Troubleshooting Outlook Web Access logon failures in Exchange 2000 and in Exchange 2003 (327843)
The information in this article applies to:
- Microsoft Exchange Server 2003 Enterprise Edition
- Microsoft Exchange Server 2003 Standard Edition
- Microsoft Exchange 2000 Server
- Microsoft Windows Small Business Server 2003, Premium Edition
- Microsoft Windows Small Business Server 2003, Standard Edition
This article was previously published under Q327843 SYMPTOMS When you try to log on to your Microsoft Exchange 2000 Server mailbox or your Microsoft Exchange Server 2003 mailbox by using Microsoft Outlook Web Access (OWA), you may experience one or more of the following symptoms: - You receive one of the following error messages:
Error Message 1You are not authorized to view this page. You do not have permission to view this directory or page using the credentials you supplied.
HTTP 401.1 - Unauthorized: Logon Failed Error Message 2Error: Access is denied. Error Message 3Page Cannot be Displayed. - You can log on successfully, but you are prompted for your credentials again. If you do not type your user name in the domain\alias format, or if you click Cancel, you receive the following error message:
Login failed or cancelled. - You can log on to Outlook Web Access by using some browsers, such as Netscape, but you cannot log on by using other browsers.
- After you type the correct credentials, the Outlook Web Access page does not load.
CAUSEThese issues typically occur when you use incorrect authentication methods or when users have not been granted the correct permissions.RESOLUTION To resolve these issues, make sure that you are using the correct authentication methods and that you have the correct permissions to the Exchange folders. To do this, follow these steps. Important Because of a change in Microsoft Internet Information Services (IIS) 6.0, if Exchange 2003 is installed on a computer that is running Microsoft Windows Server 2003, you may have to enter your username in the format of domain\ username, even if you entered a backslash as the default domain. To work around this issue, you may either enter the network basic input/output system (NetBIOS) name of your domain as the default domain or you can apply the hotfix that is discussed in Microsoft Knowledge Base (KB) article 827991.
For additional information, click the following article number to view the article in the Microsoft Knowledge Base:
827991
FIX: "HTTP Error 401.1 - Unauthorized: Access is denied due to invalid credentials" error message if the Basic authentication Default Domain property is set to a backward slash character (\) in IIS
Additionally, you must use a backslash as the default domain when Exchange 2003 is installed on a computer that is running Windows Server 2003 and forms-based authentication is enabled on that computer. When you modify the authentication method of Outlook Web Access, you should do so in Exchange System Manager.
For additional information, click the following article number to view the article in the Microsoft Knowledge Base:
240105
General information on Directory Service/Metabase Synchronization in Exchange 2000 Server
- Modify the authentication methods for the Exchange virtual directory and for the Public virtual directory in Exchange System Manager. To do this, follow these steps:
- Click Start, point to Programs, point to Microsoft Exchange, and then click System Manager.
- Expand Servers, expand Server Name, expand Protocols, expand HTTP, and then expand Exchange Virtual Server.
- Under Exchange Virtual Server, right-click Exchange, and then click Properties.
- Click the Access tab, and then click Authentication.
- Click to select the Basic authentication check box if it is not already selected.
- In the Default domain box, type the network basic input/output system (NetBIOS) name of your domain, or type a backslash if it is not already there.
- Click OK two times to close the property windows.
- Right-click the Public virtual directory, and then click Properties.
- Click the Access tab, and then click Authentication.
- Click to select the Basic authentication check box if it is not already selected.
- In the Default domain box, type the NetBIOS name of your domain, or type a backslash if it is not already there.
- Click OK two times, and then quit Exchange System Manager.
Note The default domain that is specified for basic authentication on the Exchange virtual directory and on the Public virtual directory must match. If the default domains do not match, you will continue to be prompted for credentials after you log on to Outlook Web Access.
For additional information about how to configure authentication methods for Exchange 2000 Outlook Web Access, click the following article number to view the article in the Microsoft Knowledge Base:
290341
Configuring authentication methods in an Exchange 2000 OWA virtual directory
- Modify the authentication method for the Exchweb virtual directory in Microsoft Internet Information Services (IIS). To do this, follow these steps.
- Microsoft Windows 2000 Server (IIS 5)
- Click Start, point to Programs, point to Administrative Tools, and then click Internet Services Manager.
- Expand Default Web Site.
- Right-click Exchweb, and then click Properties.
- Click the Directory Security tab, and then click Edit under Anonymous access and authentication control.
- Make sure that the Basic Authentication check box and the Integrated Windows Authentication check box are not checked, and then click to select the Anonymous access check box if it is not already selected.
- Click OK two times.
- Right-click Default Web Site, click Stop, and then click Start.
- Microsoft Windows Server 2003 (IIS 6)
- Click Start, point to Administrative Tools, and then click Internet Information Services (IIS) Manager.
- Expand Web Sites, and then expand Default Web Site.
- Right-click Exchweb, and then click Properties.
- Click the Directory Security tab, and then click Edit under Authentication and access control.
- Make sure that the Basic Authentication and Integrated Windows Authentication check boxes are not checked, and then click to select the Enable anonymous access check box if it is not already selected.
- Click OK two times.
- Right-click Default Web Site, click Stop, and then click Start.
- Grant the Authenticated Users group a minimum of Read and Execute permissions, Read permissions, and List Folder Contents permissions on the appropriate Exchange and Microsoft Windows directories.
- To assign the correct permissions, follow these steps:
- In Windows Explorer, locate and right-click the Exchsrvr\Exchweb folder, and then click Properties.
- Click the Security tab, and then make sure that the Authenticated Users group has the following permissions:
- Read and Execute
- List Folder Contents
- Read
- Verify that the system account has the Full Control permission on the Exchweb directory.
- Repeat step a through step c for the following directories:
- Winnt\System32
- Winnt\System32\Inetsrv
- Winnt\System32\Wbem
- Exchsrvr\Bin
- Exchsrvr\RES
Note You may have to restart the World Wide Web Publishing service for these settings to take effect.
Modification Type: | Minor | Last Reviewed: | 1/3/2005 |
---|
Keywords: | kberrmsg kbprb KB327843 kbAudITPRO |
---|
|