Recent Discussions
Exchange SE 15.2.2562.46: MRSProxy returns HTTP 401 after successful NTLM authentication
Hello, Anonymization note: The domain names contoso.com and contoso.local, the server name EXCH-SE-01, and the account name CONTOSO\MigrationAccount used in this post are anonymized placeholders. They do not represent the actual production domain, server, or account names. The Exchange versions, configuration values, HTTP status codes, diagnostic results, and sequence of events are unchanged. We are experiencing an issue with remote mailbox moves from Exchange Server Subscription Edition to Exchange Online. The Exchange Online migration endpoint and the following command both fail: Test-MigrationServerAvailability -ExchangeRemoteMove -RemoteServer "mail.contoso.com" -Credentials $cred The error returned by Exchange Online is: The connection to the server 'mail.contoso.com' could not be completed. The call to: https://mail.contoso.com/EWS/mrsproxy.svc failed with: The HTTP request is unauthorized with client authentication scheme 'Negotiate'. The authentication header received from the server was: 'Negotiate, NTLM'. The remote server returned an error: (401) Unauthorized. Environment Exchange version: Exchange Server Subscription Edition RTM Installed update: August 2026 Security Update KB5121573 Binary version: 15.2.2562.46 Topology: Single Exchange server Mailbox role Classic Full Hybrid Operating system: Windows Server 2022 Exchange Online migration type: Remote Move / onboarding The environment does not have separate frontend and backend Exchange servers. Both the Client Access frontend and mailbox backend services are hosted on the same Exchange server. All checked MRS binaries have the same version: Microsoft.Exchange.MailboxReplicationService.dll Microsoft.Exchange.MailboxReplicationService.Common.dll Microsoft.Exchange.MailboxReplicationService.ProxyClient.dll Microsoft.Exchange.MailboxReplicationService.ProxyService.dll MSExchangeMailboxReplication.exe File version: 15.2.2562.46 MRSProxy configuration Get-WebServicesVirtualDirectory | Format-List Identity, MRSProxyEnabled, BasicAuthentication, WindowsAuthentication, WSSecurityAuthentication, OAuthAuthentication, ExternalUrl Current configuration: MRSProxyEnabled : True BasicAuthentication : False WindowsAuthentication : True WSSecurityAuthentication : True OAuthAuthentication : True ExternalUrl : https://mail.contoso.com/EWS/Exchange.asmx Extended Protection settings have been validated by the latest Exchange Health Checker: Default Web Site/EWS: Extended Protection = Allow SSL flags = Ssl, Ssl128 Authentication = Windows, Negotiate, NTLM Exchange Back End/EWS: Extended Protection = Require SSL flags = Ssl, Ssl128 Authentication = Windows, Negotiate, NTLM Anonymous authentication = enabled Exchange Health Checker reports: Exchange SE RTM Aug26SU Build Number: 15.2.2562.46 MRS Proxy Enabled: True Extended Protection configured correctly for EWS Default Web Site: Started Exchange Back End: Started MSExchangeServicesAppPool: Started Local MRS health All local MRS health checks pass: Get-MailboxServer | Test-MRSHealth | Format-Table Check,Passed,Message -Wrap Results: ServiceCheck : Passed RPCPingCheck : Passed MRSProxyPingCheck : Passed QueueScanCheck : Passed Migration accounts The test was performed with two different on-premises accounts. Both accounts return the same HTTP 401 result. The primary migration account: Enabled : True LockedOut : False PasswordExpired : False The account is also a direct member of: Organization Management One of the accounts used for testing also has domain administrative permissions, so the symptom does not appear to be caused by missing Exchange RBAC permissions. Changing the password and updating the credentials stored in the migration endpoint did not change the result. Failed Request Tracing results Failed Request Tracing was enabled temporarily for Default Web Site. The MRSProxy request is processed in three stages. Stage 1: anonymous request The initial anonymous request to: /EWS/mrsproxy.svc returns HTTP 401, which appears to be the expected authentication challenge. Stage 2: NTLM negotiation The next request shows: WindowsAuthenticationModule AUTH_SSPI_CONTINUE_NEEDED HTTP 401.1 0x8009030e This also appears to be the normal intermediate NTLM challenge. Stage 3: authenticated request The final request shows: Authentication type : Negotiate NTLMUsed : true AUTH_SUCCEEDED : true RemoteUserName : DOMAIN\MigrationAccount AuthUserName : DOMAIN\MigrationAccount The Exchange frontend also calculates the expected backend server. However, after authentication succeeds, the request ends with: ModuleName : ManagedPipelineHandler Notification : EXECUTE_REQUEST_HANDLER HttpStatus : 401 HttpSubStatus : 0 ErrorCode : 0 Therefore, Windows Authentication appears to complete successfully. The final HTTP 401 is returned later, while the Exchange/WCF MRSProxy handler is executing. No corresponding failed domain logon events are recorded in the Windows Security log. No new ASP.NET event stating: MRS proxy service is disabled is generated for the current requests. Additional checks already completed We have already verified the following: MRSProxyEnabled=True Test-MRSHealth passes Two migration accounts tested Migration account is in Organization Management Basic Authentication enabled temporarily for testing Windows Authentication enabled Negotiate and NTLM providers present Frontend Extended Protection set to Allow Backend Extended Protection set to Require Frontend TLS certificate valid Backend port 444 certificate valid MSExchangeServicesAppPool running Mailbox Replication Service running EWS physical paths valid WCF *.svc handler mapping present MRS binaries present and version-consistent Exchange server fully restarted IIS restarted MRSProxy disabled and enabled again Temporarily enabling Basic Authentication did not change the result. Using another migration account did not change the result. The dedicated Exchange hybrid application and Microsoft Graph hybrid flow are also configured and Test-OAuthConnectivity succeeds. We understand that this configuration is not used for MRS remote mailbox moves. August 2026 SU known issue We reviewed the Exchange Team announcement for the August 2026 Security Update. The article mentions that MRS migrations can fail if a backend mailbox server has the August 2026 SU while the frontend Exchange server proxying the connection is on an older build. This does not seem to match our topology because this is a single Exchange server and all MRS components are on version 15.2.2562.46. The error is also HTTP 401 rather than TooManyTransientFailureRetriesPermanentException. Questions Has anyone observed the following behavior after installing Exchange SE August 2026 SU, KB5121573? MRSProxyEnabled=True Test-MRSHealth passes NTLM authentication reaches AUTH_SUCCEEDED ManagedPipelineHandler returns final HTTP 401.0 Test-MigrationServerAvailability fails In particular: Is there a known issue in KB5121573 related to MRSProxy authorization after successful NTLM authentication? Does MRSProxy require any additional authorization configuration introduced by the August 2026 security changes? Is there a supported way to validate the MRSProxyAuthorizationManager decision? Are there additional diagnostic logs that show why the WCF MRSProxy handler returns HTTP 401 after AUTH_SUCCEEDED? Is reapplying KB5121573 the recommended repair action in this situation? Has anyone resolved the issue without recreating the EWS virtual directory or disabling Extended Protection? We have retained the following diagnostic evidence and can provide sanitized excerpts: Exchange Health Checker TXT/XML Test-MigrationServerAvailability output Test-MRSHealth output Frontend EWS Failed Request Tracing EWS HttpProxy logs EWS and backend IIS configuration MRS binary versions and hashes Any guidance or confirmation from the Exchange Team or administrators who encountered the same behavior would be appreciated. Thank you.71Views1like2CommentsMicrosoft Entra Connect 2.x Version Retirement Reminder
Microsoft is retiring older versions of Microsoft Entra Connect Sync 2.x as part of its version lifecycle policy. Version 2.5.79.0 Retirement date: 23 October 2026 This version will retire 12 months after the release of version 2.5.190.0. Important to know Microsoft Entra Connect Sync 2.x versions retire 12 months after a newer version is released. This retirement policy has been in effect since 15 March 2023. For new installations: Always install the latest available version. For existing environments: Plan your upgrade to the latest version before your currently installed version reaches its retirement date.Anyone else seeing mailboxes with Exchange Online 2 showing they now have 150gb?
Noticed this this morning. I understand that Basic was going to go to 100gb as they roll that out, but did they also increase Exchange 2 to 150gb to make it still worth paying for it vs an archive license? Or is this a glitch that is going to give us a problem later when people blow through the limit and MS corrects it? This example mailbox is licensed with Business Basic, then Exchange Online added on. It now shows 150gb. I'm seeing this for every user in every tenant I have looked at so far.500Views1like3CommentsThe Demise of the OWA Light Client
On July 8, Microsoft said that they will retire the OWA Light client for Exchange Server in August 2026. But what happened to the OWA Light client for Exchange Online? It seems like Microsoft announced the retirement of OWA Light for Exchange Online in June 2024, but didn’t really make the fact clear in a blog post about consumer accounts. In any case, you can’t run OWA Light for Exchange Online, even if you wanted to. https://office365itpros.com/2026/07/17/owa-light-retirement/83Views1like1CommentExchange Online PowerShell Updates to 3.10.1 to Fix CBA
Microsoft rushed out version 3.10.1 of the Exchange Online management PowerShell module to fix a problem with certificate-based authentication. It seems like a change in an internal Microsoft identity platform caused the tokens issued after a successful connection to Exchange Online to not authorize the execution of further cmdlets. To their credit, Microsoft fixed the issue, but is this the kind of thing that should be caught in testing? https://office365itpros.com/2026/07/27/exchange-online-management-3-10-1/193Views0likes1CommentPrimary Mailbox Quota Increases to 100 GB for Microsoft 365 Business Plans
Microsoft announced details about how they will deploy the 100 GB mailbox quota to Microsoft 365 Business tenants. A new service plan is being deployed to tenants to liberate the additional 50 GB of quota. Having a larger mailbox quota delivers a fantastic opportunity to fill a mailbox with all sorts of digital debris, something that can cause problems in the era of AI. Perhaps enabling mailbox archiving for Business tenants to allow them to clear out old mailbox items would have been better? https://office365itpros.com/2026/08/21/100-gb-mailbox-quota-m365-business/154Views0likes1CommentHow to submit support tickets?
Hi, folks. How does one submit a support request for the Exchange Online PowerShell v3 module? The following article instructs you what not to do, but provides zero detail on what to do: About the Exchange Online PowerShell V3 module | Microsoft Learn Similarly, the following articles highlight the "correct" process, however, it doesn't work: Get support - Microsoft 365 admin | Microsoft Learn How can I get support for M365 Exchange Online? - Microsoft Q&A Where having used the above option, you get to the end and are shown the following completely unrelated message with the support request having been lost in the process: The bug I'm trying to submit is outlined here: UShort Error with the Exchange Module - Microsoft Community Hub Cheers, LainSolved701Views0likes3CommentsEmail Migration Error
While migrating emails from On-Prem MDaemon server to Microsoft Exchange Online , we are getting the following error - Too Many Transient Failure Retries Permanent Exception. I have also attached the snapshot for reference. We have tried migrating live users and new freshly created users (Test users) but still the same error. Request you to help on same.520Views0likes2CommentsHELP - cannot add email to the exchange with outlook classic 2021 and 2024
We have recently upgraded and have a exchange email accounts. We have tried to add emails to connect through exchange we constantly get this error message The action cannot be completed. The name cannot be matched to a name in the address list. We have searched and undertaken many things to and still says this, would anyone know how to fix this?93Views0likes1CommentRemove-Calendarevents
VasilMichev and TonyRedmond Does it need permission on Termed employees calendar? i am Global Admin and when i run this command with preview it does not preview any results Remove-CalendarEvents -Identity james.bond@domain.com -CancelOrganizedMeetings -QueryStartDate 11-7-2016 -QueryWindowInDays 120 -PreviewOnly -Verbose5.2KViews0likes9CommentsCanon Maxify Printer & Authentication
I recently added Microsoft Authenticator for all our domain email accounts. I have an account that I use for devices and applications to send emails to our domain internally. In each app, I re-tested the account, went into Microsoft Authenticator, approved the request and sent a test email: the apps work! My problem is my Canon Maxify printer. I entered the following information: sender address: user@ domain.com Outgoing mail server SMTP: smtp.office365.com Port Number: 587] Checked on Secure Connection (SSL) Checked on Don't verify certificate For authentication: SMTP authentication But it doesn't work. Do I need to enable a setting in Microsoft Entra and Exchange to get this to work? It is important that the printer send me status messages so I know when there is an issue. I also want to add that the email settings were working until I added the Microsoft Authenticator. Thank you!Solved189Views0likes2CommentsExchange Room Resource Name Change
We have Room resources on Exchange online which were migrated from on-premise exchange server, last year we completely migrated the on-premise exchange to EXO, now when we had to change the names of these room resources due to some relocations of the meeting rooms, we had to rename it from the on-premise ad since it is syncd. I have just renamed the AD object property(display name, SMTP etc), and once it is syncd via AAD, now could see the new name from the EXO but when we use Get-Mailbox -Identity via Exchange online powershell its still showing up the old name, is there any other on-premise ad attribute which needs to be changed?4.9KViews0likes7CommentsUsing a scanner device with HVE
Has anyone had any success in setting up a scanner device with HVE? Everything I've read about the HVE option allows for a scanner to send to HVE, but as I've had no luck in getting my Brother ADS-2800 to communicate with HVE. I've confirmed the settings multiple times, but keep getting the same error when I attempt a test email from the scanner. " Communication over the network using SSL was unsuccessful. The SSL settings may not be configured to match the server settings. Confirm the send e-mail server "Port" and the setting for "SSL/TLS". We'd like to use these scanners for sending into a pre-designated internal mailbox. In theory it should work - in practice however, different story.139Views0likes1CommentGet-EXOMailbox -Filter returns empty when $WarningPreference = 'SilentlyContinue'
Get-EXOMailbox -Filter returns empty when $WarningPreference = 'SilentlyContinue' under UAMI app-only auth Module version: ExchangeOnlineManagement 3.x (PS7, Azure Automation sandbox) Auth method: Connect-ExchangeOnline -ManagedIdentity -ManagedIdentityAccountId <UAMI ClientId> Reproduction steps: $WarningPreference = 'SilentlyContinue' Connect-ExchangeOnline -ManagedIdentity ` -ManagedIdentityAccountId "<UAMI-ClientId>" ` -Organization "yourtenant.onmicrosoft.com" ` -ShowBanner:$false # Returns empty — mailbox provably exists Get-EXOMailbox -Filter "ExternalDirectoryObjectId -eq '<EntraOID>'" # Restore and retry — returns correctly $WarningPreference = 'Continue' Get-EXOMailbox -Filter "ExternalDirectoryObjectId -eq '<EntraOID>'" Expected: Mailbox object returned regardless of $WarningPreference Actual: Returns $null when $WarningPreference = 'SilentlyContinue' Notes: Only affects -Filter parameter under app-only/UAMI auth -Identity and -UserPrincipalName are not affected Delegated auth sessions are not affected $WarningPreference = 'SilentlyContinue' is a common pattern in Azure Automation runbooks, making this a significant undocumented breaking behaviour for automation scenarios116Views0likes1CommentOutlook - Online mode address book search fails with "Operation failed" when Name only is ticked.
I hope you had this issue and managed to solve 😂 pulling my hair already. Symptom: In classic Outlook for Windows, open the Address Book → set Search to Name only → type any single character → "The address book operation failed." Switch to More columns and the exact same search works fine. Ctrl+K resolution in the To: field works. OWA people search works. Mail flow is fine. It's only the Name-only ANR seek in the dialog. Environment: Exchange hybrid, mailbox in Exchange Online, dir-syncedfrom on-prem AD via Entra Connect Classic Outlook for Windows, online mode (Cached Mode is not permitted here — this is the constraint, I can't just flip it) Affects all users, all machines What I've already ruled out: Test Result Other address lists (Contacts, All Users) Same failure Ctrl+K in To: field Works Safe mode (outlook.exe /safe) Same failure — not add-ins Multiple accounts / multiple machines Same failure Brand-new mail profile Same failure — not profile corruption Addressing order (Tools > Options) GAL set first, not "Choose automatically" Off corporate network (5G) Same failure AddressBookPolicy / OfflineAddressBook on mailbox Both blank (inherit defaults) Get-OfflineAddressBook Default OAB, IsDefault: True, web dist enabled Get-GlobalAddressList Default GAL, IsDefaultGlobalAddressList: True, stock default RecipientFilter192Views0likes2CommentsDynamics 365 App for Outlook is not supported Cross Tenant
Hello, I am referring to the disclaimer here which clearly says that Dynamics 365 App for outlook is not supported when the excahange online is on a tenant separate from the Dynmics 365 Sales tenant. This seems to be true even after properly registering the Dynamics 365 as an application in the Azure Tenant of the Exchange Online instance and then configuring the profile etc. all correctly. It is mentioned that the incoming-outgoing emails and appt/contact/task sync will all work through server-side synchronization. But when will this be available for Dynamics 365 App for Outlook in cross-tenant scenario for customers ? As most customers prefer to have their exchange on a dedicated usually the corp hq tenant for better management and then all business apps in different separate tenants based on region/department/child companies ? Please also suggest if there are any workarounds. And kindly give me any pointers to other forums that will be more appropriate for this question, just in case…. Many Thanks https://learn.microsoft.com/en-us/power-platform/admin/connect-exchange-online-server-profile-oauth1.1KViews0likes2CommentsHCW - Hybrid Configuration Wizard for Hybrid Certificate
I've gone through about 5 Microsoft Exchange Support Engineers for last two years with Exchange on-line migration and 80% of time running HCW, it caused email outages where the engineers did not know what to do. They've also gave conflicting information on how to correctly run HCW for adding server and to replace certificate. Some say use powershell and some says do not use powershell. Now, I need to replace the hybrid certificate, do I uncheck everything and check only "Update Secure Mail Certificate for connectors" in a centralized transport setup (email flows through on-prem servers) ? I assume uncheck everything will not roll back configurations. I have Microsoft Exchange engineers says it will and some say it won't and they all say they have 20+ experience.210Views0likes2CommentsMicrosoft Blocks EWS Access for Kiosk Users
A December 2 announcement says that Exchange Online will block access to Exchange Web Services for users with kiosk or frontline worker licenses from March 2026. In fact, the Exchange Online service description has always excluded EWS access for these licenses, but the necessary code to enforce the exclusion was never implemented. It will be in March. Time to check licenses… https://office365itpros.com/2025/12/05/exchange-web-services-kiosk/295Views0likes1Comment
Events
Recent Blogs
- Customers still using Exchange 2016 or 2019 should read this update about oldest version of Exchange Server allowed to send email to Exchange Online over the OnPremises connector.Sep 02, 20262.1KViews0likes11Comments
- We wanted to ask how you use Guid, SamAccountName, and DistinguishedName in Exchange Online.Aug 27, 20261.6KViews1like6Comments