Multiple federated accounts cannot login to Outlook Desktop

%3CLINGO-SUB%20id%3D%22lingo-sub-1973460%22%20slang%3D%22en-US%22%3EMultiple%20federated%20accounts%20cannot%20login%20to%20Outlook%20Desktop%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1973460%22%20slang%3D%22en-US%22%3E%3CP%3EEnvironment%3A%3C%2FP%3E%3CUL%3E%3CLI%3EAD%20FS%20on-prem%3C%2FLI%3E%3CLI%3EExchange%20Online%20Hybrid%3C%2FLI%3E%3C%2FUL%3E%3CP%3EClient%3A%3C%2FP%3E%3CUL%3E%3CLI%3EDomain%20bound%20Windows%2010%3C%2FLI%3E%3CLI%3EOffice%202016%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20client%20machine%2C%20user%20is%20setup%20with%20his%20mailbox%20in%20Outlook.%3C%2FP%3E%3CP%3EUser%20also%20requires%20to%20add%20additional%20mailbox%20in%20their%20Outlook.%20When%20we%20try%20to%20add%20another%20account%2C%20it%20does%20not%20prompt%20for%20credentials%20and%20adds%20the%20account%20in%20Outlook%20right%20away.%20This%20is%20happening%20because%20user%20is%20logged%20into%20machine%20with%20his%20AD%20account%20and%20AD%20FS%20uses%20those%20credentials%20and%20skips%20the%20authentication%20window%20even%20if%20we%20are%20trying%20to%20setup%20a%20new%20account.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20can%20this%20situation%20be%20handled%20and%20user%20can%20be%20allowed%20to%20setup%20another%20account%20in%20their%20Outlook%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1973460%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Eadfs%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1977851%22%20slang%3D%22en-US%22%3ERe%3A%20Multiple%20federated%20accounts%20cannot%20login%20to%20Outlook%20Desktop%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1977851%22%20slang%3D%22en-US%22%3E%3CP%3EHey!%3CBR%20%2F%3EHow%20are%20you%20adding%20the%20new%20account%20to%20the%20current%20Outlook%20profile%3F%3CBR%20%2F%3EYou%20could%20test%20to%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3COL%3E%3CLI%3ECheck%20Credential%20Manager%20after%20saved%20credentials%20for%20the%20new%20account%20you%20are%20trying%20add%2C%20and%20clear%20them%20if%20there%20are%20any%3C%2FLI%3E%3CLI%3EShutdown%20Outlook%3C%2FLI%3E%3CLI%3EOpen%20the%20mail%20application%20through%20the%20control%20panel%3C%2FLI%3E%3CLI%3EShow%20profiles%3C%2FLI%3E%3CLI%3ESelect%20the%20profile%20and%20click%20on%20properties%3C%2FLI%3E%3CLI%3EAdd%20the%20new%20account%20under%20email%20address%3C%2FLI%3E%3C%2FOL%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1977900%22%20slang%3D%22en-US%22%3ERe%3A%20Multiple%20federated%20accounts%20cannot%20login%20to%20Outlook%20Desktop%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1977900%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F97603%22%20target%3D%22_blank%22%3E%40Pontus%20Sj%C3%A4lander%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EADFS%20IDP%20URL%20is%20added%20under%20Trusted%20sites%20in%20IE%20and%20controlled%20by%20system%20admin%20through%20group%20policy.%26nbsp%3B%3C%2FLI%3E%3CLI%3EADFS%20IDP%20URL%20being%20in%20Trusted%20sites%20makes%20user%20to%20auto-login%20to%20this%20site%20using%20his%20AD%20Account%20login%20to%20PC%3C%2FLI%3E%3CLI%3ECredential%20Manager%20do%20not%20have%20any%20entry%20for%20new%20account%20I'm%20trying%20to%20add%3C%2FLI%3E%3CLI%3EI%20shutdown%20Outlook%3C%2FLI%3E%3CLI%3EOpened%20Mail%20app%20from%20control%20panel%20%26gt%3B%20added%20email%20and%20password%3C%2FLI%3E%3CLI%3EThen%20I%20see%20prompt%20of%20modern%20authentication%20for%20about%202-3%20seconds%20and%20then%20it%20disappears%3C%2FLI%3E%3CLI%3EConfig%20wizard%20says%20%22Congratulations!%20Your%20email%20account%20was%20successfully%20configured%20and%20is%20ready%20to%20use.%22%3C%2FLI%3E%3CLI%3EI%20closed%20wizard%2C%20opened%20Outlook.%3C%2FLI%3E%3CLI%3ENow%2C%20I%20continuously%20see%20modern%20authentication%20prompt%20appear%2Fdisappear%3C%2FLI%3E%3CLI%3ENewly%20mailbox%20is%20collapsed%20and%20when%20I%20try%20to%20expand%20it%2C%20I%20see%20following%20message%3A%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Screenshot%202020-12-10%20151917.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F239706iC491947F4C99EA76%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22Screenshot%202020-12-10%20151917.png%22%20alt%3D%22Screenshot%202020-12-10%20151917.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%2C%20the%20issue%20still%20persists.%20I%20think%20when%20I%20try%20to%20add%20new%20account%2C%20it%20redirects%20to%20Microsoft%20modern%20authentication%20prompt.%20Microsoft%20authentication%20prompts%20figures%20that%20this%20domain%20is%20federated%20and%20it%20redirects%20to%20our%20ADFS%20for%20authentication.%20On%20ADFS%2C%20previous%20user%20is%20already%20signed%20in%20so%20based%20on%20single-sign-on%20concept%2C%20it%20uses%20current%20session%20and%20pass%20token%20to%20Microsoft.%20Now%2C%20Microsoft%20was%20expecting%20token%20for%20a%20new%20account%20but%20it%20received%20for%20the%20existing%20mailbox%20and%20hence%20we%20cannot%20authenticate%20to%20new%20account.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1977941%22%20slang%3D%22en-US%22%3ERe%3A%20Multiple%20federated%20accounts%20cannot%20login%20to%20Outlook%20Desktop%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1977941%22%20slang%3D%22en-US%22%3EI%20see%20what%20you%20mean.%20If%20you%20create%20a%20whole%20new%20profile%2C%20and%20add%20the%20new%20account%2C%20same%20issue%3F%3CBR%20%2F%3EJust%20for%20making%20sure%20that%20there%20isn't%20any%20%22local%22%20issues%20with%20the%20device%2Foffice%20installation%20I%20would%20have%20added%20those%20accounts%20on%20a%20new%20VM%20that%20is%20100%25%20patched%20and%20see%20if%20you%20have%20the%20same%20result%3C%2FLINGO-BODY%3E
Occasional Contributor

Environment:

  • AD FS on-prem
  • Exchange Online Hybrid

Client:

  • Domain bound Windows 10
  • Office 2016

 

On client machine, user is setup with his mailbox in Outlook.

User also requires to add additional mailbox in their Outlook. When we try to add another account, it does not prompt for credentials and adds the account in Outlook right away. This is happening because user is logged into machine with his AD account and AD FS uses those credentials and skips the authentication window even if we are trying to setup a new account.

 

How can this situation be handled and user can be allowed to setup another account in their Outlook?

6 Replies

Hey!
How are you adding the new account to the current Outlook profile?
You could test to:

  1. Check Credential Manager after saved credentials for the new account you are trying add, and clear them if there are any
  2. Shutdown Outlook
  3. Open the mail application through the control panel
  4. Show profiles
  5. Select the profile and click on properties
  6. Add the new account under email address

@Pontus Själander 

 

  • ADFS IDP URL is added under Trusted sites in IE and controlled by system admin through group policy. 
  • ADFS IDP URL being in Trusted sites makes user to auto-login to this site using his AD Account login to PC
  • Credential Manager do not have any entry for new account I'm trying to add
  • I shutdown Outlook
  • Opened Mail app from control panel > added email and password
  • Then I see prompt of modern authentication for about 2-3 seconds and then it disappears
  • Config wizard says "Congratulations! Your email account was successfully configured and is ready to use."
  • I closed wizard, opened Outlook.
  • Now, I continuously see modern authentication prompt appear/disappear
  • Newly mailbox is collapsed and when I try to expand it, I see following message:

Screenshot 2020-12-10 151917.png

 

So, the issue still persists. I think when I try to add new account, it redirects to Microsoft modern authentication prompt. Microsoft authentication prompts figures that this domain is federated and it redirects to our ADFS for authentication. On ADFS, previous user is already signed in so based on single-sign-on concept, it uses current session and pass token to Microsoft. Now, Microsoft was expecting token for a new account but it received for the existing mailbox and hence we cannot authenticate to new account.

I see what you mean. If you create a whole new profile, and add the new account, same issue?
Just for making sure that there isn't any "local" issues with the device/office installation I would have added those accounts on a new VM that is 100% patched and see if you have the same result

@Pontus Själander 

 

Same issue with fresh new profile as well.

There is no local issue on machine. This is a citrix environment and we have tested this on 2 different citrix machines as well and behavior is same everywhere.

Alright, that's good!
Next step for me, would be to do exactly the same thing on another user, just for trying to locate the issue. Might be some old attributes/autodiscover functions that is causing the issue on one of those specific accounts you are currently working with