AutoDiscover not working externally in a hybrid setup

Copper Contributor
 

Hello,

 

I am hoping someone might know how to help us with this issue. I'm not finding much online for this error.

 

In our lab, we have:

Exchange 2016

Microsoft 365 E3

Hybrid setup

Modern Auth setup

 

Migrated a mailbox from on premise to 365.

 

I tried to setup a mailbox externally on Outlook 2016 (Windows 10) and on my iphone (Outlook App). Both fail. (Note: It does work on Outlook on a domain joined computer inside the network). In Outlook, at the "searching for email address removed for privacy reasons settings", it prompts for authentication to Azure. After I authenticate, it redirects to "Can't reach this page" "Make sure your web address https://login.microsoftonline.com..". The iphone's mailbox setup has same error.

==========================

Ran the Outlook Mobile Hybrid Modern Authentication Test

Connectivity Test Failed

Test Details

Testing Outlook Mobile Hybrid Modern Authentication (HMA) for SMTP email address: email address removed for privacy reasons.

Testing Outlook Mobile Hybrid Modern Authentication (HMA) failed. Test Steps

Sending an Autodiscover request to the on-premises Exchange Autodiscover service: https://autodiscover.bedrock.net/autodiscover/autodiscover.json?Email=email address removed for priv.... The on-premises Exchange Autodiscover service didn't return a valid response that passed analysis.

Test Steps

Sending an Autodiscover request to the on-premises Exchange Autodiscover service: https://autodiscover.bedrock.net/autodiscover/autodiscover.json?Email=email address removed for priv.... The on-premises Exchange Autodiscover service didn't return a valid response. Additional Details The EAS response contained unexpected data: Unexpected character encountered while parsing value: <. Path '', line 0, position 0.. HTTP Response Headers: request-id: 59205ba7-0b1e-49c3-9c20-14747900da60

X-CalculatedBETarget: lab-ex02.bedrock.lab
X-DiagInfo: LAB-EX02
X-BEServer: LAB-EX02
X-OWA-Version: 15.1.2507.6
X-FEServer: LAB-EX02
Content-Length: 275
Cache-Control: private
Content-Type: text/html; charset=utf-8
Date: Thu, 29 Dec 2022 18:20:01 GMT
Location: https://outlook.office365.com/autodiscover/autodiscover.json?Email=fred.flinstone%40bedrock.mail.onm...
Set-Cookie: X-BackEndCookie=; expires=Tue, 29-Dec-1992 18:20:02 GMT; path=/autodiscover; secure; HttpOnly

Server: Microsoft-IIS/10.0
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET

====================================

 

I ran Outlook Connectivity and see these errors:

Attempting to send an Autodiscover POST request to potential Autodiscover URLs.
Autodiscover settings weren't obtained when the Autodiscover POST request was sent.
Test Steps
The Microsoft Connectivity Analyzer is attempting to retrieve an XML Autodiscover response from URL https://bedrock.net:443/Autodiscover/Autodiscover.xml for user email address removed for privacy reasons.
The Microsoft Connectivity Analyzer failed to obtain an Autodiscover XML response.
Additional Details

A Web exception occurred because an HTTP 404 - 404 response was received from Unknown.

HTTP Response Headers:
Keep-Alive: timeout=5, max=100
Connection: Keep-Alive
Content-Length: 227
Content-Type: text/html; charset=iso-8859-1
Date: Thu, 29 Dec 2022 18:37:05 GMT
Server: Apache

===============================================

Testing the MAPI Address Book endpoint on the Exchange server.

An error occurred while testing the address book endpoint.
Test Steps
Testing the address book "Check Name" operation for user email address removed for privacy reasons against server outlook.office365.com.
An error occurred while attempting to resolve the name.

Additional Details
A protocol layer error occured.

HttpStatusCode: 401
Failure LID: 47372
Failure Information:
###### REQUEST [2022-12-29T18:37:15.2603368Z] [ResolvedIPs: 52.96.214.50,52.96.59.194,52.96.182.146,52.96.17.178] ######
POST /mapi/nspi/?mailboxId=email address removed for privacy reasons HTTP/1.1
Content-Type: application/octet-stream
User-Agent: MapiHttpClient
X-RequestId: bdc6cc01-abed-4c68-b39e-0cf36ae84f2e:1
X-ClientInfo: 3571f951-bafb-42de-b014-b7eceb5042d2:1
client-request-id: b95a575a-7b2e-4df2-8e7f-39d1acfae4b5
X-ClientApplication: MapiHttpClient/15.20.5791.1
X-RequestType: Bind
Authorization: Basic [truncated]
Host: outlook.office365.com
Cookie: MapiRouting=UlVNOmIxNGQ4Yjg5LTJkZmItNDU2Zi1iYTc0LWZhZDk5Y2E0NmU3MDroNyC1y+naCA==
Content-Length: 45

--- REQUEST BODY [+0.002] ---

..[BODY SIZE: 45]

--- REQUEST SENT [+0.002] ---

###### RESPONSE [+0.058] ######

HTTP/1.1 401

request-id: c40ba328-2148-2c73-2b03-37b87a4a656a
Alt-Svc: h3=":443",h3-29=":443"
X-CalculatedBETarget: DM8PR16MB4454.namprd16.PROD.OUTLOOK.COM
X-BackEndHttpStatus: 401
X-ServerApplication: Exchange/15.20.5944.016
X-RequestId: bdc6cc01-abed-4c68-b39e-0cf36ae84f2e:1
X-ClientInfo: 3571f951-bafb-42de-b014-b7eceb5042d2:1 X-RequestType: Bind
X-RUM-Validated: 1
X-RUM-NotUpdateQueriedPath: 1
X-DiagInfo: DM8PR16MB4454
X-BEServer: DM8PR16MB4454
X-Proxy-RoutingCorrectness: 1
X-FailureContext: BackEnd;401;;;;;
X-Proxy-BackendServerStatus: 401
X-FirstHopCafeEFZ: DSM
X-FEProxyInfo: DS7PR03CA0303.NAMPRD03.PROD.OUTLOOK.COM
X-FEEFZInfo: DSM
X-FEServer: DS7PR03CA0303 Content-Length: 0
Date: Thu, 29 Dec 2022 18:37:15 GMT
Set-Cookie: MapiRouting=UlVNOmIxNGQ4Yjg5LTJkZmItNDU2Zi1iYTc0LWZhZDk5Y2E0NmU3MDpc/CS1y+naCA==; path=/mapi/; secure; HttpOnly
Server: Microsoft-IIS/10.0
WWW-Authenticate: Basic [truncated]
X-Powered-By: ASP.NET

--- RESPONSE BODY [+0.058] ---

--- RESPONSE DONE [+0.058] ---

###### EXCEPTION THROWN [+0.058] ######

HTTP Response Headers:
request-id: c40ba328-2148-2c73-2b03-37b87a4a656a
Alt-Svc: h3=":443",h3-29=":443"
X-CalculatedBETarget: DM8PR16MB4454.namprd16.PROD.OUTLOOK.COM
X-BackEndHttpStatus: 401
X-ServerApplication: Exchange/15.20.5944.016
X-RequestId: bdc6cc01-abed-4c68-b39e-0cf36ae84f2e:1
X-ClientInfo: 3571f951-bafb-42de-b014-b7eceb5042d2:1
X-RequestType: Bind
X-RUM-Validated: 1 X-RUM-NotUpdateQueriedPath: 1
X-DiagInfo: DM8PR16MB4454
X-BEServer: DM8PR16MB4454
X-Proxy-RoutingCorrectness: 1
X-FailureContext: BackEnd;401;;;;;
X-Proxy-BackendServerStatus: 401
X-FirstHopCafeEFZ: DSM
X-FEProxyInfo: DS7PR03CA0303.NAMPRD03.PROD.OUTLOOK.COM
X-FEEFZInfo: DSM
X-FEServer: DS7PR03CA0303
Content-Length: 0
Date: Thu, 29 Dec 2022 18:37:15 GMT
Set-Cookie: MapiRouting=UlVNOmIxNGQ4Yjg5LTJkZmItNDU2Zi1iYTc0LWZhZDk5Y2E0NmU3MDpc/CS1y+naCA==; path=/mapi/; secure; HttpOnly Server: Microsoft-IIS/10.0
WWW-Authenticate: Basic Realm=""
X-Powered-By: ASP.NET

HTTP Status Code: 401 Unauthorized

0 Replies