Forum Discussion
Exchange SE 15.2.2562.46: MRSProxy returns HTTP 401 after successful NTLM authentication
Your trace shows NTLM completing, IIS recording AUTH_SUCCEEDED for the intended account, and the final 401 appearing only when the managed MRSProxy handler executes. That makes another password, provider-order change, or disabling Extended Protection unlikely to fix the failure. Microsoft’s KB5121573 known-issues list does not currently identify this MRSProxy symptom, so it is not a confirmed update defect. Keep Extended Protection and documented EWS authentication settings intact. Confirm front-end and back-end Exchange components report the same installed build, rerun Exchange Health Checker, and preserve its report. Collect matching UTC slices from IIS/FREB, HttpProxy EWS logs, MRS logs, and the Application log for one Test-MigrationServerAvailability request. Include the request ID, authenticated user, endpoint, and hybrid configuration. Do not recreate EWS or reapply the update without evidence of a damaged installation. Open an Exchange support case with the trace bundle; this post-authentication authorization failure needs product-level analysis.