBusyInfo                         :
    DisableHandsetOnLockedMachine               :
    DisableMeetingSubjectAndLocation            :
    DisableHtmlIm                               :
    DisableInkIM                                :
    DisableOneNote12Integration                 :
    DisableOnlineContextualSearch               :
    DisablePhonePresence                        :
    DisablePICPromptDisplayName                 :
    DisablePoorDeviceWarnings                   :
    DisablePoorNetworkWarnings                  :
    DisablePresenceNote                         :
    DisableRTFIM                                :
    DisableSavingIM                             :
    DisplayPhoto                                : PhotosFromADOnly
    EnableAppearOffline                         :
    EnableCallLogAutoArchiving                  : True
    EnableClientMusicOnHold                     : False
    EnableConversationWindowTabs                :
    EnableEnterpriseCustomizedHelp              :
    EnableEventLogging                          :
    EnableExchangeContactSync                   : True
    EnableExchangeDelegateSync                  :
    EnableFullScreenVideo                       :
    EnableHighPerformanceConferencingAppSharing : False
    EnableHotdesking                            :
    EnableIMAutoArchiving                       : True
    EnableMediaRedirection                      : True
    EnableNotificationForNewSubscribers         :
    EnableSkypeUI                               :
    EnableSQMData                               : False
    EnableTracing                               :
    EnableURL                                   :
    EnableUnencryptedFileTransfer               :
    EnableVOIPCallDefault                       : False
    ExcludedContactFolders                      :
    HotdeskingTimeout                           : 00:05:00
    IMWarning                                   :
    MAPIPollInterval                            :
    MaximumDGsAllowedInContactList              : 10
    MaximumNumberOfContacts                     :
    MaxPhotoSizeKB                              : 30
    MusicOnHoldAudioFile                        :
    P2PAppSharingEncryption                     : Supported
    EnableHighPerformanceP2PAppSharing          : False
    PlayAbbreviatedDialTone                     :
    SearchPrefixFlags                           :
    ShowRecentContacts                          : True
    ShowManagePrivacyRelationships              : False
    ShowSharepointPhotoEditLink                 : False
    SPSearchInternalURL                         :
    SPSearchExternalURL                         :
    SPSearchCenterInternalURL                   :
    SPSearchCenterExternalURL                   :
    TabURL                                      :
    TracingLevel                                : Light
    WebServicePollInterval                      : 00:01:00
    HelpEnvironment                             :
    MSL Test Login
    TL_ERROR(TF_SECURITY) [3]21A4.17E8::03/25/2015-22:39:21.107.00005d39 (SIPStack,SIPAdminLog::WriteSecurityEvent:SIPAdminLog.cpp(319))[1363057693] $$begin_record
    Text: Failed to validate user credentials
    Result-Code: 0x8009030c SEC_E_LOGON_DENIED
    Source: LyncEdgeG.localdomain.co.uk:49201
    SIP-Start-Line: REGISTER sip:domain.com SIP/2.0
    SIP-Call-ID: 2cab650cdf3e4d62aea1cb0c2166c07e
    SIP-CSeq: 3 REGISTER
    Lync Tips Blog - [email protected] - If this post has been useful please click the green arrow to the left or click 'Propose as answer'

  • Possible to Have Lync 2013 MSP Installer With Credentials?

    So I am working on a silent lync installer to push out to all my clients, using a custom .MSP file. I am wondering is it possible to include their logged in credentials to the installer? So when they first open Lync after the install, it just logs right
    in, without needing to change the Sign-in Address.
    Currently it defaults to "[email protected]"

    Hi,
    Base on my Knowledge, it is impossible to achieve it with the .MSP file.
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

  • Lync 2013 + clear "Sign-In Address" and disable "Save Password" on shared account

    Hello,
    We are trying to setup Lync on a few kiosk machines that will have a shared non-admin account.  We'd like to modify Lync to not save the "Sign-In Address" and instead of showing the last persons login credentials, show "[email protected]".
    I'd also like to disable the "Save Password" check box.
    The kiosks are not on the domain, although the vast majority of our machines are on the domain and we have SSO setup and don't want to mess with how that part of the signin process is working.
    Is there a way to modify the login behavior of Lync via GPO or Task Scheduler/Scripts?
    Phillip Toynton

    Open Control Panel, click Credential Manager.
    Remove the credential for Lync account. Then you can enter the password again.
    You can uncheck save my password, the related registry key is HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Lync\SavePassword.
    But this registry can be modified by Lync users, you can’t disable it.
    Lisa Zheng
    TechNet Community Support

  • Lync 2013 mobile sign in error

    I try sign in to Lync in my Windows Phone, and get error - Check my password. My password correct. For diagnose I enable "Failed Request Tracing Rules" on IIS on Lync 2013 Server and view only one warning from DirectoryListingModule - HttpStatus
    403 Forbidden. I try reinstall web components on Server but no relult. How I can fix this?
    If I create file "C:\Program Files\Microsoft Lync Server 2013\Web Components\External Website\default.aspx", I view blank page for
    https://lyncdiscover.mydomain.com
    If I enable Directory Browsing for Lync Server External Web Site, I view folder content for
    https://lyncdiscover.mydomain.com and in "Failed Request Tracing Logs" I see OCSAuthModule - HttpStatus 401 Unauthorized

    Hi,
    The error message indicate the client is having an issue authenticating with Lync Server 2013. Please double check that Authentication Delegation is verified on the reverse proxy publishing rule configuration.
    Client may authenticate directly. If the reverse proxy publishing rules are set to No delegate and client cannot authenticate directly, it fails to sign-in when it reaches the step to provide credentials to request a token after MEX retrieval.
    More details you can refer to the link below, it is for Lync server 2010 but similar for Lync server 2013:
    http://blogs.technet.com/b/nexthop/archive/2012/02/21/troubleshooting-external-lync-mobility-connectivity-issues-step-by-step.aspx
    Best Regards,
    Eason Huang
    Eason Huang
    TechNet Community Support

  • Lync phone device sign in failed

    Hi. I have an environment of Lync 2010.
    Front End Pool - 1 server
    Director pool - 2 servers
    AV pool - 2 servers
    My DNS system is split brain. Local domain company.net, external domain company.com
    DNS pinpoint zones:
    lyncpool01.company.net pointed to Lync FE server IP address
    _sipinternaltls._tcp.company.com SRV 0 0 5061 pointed to sip.company.com
    sip.company.com pointed to Lync FE server IP address.
    dialin.company.com pointed to Lync FE server IP address
    meet.company.com pointed to Lync FE server IP address
    ucupdates-r2.company.com pointed to Lync FE server IP address
    _ntp._udp.company.com SRV 0 0 123 pointed to my DC (WIN2K8R2)
    =================================================
    DHCP options
    I tried to point option 120 and 43 to FE and Director pool, but no result.
    All 6 options of DHCP successfully deployed:
    ==============================================================================
    The result of Test-CsPhoneBootStrap
    VERBOSE: Target server fqdn AND web service URL provided by user.
    'STActivity' activity started.
    Trying to download a certificate chain from web service.
    Web Service url :
    http://lyncpool01.company.net/CertProv/CertProvisioningService.svc
    Certificate chain downloaded successfully.
    'STActivity' activity completed in '0,0185095' secs.
    'STActivity' activity started.
    Trying to get web ticket.
    Web Service url :
    https://lyncpool01.company.net:443/WebTicket/WebTicketService.svc
    Using PIN auth with Phone\Ext : 1010 Pin : 180291
    GetWebTicketActivity completed.
    'STActivity' activity completed in '0,1102579' secs.
    'STActivity' activity started.
    Starting ResolveUser activity using Web Ticket.
    Web Service url :
    https://lyncpool01.company.net:443/CertProv/CertProvisioningService.svc
    Found user : sip:[email protected]
    Setting sip uri 'sip:[email protected]' back to parent workflow.
    ResolveUser activity completed.
    'STActivity' activity completed in '0,0988848' secs.
    'STActivity' activity started.
    Trying to get web ticket.
    Web Service url :
    https://lyncpool01.copmany.net:443/WebTicket/WebTicketService.svc
    Using PIN auth with Phone\Ext : 1010 Pin : 180291
    GetWebTicketActivity completed.
    'STActivity' activity completed in '0,1038949' secs.
    'STActivity' activity started.
    Trying to download a CS certificate for User :
    [email protected] endpoint :
    STEpid
    Web Service url :
    https://lyncpool01.company.net:443/CertProv/CertProvisioningService.svc
    GetCSCertificate activity completed.
    'STActivity' activity completed in '0,4309389' secs.
    'Register' activity started.
    Sending Registration request:
     Target Fqdn      = lyncpool01.company.net
     User Sip Address = sip:[email protected]
     Registrar Port = No Port is provided..
    Auth Type 'Certificate' is selected.
    Registration Request hit against LC2K10EES.company.net
    'Register' activity completed in '0,0913775' secs.
    Starting cleanup...
    cleanup successful.
    'UnRegisterActivity' activity started.
    'UnRegisterActivity' activity completed in '0,0049845' secs.
    Workflow
    'Microsoft.Rtc.SyntheticTransactions.Workflows.STPhoneBootstrapWorkflow',
    succeded.
    VERBOSE: Workflow Instance Id d80e2d02-5e25-47dd-9927-ec8809c19089, completed.
    VERBOSE: Workflow Execution Time (sec): 0.9030903
    ===========================================================================
    The result of Test-CsClientAuth
    VERBOSE: Target web service url not provided. Will have to extract it from auth
     challenge.
    'STActivity' activity started.
    Starting STS Uri Discovery...
    Found sts-uri :
    https://lyncpool01.company.net:443/CertProv/CertProvisioningService.svc.
    STS Uri Discovery activity completed successfully.
    'STActivity' activity completed in '0,0141103' secs.
    'STActivity' activity started.
    Trying to get web ticket.
    Web Service url :
    https://lyncpool01.company.net:443/WebTicket/WebTicketService.svc
    Using NTLM\Kerb auth.
    GetWebTicketActivity completed.
    'STActivity' activity completed in '0,0556596' secs.
    'STActivity' activity started.
    Trying to download a CS certificate for User :
    [email protected] endpoint :
    STEpid
    Web Service url :
    https://lyncpool01.company.net:443/CertProv/CertProvisioningService.svc
    GetCSCertificate activity completed.
    'STActivity' activity completed in '0,5940291' secs.
    'Register' activity started.
    Sending Registration request:
     Target Fqdn      = lyncpool01.company.net
     User Sip Address = sip:[email protected]
     Registrar Port = No Port is provided..
    Auth Type 'Certificate' is selected.
    Registration Request hit against LC2K10EES.company.net
    'Register' activity completed in '0,0951852' secs.
    'UnRegisterActivity' activity started.
    'UnRegisterActivity' activity completed in '0,0046577' secs.
    Starting cleanup...
    cleanup successful.
    Workflow 'Microsoft.Rtc.SyntheticTransactions.Workflows.STClientAuthWorkflow',
    succeded.
    VERBOSE: Workflow Instance Id 5419b6d7-ff06-4244-9dba-708d61978e88, completed.
    VERBOSE: Workflow Execution Time (sec): 0.8020802
    ===========================================================
    Configuration information of Lync 2010 Client
    ==============================================================================
    The result of Get-CsWebServiceConfiguration
    PS C:\Users\raliyev> Get-CsWebServiceConfiguration
    Identity                             : Global
    TrustedCACerts                       : {}
    MaxGroupSizeToExpand                 : 100
    EnableGroupExpansion                 : True
    UseWindowsAuth                       : Negotiate
    UseCertificateAuth                   : True
    UsePinAuth                           : True
    AllowAnonymousAccessToLWAConference  : True
    EnableCertChainDownload              : True
    InferCertChainFromSSL                : True
    CASigningKeyLength                   : 2048
    MaxCSRKeySize                        : 16384
    MinCSRKeySize                        : 1024
    MaxValidityPeriodHours               : 8760
    MinValidityPeriodHours               : 8
    DefaultValidityPeriodHours           : 4320
    MACResolverUrl                       :
    SecondaryLocationSourceUrl           :
    ShowJoinUsingLegacyClientLink        : True
    ShowDownloadCommunicatorAttendeeLink : True
    =====================================================
    The result of Get-CsProxyConfiguration
    Identity                           : Global
    Realm                              : Microsoft.Rtc.Management.WritableConfig.Se
                                         ttings.SipProxy.UseDefault
    MaxClientMessageBodySizeKb         : 128
    MaxServerMessageBodySizeKb         : 5000
    TreatAllClientsAsRemote            : False
    OutgoingTlsCount                   : 4
    DnsCacheRecordCount                : 30000
    EnableWhiteSpaceKeepAlive          : True
    UseKerberosForClientToProxyAuth    : False
    UseNtlmForClientToProxyAuth        : True
    DisableNtlmFor2010AndLaterClients  : False
    UseCertificateForClientToProxyAuth : True
    AcceptClientCompression            : True
    MaxClientCompressionCount          : 15000
    AcceptServerCompression            : True
    MaxServerCompressionCount          : 1024
    RequestServerCompression           : True
    ===========================================================
    Lync logging tool is not showing any usefull information.
    I cheked for logs: CertProvisioning, S4, Sipstack and WebInfrastructure.
    ====================================================
    Finally can't catch the problem.
    RFT

    OK, that is very telling as USB tethering has very few requirements and in most environments works rought out of the box.
    Here the main things to check:
    Is the Lync User's Telephony setting set to Enterprise Voice?  This is a requirement to use Lync Phone Edition (the
    Line URI does not need to be populated).
    Time Server issues can also prevent sign-in.  If a Time Server is not provided via DHCP or DNS SRV then the phone will fallback to connecting to
    time.windows.com, so if the phone does not have Internet access or NTP traffic is blocked at a firewall, then this could be your problem as well.
    Obvious, but worth pointing out: make sure the phone is connected to Ethernet and receiving a basic DHCP lease (IP, subnet, gateway, DNS, etc).  USB tethering does not work unless the device is also connected to Ethernet.
    Follow the steps in this article to at least get USB tethering working
    http://blog.schertz.name/2010/12/externally-provisioning-lync-phone-edition-3
    Then you can move on to PIN authentication:
    http://blog.schertz.name/2010/12/configuring-lync-server-for-phone-edition-devices
    Jeff Schertz | Microsoft Solutions Architect - Polycom | Lync MVP

  • Lync Mobile client signs out - Error- IIS reset on Front End - WAS Errors

    I have a very limited understanding of Lync dependency's & how to trace the issue I'm now seeing. Would appreciate any direction or information to assist.
    We have Primary & Secondary Pools - both pools seem to be effected at different times. The Mobile Clients will error & not sign in until iisreset
    is done on the effected Front End.
    This issue has started a few weeks ago. Before that this has happened maybe twice in a year.
    A few weeks ago we did move the FileStore location of the Primary Front End only (off a Siffs Application store to the local drive of the Primary Front End)– AV scan
    exclusion was set for FileStore location.
    Also some Windows 2008R2 patches were applied.
    The Deployment Wizard has been rerun incase something was broken by MS updates.
    The Window Event log is clean apart from:
    WAS events: (1 to 4 are grouped)
    5013 - A process serving application pool 'LyncUcwa' suffered a fatal communication error with the Windows Process Activation Service. The process id was '24076'. The data field
    contains the error number.
    5011- The Windows Process Activation Service failed to generate an application pool config file for application pool 'LyncExtFeature'. The error type is '7'.
    5189 - A process serving application pool 'LyncIntFeature' suffered a fatal communication error with the Windows Process Activation Service. The process id was '17216'. The data
    field contains the error number.
    5011 - A process serving application pool 'LyncUcwa' exceeded time limits during shut down. The process id was '12520'.
    The Windows Process Activation Service failed to generate an application pool config file for application pool 'LyncIntReach'. The error type is '7'. To resolve this issue, please
    ensure that the applicationhost.config file is correct and recommit the last configuration changes made. The data field contains the error number.
      Schannel: Same Error event happens twice within a few seconds
    ID 36888 -
    The following fatal alert was generated: 10. The internal error state is 1203.
    ID 36888 -
    The following fatal alert was generated: 10. The internal error state is 1203.
    From What I’ve read SChannel doesn’t seem to be an issue.
    Another set of WAS events:
    5011 - A process serving application pool 'LyncUcwa' suffered a fatal communication error with the Windows Process Activation Service. The process id was '19132'.
    5011 - A process serving application pool 'LyncIntFeature' suffered a fatal communication error with the Windows Process Activation Service. The process id was
    '23876'.
    5011 - A process serving application pool 'LyncIntReach' suffered a fatal communication error with the Windows Process Activation Service. The process id was
    '9876'.
    5011 - A process serving application pool 'LyncExtFeature' suffered a fatal communication error with the Windows Process Activation Service. The process id was
    '21804'.
    5138 -
    A worker process '6620' serving application pool 'LyncUcwa' failed to stop a listener channel for protocol 'http' in the allotted time.
    5013 - A process serving application pool 'LyncUcwa' exceeded time limits during shut down.
    Our Exchange UM started to generate errors recently but not sure if that’s a result of the iisreset for WWW Pub – but these events don’t match any timing of Front End events:
    Windows Process Activation Service
    11/13/2014 04:06:37 PM
    LogName=System
    SourceName=Microsoft-Windows-Service Control Manager
    EventCode=7031
    EventType=2
    Type=Error
    ComputerName=Pxxx.xxx.com.au
    TaskCategory=The operation completed successfully.
    OpCode=The operation completed successfully.
    RecordNumber=62445
    Keywords=Classic
    Message=The Windows Process Activation Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Run the configured recovery program.
    World Wide Web Publishing Service
    11/13/2014 04:06:37 PM
    LogName=System
    SourceName=Microsoft-Windows-Service Control Manager
    EventCode=7034
    EventType=2
    Type=Error
    ComputerName= Pxxx.xxx.com.au
    TaskCategory=The operation completed successfully.
    OpCode=The operation completed successfully.
    RecordNumber=62444
    Keywords=Classic
    Message=The World Wide Web Publishing Service service terminated unexpectedly.  It has done this 2 time(s).
    I’m not sure where to go with this now. Any direction would be appreciated.
    Thank you
     

    Hi Davej006,
    Web sites and Web applications depend on the availability of Internet Information Services (IIS) application pools. IIS application pools in turn depend on the Windows Process Activation Service (WAS). If WAS is not running or errors occur
    during the startup or shutdown of an application pool, Web sites and Web applications may not be available.
    And based on my understanding, if some program works sometime and does not in other times, RAM is the problem.
    You could refer to the following article to troubleshoot your problem.
    http://technet.microsoft.com/en-us/library/cc735271(v=ws.10).aspx
    Hope it can be helpful.
    Best regards,
    Eric

  • Lync HP 4120 Sign in problems with Lync Server 2013

    Hi, this is my second request for help, this with more information...
    I`ll ready install the follow infrastructure:  (I change the name of my organization for contoso)
    Lync Server 2013 Installation with Enterprise mode with 1 front end :  Pool: lync.contoso.com  Front End: lyncfe01.contoso.com     Back End: lyncsql01.contoso.com
    I`ll ready install a PKI infrastructure with two tiers, the root offline and the subordnate ac.contoso.com
    This with the defailt algorithm configuration RSA SHA1
    My phones are HP 4120 
    In the Front End Server i configured the SCHANNEL registers:
    EnableSessionTicket in 2
    Send..etc in 0
    Ok, the installation is ok, services are OK, Client login trough PC its OK, PSTN Configuration... (I can make a phonecall with the lync client of Office 365)
    Commnd Checks:  
    When i run the command Test-CsPhoneBootstrap -PhoneOrExt 12345 -PIN 123456 -TargetFqdn lync.contoso.com
    The result is:
    Target Fqdn   : lync.contoso.com
    Target Uri    : https://lync.contoso.com:443/CertProv/CertProvisioningService.svc
    Result        : Success
    Latency       : 00:00:09.0559615
    Error Message :
    Diagnosis     :
    When i run the command Test-CsPhoneBootstrap -PhoneOrExt 12345 -PIN 123456 for
    check the DHCP the result is:
    Target Fqdn   : lync.contoso.com
    Target Uri    : https://lync.contoso.com:443/CertProv/CertProvisioningService.svc
    Result        : Success
    Latency       : 00:00:09.0559615
    Error Message :
    Diagnosis     :
    When i run the follow command 
    PS C:\Users\Administrator> $cred = Get-Credential
    cmdlet Get-Credential at command pipeline position 1
    Supply values for the following parameters:
    Credential
    PS C:\Users\Administrator> Test-CsClientAuth -TargetFqdn lync.contoso.com -UserSipAddress "sip:[email protected]" -UserCredential $cred
    I got this:
    Target Fqdn   : lync.contoso.com
    Target Uri    : https://lync.contoso.com:443/CertProv/CertProvisioningService.svc
    Result        : Success
    Latency       : 00:00:00.3431783
    Error Message :
    Diagnosis     :
    But.. when i use the same command but i remove the -targetFqdn for check the Dhcp i got this:
    VERBOSE: Workflow Instance Id 'bca95636-af7b-4b0a-b43d-dba259294b2d', started.
    VERBOSE: Command line executed is 'Test-CsClientAuth -UserSipAddress "sip:[email protected]" -UserCredential $cred
     -Verbose'.
    Target Fqdn   :
    Target Uri    :
    Result        : Failure
    Latency       : 00:00:00
    Error Message : 10060, A connection attempt failed because the connected party did not properly respond after a period
                    of time, or established connection failed because connected host has failed to respond 194.90.8.20:5061
                    Inner Exception:A connection attempt failed because the connected party did not properly respond after
                    a period of time, or established connection failed because connected host has failed to respond
                    194.90.8.20:5061
    Diagnosis     :
    VERBOSE: Workflow 'Microsoft.Rtc.SyntheticTransactions.Workflows.STClientAuthWorkflow' started.
    Workflow 'Microsoft.Rtc.SyntheticTransactions.Workflows.STClientAuthWorkflow' completed in '5.62E-05' seconds.
    Target web service Url not provided. Will have to extract it from authentication challenge.
    An exception 'Unable to establish a connection.' occurred during Workflow
    Microsoft.Rtc.SyntheticTransactions.Workflows.STClientAuthWorkflow execution.
    Exception Call Stack:    at Microsoft.Rtc.Signaling.SipAsyncResult`1.ThrowIfFailed()
       at Microsoft.Rtc.Signaling.Helper.EndAsyncOperation[T](Object owner, IAsyncResult result)
       at Microsoft.Rtc.SyntheticTransactions.Activities.GetSTSUriActivity.InternalExecute(ActivityExecutionContext
    executionContext)
       at Microsoft.Rtc.SyntheticTransactions.Activities.SyntheticTransactionsActivity.Execute(ActivityExecutionContext
    executionContext)
       at System.Workflow.ComponentModel.ActivityExecutor`1.Execute(T activity, ActivityExecutionContext executionContext)
       at System.Workflow.ComponentModel.ActivityExecutorOperation.Run(IWorkflowCoreRuntime workflowCoreRuntime)
       at System.Workflow.Runtime.Scheduler.Run()
       at System.Net.Sockets.Socket.EndConnect(IAsyncResult asyncResult)
       at Microsoft.Rtc.Internal.Sip.TcpTransport.OnConnected(Object arg)
    'GetSTSUri' activity started.
    Starting STS Uri Discovery...
    ERROR getting STS Uri.
    'UnRegister' activity started.
    'UnRegister' activity completed in '3.12E-05' seconds.
    VERBOSE: Workflow Instance ID 'bca95636-af7b-4b0a-b43d-dba259294b2d' completed.
    VERBOSE: Workflow run-time (sec): 126.0548512.
    The Real Problem is that my Lync HP 4120 Phone can't make a sign in, not from USB cable loging, nor with PIN authentification
    When I try to make a login with the USB cable, I set the user and password and the phone says "Connecting to Lync".. "Downloading a certificate" ... "Installing certificate"... "Downloading Certificate"...
    "Installing Certificate".. forever 
    When I try to make a login with PIN Authentification, the phone first displays the following:
    Account used is not authorized, Please Contact your support team and then shows this:
    An Account matching this phone number cannot be found. Please contact your support team.
    The Pin authentification is enable
    In the Lync Server Enable Kerberos Authentification, Enable Integrated Windows Authentification and Enable Certificate Authentification are enable
    This is the configuration from DHCP 
    Starting Discovery ... 
    Sending Packet (Size: 284, Network Adapter: xx.xx.xx.xx, Attempt Type: Broadcast only)
    --Begin Packet--
    DHCP: INFORM                (xid=130EA7FA)
    DHCP: Op Code           (op)      = 1
    DHCP: Hardware Type     (htype)   = 6
    DHCP: Hops              (hops)    = 0
    DHCP: Transaction ID    (xid)     = 319727610
    DHCP: Seconds           (secs)    = 0
    DHCP: Flags             (flags)   = 0000
    DHCP: Client IP Address (ciaddr)  = Xx.xx.xx.xx
    DHCP: Your IP Address   (yiaddr)  = 0.0.0.0
    DHCP: Server IP Address (siaddr)  = 0.0.0.0
    DHCP: Relay IP Address  (giaddr)  = 0.0.0.0
    DHCP: Client HW Address (chaddr)  = FC15B4###--End Packet--
    Received Packet
    Sender:xx.xx.xx.xx:67, Size:363
    --Begin Packet--
    DHCP: ACK                (xid=130EA7FA)
    DHCP: Op Code           (op)      = 1
    DHCP: Hardware Type     (htype)   = 6
    DHCP: Hops              (hops)    = 0
    DHCP: Transaction ID    (xid)     = 319727610
    DHCP: Seconds           (secs)    = 0
    DHCP: Flags             (flags)   = 0000
    DHCP: Client IP Address (ciaddr)  = xx.xx.xx.xx
    DHCP: Your IP Address   (yiaddr)  = 0.0.0.0
    DHCP: Server IP Address (siaddr)  = 0.0.0.0
    DHCP: Relay IP Address  (giaddr)  = 0.0.0.0
    DHCP: Client HW Address (chaddr)  = FC15B4100289
    DHCP: Server Host Name  (sname)   = 
    DHCP: Boot File Name    (file)    = 
    DHCP: Magic Cookie                = 99.130.83.99
    DHCP: Option Field
        DHCP: DHCP MESSAGE TYPE(  53) = (Length: 1) DHCP ACK
        DHCP: Server Identifier(  54) = (Length: 4) XX.XX.XX.XX
        DHCP: Client Identifier(  61) = (Length: 0)  ()
        DHCP: SIP Server( 120)        = (Length: 17) enc:0 lync.contoso.com (00046C796E6306756E69736F6E026D7800)
        DHCP: Host Name(  12)         = (Length: 0) 
        DHCP: Vendor Identifier(  60) = (Length: 0) 
        DHCP: Param Req List(  55)    = (Length: 0) 0 0
        DHCP: Vendor Info(  43)       = (Length: 86) MS-UC-Clienthttpslync.contoso.com443%/CertProv/CertProvisioningService.svcÜNAP (010C4D532D55432D436C69656E7402056874747073030E6C796E632E756E69736F6E2E6D78040334343305252F4365727450726F762F4365727450726F766973696F6E696E67536572766963652E737663DC034E4150)
        DHCP: End of this option field
    --End Packet--
    Result: Success
    DHCP Server : xx.xx.x.xx.
    SIP Server FQDN : lync.contoso.com
    Certificate Provisioning Service URL : https://lync.contoso.com:443/CertProv/CertProvisioningService.svc
    thanks for all, hope somebody can help me with this problem.. i am going crazy...

    Hi, i connected the Lync Phone to another switch and i update the firmware to the newest firmware and i got the same problem..  
    The lync phone download the certificate but cant install it and the still the same error with the SIP login
    An Account matching this phone number cannot be found. Please contact your support team.

Maybe you are looking for