Forum Discussion

CosmoDenger's avatar
CosmoDenger
Brass Contributor
Oct 10, 2019

Polycom VVX 411 Signing out Users at Random

Hello,

We are about to roll out Polycom VVX411 phones using SfB but in our testing users are getting logged out seemingly randomly between 7-30 days.  They do get an error "Exchange authentication failed. Sign out and sign in again." on their Polycom phones about 1-2 hours before the phone actually logs them out. We are running Polycom UC Software version 5.9.3.2857

 

We have MFA enabled for our end users also.  We are using SfB and Exchange online, nothing on-prem. 

 

Has anyone seen or fixed this issue in their environment?

Thanks!

15 Replies

  • DamianCastillo's avatar
    DamianCastillo
    Copper Contributor

    Hi CosmoDenger 

     

    If you are using MFA, web sign-in is required.

     

    Ref: https://documents.polycom.com/bundle/ucs-sfb-dg-5-9-0/page/c-ucs-sfb-web-sign-in-for-skype-for-business-online.html

     

    Web Sign In supports Multi-Factor Authentication (MFA) on polycom phones. If you are using MFA, you must use Web Sign In as the user sign-in method with Polycom phones.

     

    For more information on configuring Office 365, see Microsoft's Configure Azure Multi-Factor Authentication Settings.

     

    • CosmoDenger's avatar
      CosmoDenger
      Brass Contributor

      DamianCastillo, absolutely.  We have no problems signing in.  The issue is that our users are signed out automatically every 7 days.  I have two cases open with Microsoft and no one can figure out what to change to prevent the sign outs. 

      • DamianCastillo's avatar
        DamianCastillo
        Copper Contributor

        Hello CosmoDenger 

         

        Are you still having the same issue? usually, that kind of error can be found in the logs of the phones.

         

        You can try checking this Poly community post:

        https://community.polycom.com/t5/VoIP-SIP-Phones/FAQ-How-can-change-Logging-Levels-or-use-Syslog/td-p/4741

         

        I would recommend you to enable these ones for exchange issues:

        app1=2 , pps=2 , sip=debug, so=2 , auth=debug  nisvc= debug  pgui= debug  curl=1

         

        and for registration issues:

        app1=2 , pps=1 , sip=debug, so=2 , auth=debug  nisvc= debug  tls= debug  curl=1

         

        Also, you may confirm that the consent its being applied by your O365 Admin:

        https://techcommunity.microsoft.com/t5/skype-for-business-blog/oauth-2-0-and-third-party-application-id-timeline-extended-to/ba-p/482876

         

        That would give you an idea.

         

        (Y) 😄 

         

  • CosmoDenger's avatar
    CosmoDenger
    Brass Contributor

    Update: I have a ticket open with Microsoft and Polycom for this issue.  At this point they are just pointing fingers at each other.  I'll update everyone if we find a solution. 

Resources