Outlook intermittent issues connecting to Exchange Online

%3CLINGO-SUB%20id%3D%22%5C%26quot%3Blingo-sub-3145585%5C%26quot%3B%22%20slang%3D%22%5C%26quot%3Ben-US%5C%26quot%3B%22%3EOutlook%20intermittent%20issues%20connecting%20to%20Exchange%20Online%26lt%3B%5C%2Flingo-sub%26gt%3B%3CLINGO-BODY%20id%3D%22%5C%26quot%3Blingo-body-3145585%5C%26quot%3B%22%20slang%3D%22%5C%26quot%3Ben-US%5C%26quot%3B%22%3E%3CP%3EI%20have%20a%20client%20with%20three%20server%20Windows%20Server%202019%20RD%20Session%20Host%20farm.%20In%20addition%2C%20many%20users%20are%20running%20Windows%2010%20Enterprise.%20Both%20of%20these%20have%20the%20same%20key%20build%20number.%20The%20RD%20Session%20Host%20and%20the%20end%20user%20PCs%20are%20running%20Microsoft%20365%20Apps%20for%20Enterprise.%20All%20mailboxes%20are%20in%20Exchange%20Online.%20For%20months%20we%20have%20had%20intermittent%20issues%20with%20some%2C%20but%20not%20all%2C%20users.%26lt%3B%5C%2FP%26gt%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%26lt%3B%5C%2FP%26gt%3B%3C%2FP%3E%3CP%3EIntermittently%20when%20a%20user%2C%20often%20on%20a%20RD%20Session%20Host%2C%20opens%20Outlook%20he%20or%20she%20gets%20this%20error%3A%26lt%3B%5C%2FP%26gt%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%26lt%3B%5C%2FP%26gt%3B%3C%2FP%3E%3CP%3ECannot%20start%20Microsoft%20Outlook.%20Cannot%20open%20the%20Outlook%20window.%20The%20set%20of%20folders%20cannot%20be%20opened.%20The%20information%20store%20could%20not%20be%20opened.%26lt%3B%5C%2FP%26gt%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%26lt%3B%5C%2FP%26gt%3B%3C%2FP%3E%3CP%3EOn%20the%20RD%20Session%20Host%20the%20Outlook%20profiles%20are%20in%20online%20mode%20not%20cached%20mode.%26nbsp%3B%20%26nbsp%3B%26lt%3B%5C%2FP%26gt%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%26lt%3B%5C%2FP%26gt%3B%3C%2FP%3E%3CP%3EThings%20we%20have%20tried%3A%26lt%3B%5C%2FP%26gt%3B%3CUL%3E%3CLI%3EWhen%20this%20occurs%20we%20are%20unable%20to%20create%20a%20new%20Outlook%20profile%20as%20it%20gives%20an%20error.%20I%20don't%20have%20the%20specific%20verbiage%20but%20fundamentally%20it's%20unable%20to%20connect%20to%20the%20user%20mailbox%20or%20information%20store.%26lt%3B%5C%2FLI%26gt%3B%3C%2FLI%3E%3CLI%3EIf%20the%20user%20opens%20a%20web%20browser%20he%20or%20she%20can%20access%20business%20email%20via%20Outlook%20Online.%26lt%3B%5C%2FLI%26gt%3B%3C%2FLI%3E%3CLI%3EIf%20the%20user%20logs%20off%20that%20RD%20Session%20Host%20and%20is%20forced%20to%20login%20to%20a%20different%20one%20often%20Outlook%20will%20connect%20to%20Exchange%20Online%20on%20that%20second%20RD%20Session%20Host.%20If%20the%20user%20remains%20on%20the%20initial%20RD%20Session%20Host%20later%20that%20day%20Outlook%20may%20be%20able%20to%20connect.%26lt%3B%5C%2FLI%26gt%3B%3C%2FLI%3E%3CLI%3EWe%20modified%20the%20Sonicwall%20hardware%20firewall's%20geo-IP%20filter%20to%20not%20block%20outbound%20connections%20based%20on%20destination%20country.%26nbsp%3B%26lt%3B%5C%2FLI%26gt%3B%3C%2FLI%3E%3CLI%3EUsers%20have%20Office%20365%20E3%20licenses%2C%20therefore%2C%20there%20are%20no%20Conditional%20Access%20policies.%26lt%3B%5C%2FLI%26gt%3B%3C%2FLI%3E%3CLI%3EUsers%20do%20not%20have%20Azure%20AD%20MFA%20explicitly%20enabled%20on%20their%20accounts.%26lt%3B%5C%2FLI%26gt%3B%3C%2FLI%3E%3CLI%3EWe%20are%20using%20Cisco%20Umbrella%20with%20the%20OpenDNS%20DNS%20servers.%20The%20RD%20Session%20Hosts%20do%20not%20have%20the%20Cisco%20Umbrella%20Roaming%20Client%20installed%20as%20they%20don't%20leave%20the%20network.%20The%20Windows%20Server%20DNS%20Server%20roles%20are%20configured%20to%20forward%20to%20OpenDNS.%20I%20enabled%20DNS%20debug%20logging%20and%20reviewed%20the%20DNS%20queries%20from%20a%20recent%20incident.%20I%20found%20no%20DNS%20queries%20with%20result%20other%20than%20NOERROR.%20The%20second%20DNS%20server's%20log%20wrapped%20prior%20to%20the%20most%20recent%20incident.%20Globally%20we%20are%20blocking%20pastebin.com%20and%20github.io.%20I%20found%20neither%20of%20them%20in%20the%20DNS%20log.%26lt%3B%5C%2FLI%26gt%3B%3C%2FLI%3E%3CLI%3EThe%20most%20recent%20user%20who%20had%20the%20problem%20is%20a%20new%20employee%20with%20a%20very%20small%20user%20mailbox.%26lt%3B%5C%2FLI%26gt%3B%3C%2FLI%3E%3CLI%3EWe%20worked%20with%20our%20CSP%20and%20Microsoft%20tech%20support%20but%20they%20were%20unable%20to%20figure%20it%20out.%26lt%3B%5C%2FLI%26gt%3B%3C%2FLI%3E%3CLI%3EDuring%20the%20most%20recent%20incident%20I%20explored%20starting%20Outlook%20logging%20but%20in%20order%20to%20do%20that%20you%20need%20to%20go%20into%20the%20Outlook%20options...which%20I%20couldn't%20access.%26lt%3B%5C%2FLI%26gt%3B%26lt%3B%5C%2FUL%26gt%3B%3CP%3E%26nbsp%3B%26lt%3B%5C%2FP%26gt%3B%3C%2FP%3E%3CP%3EI'm%20running%20out%20of%20ideas.%20The%20intermittent%20nature%20and%20the%20fact%20that%20it's%20not%20impacting%20all%20users%20has%20me%20frustrated%20and%20running%20out%20of%20places%20to%20look.%20Do%20I%20need%20to%20look%20at%20installing%20and%20configuring%20FSLogix%20and%20have%20the%20RD%20Session%20Host%20users%20transition%20to%20Outlook%20with%20cached%20mode%3F%20As%20far%20as%20I%20know%20this%20is%20the%20only%20client%20where%20we%20are%20having%20this%20issue%20and%20I'm%20having%20trouble%20figuring%20out%20what's%20unique%20about%20them.%26nbsp%3B%26lt%3B%5C%2FP%26gt%3B%26lt%3B%5C%2Flingo-body%26gt%3B%3CLINGO-LABS%20id%3D%22%5C%26quot%3Blingo-labs-3145585%5C%26quot%3B%22%20slang%3D%22%5C%26quot%3Ben-US%5C%26quot%3B%22%3E%3CLINGO-LABEL%3EExchange%20Online%26lt%3B%5C%2Flingo-label%26gt%3B%3CLINGO-LABEL%3EOffice%20365%26lt%3B%5C%2Flingo-label%26gt%3B%26lt%3B%5C%2Flingo-labs%26gt%3B%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3C%2FP%3E%3C%2FLI%3E%3C%2FUL%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3C%2FLINGO-SUB%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3145585%22%20slang%3D%22en-US%22%3EOutlook%20intermittent%20issues%20connecting%20to%20Exchange%20Online%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3145585%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20a%20client%20with%20three%20server%20Windows%20Server%202019%20RD%20Session%20Host%20farm.%20In%20addition%2C%20many%20users%20are%20running%20Windows%2010%20Enterprise.%20Both%20of%20these%20have%20the%20same%20key%20build%20number.%20The%20RD%20Session%20Host%20and%20the%20end%20user%20PCs%20are%20running%20Microsoft%20365%20Apps%20for%20Enterprise.%20All%20mailboxes%20are%20in%20Exchange%20Online.%20For%20months%20we%20have%20had%20intermittent%20issues%20with%20some%2C%20but%20not%20all%2C%20users.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIntermittently%20when%20a%20user%2C%20often%20on%20a%20RD%20Session%20Host%2C%20opens%20Outlook%20he%20or%20she%20gets%20this%20error%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECannot%20start%20Microsoft%20Outlook.%20Cannot%20open%20the%20Outlook%20window.%20The%20set%20of%20folders%20cannot%20be%20opened.%20The%20information%20store%20could%20not%20be%20opened.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20the%20RD%20Session%20Host%20the%20Outlook%20profiles%20are%20in%20online%20mode%20not%20cached%20mode.%26nbsp%3B%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThings%20we%20have%20tried%3A%3C%2FP%3E%3CUL%3E%3CLI%3EWhen%20this%20occurs%20we%20are%20unable%20to%20create%20a%20new%20Outlook%20profile%20as%20it%20gives%20an%20error.%20I%20don't%20have%20the%20specific%20verbiage%20but%20fundamentally%20it's%20unable%20to%20connect%20to%20the%20user%20mailbox%20or%20information%20store.%3C%2FLI%3E%3CLI%3EIf%20the%20user%20opens%20a%20web%20browser%20he%20or%20she%20can%20access%20business%20email%20via%20Outlook%20Online.%3C%2FLI%3E%3CLI%3EIf%20the%20user%20logs%20off%20that%20RD%20Session%20Host%20and%20is%20forced%20to%20login%20to%20a%20different%20one%20often%20Outlook%20will%20connect%20to%20Exchange%20Online%20on%20that%20second%20RD%20Session%20Host.%20If%20the%20user%20remains%20on%20the%20initial%20RD%20Session%20Host%20later%20that%20day%20Outlook%20may%20be%20able%20to%20connect.%3C%2FLI%3E%3CLI%3EWe%20modified%20the%20Sonicwall%20hardware%20firewall's%20geo-IP%20filter%20to%20not%20block%20outbound%20connections%20based%20on%20destination%20country.%26nbsp%3B%3C%2FLI%3E%3CLI%3EUsers%20have%20Office%20365%20E3%20licenses%2C%20therefore%2C%20there%20are%20no%20Conditional%20Access%20policies.%3C%2FLI%3E%3CLI%3EUsers%20do%20not%20have%20Azure%20AD%20MFA%20explicitly%20enabled%20on%20their%20accounts.%3C%2FLI%3E%3CLI%3EWe%20are%20using%20Cisco%20Umbrella%20with%20the%20OpenDNS%20DNS%20servers.%20The%20RD%20Session%20Hosts%20do%20not%20have%20the%20Cisco%20Umbrella%20Roaming%20Client%20installed%20as%20they%20don't%20leave%20the%20network.%20The%20Windows%20Server%20DNS%20Server%20roles%20are%20configured%20to%20forward%20to%20OpenDNS.%20I%20enabled%20DNS%20debug%20logging%20and%20reviewed%20the%20DNS%20queries%20from%20a%20recent%20incident.%20I%20found%20no%20DNS%20queries%20with%20result%20other%20than%20NOERROR.%20The%20second%20DNS%20server's%20log%20wrapped%20prior%20to%20the%20most%20recent%20incident.%20Globally%20we%20are%20blocking%20pastebin.com%20and%20github.io.%20I%20found%20neither%20of%20them%20in%20the%20DNS%20log.%3C%2FLI%3E%3CLI%3EThe%20most%20recent%20user%20who%20had%20the%20problem%20is%20a%20new%20employee%20with%20a%20very%20small%20user%20mailbox.%3C%2FLI%3E%3CLI%3EWe%20worked%20with%20our%20CSP%20and%20Microsoft%20tech%20support%20but%20they%20were%20unable%20to%20figure%20it%20out.%3C%2FLI%3E%3CLI%3EDuring%20the%20most%20recent%20incident%20I%20explored%20starting%20Outlook%20logging%20but%20in%20order%20to%20do%20that%20you%20need%20to%20go%20into%20the%20Outlook%20options...which%20I%20couldn't%20access.%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20running%20out%20of%20ideas.%20The%20intermittent%20nature%20and%20the%20fact%20that%20it's%20not%20impacting%20all%20users%20has%20me%20frustrated%20and%20running%20out%20of%20places%20to%20look.%20Do%20I%20need%20to%20look%20at%20installing%20and%20configuring%20FSLogix%20and%20have%20the%20RD%20Session%20Host%20users%20transition%20to%20Outlook%20with%20cached%20mode%3F%20As%20far%20as%20I%20know%20this%20is%20the%20only%20client%20where%20we%20are%20having%20this%20issue%20and%20I'm%20having%20trouble%20figuring%20out%20what's%20unique%20about%20them.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3145585%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%20Online%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
New Contributor

I have a client with three server Windows Server 2019 RD Session Host farm. In addition, many users are running Windows 10 Enterprise. Both of these have the same key build number. The RD Session Host and the end user PCs are running Microsoft 365 Apps for Enterprise. All mailboxes are in Exchange Online. For months we have had intermittent issues with some, but not all, users.

 

Intermittently when a user, often on a RD Session Host, opens Outlook he or she gets this error:

 

Cannot start Microsoft Outlook. Cannot open the Outlook window. The set of folders cannot be opened. The information store could not be opened.

 

On the RD Session Host the Outlook profiles are in online mode not cached mode.   

 

Things we have tried:

  • When this occurs we are unable to create a new Outlook profile as it gives an error. I don't have the specific verbiage but fundamentally it's unable to connect to the user mailbox or information store.
  • If the user opens a web browser he or she can access business email via Outlook Online.
  • If the user logs off that RD Session Host and is forced to login to a different one often Outlook will connect to Exchange Online on that second RD Session Host. If the user remains on the initial RD Session Host later that day Outlook may be able to connect.
  • We modified the Sonicwall hardware firewall's geo-IP filter to not block outbound connections based on destination country. 
  • Users have Office 365 E3 licenses, therefore, there are no Conditional Access policies.
  • Users do not have Azure AD MFA explicitly enabled on their accounts.
  • We are using Cisco Umbrella with the OpenDNS DNS servers. The RD Session Hosts do not have the Cisco Umbrella Roaming Client installed as they don't leave the network. The Windows Server DNS Server roles are configured to forward to OpenDNS. I enabled DNS debug logging and reviewed the DNS queries from a recent incident. I found no DNS queries with result other than NOERROR. The second DNS server's log wrapped prior to the most recent incident. Globally we are blocking pastebin.com and github.io. I found neither of them in the DNS log.
  • The most recent user who had the problem is a new employee with a very small user mailbox.
  • We worked with our CSP and Microsoft tech support but they were unable to figure it out.
  • During the most recent incident I explored starting Outlook logging but in order to do that you need to go into the Outlook options...which I couldn't access.

 

I'm running out of ideas. The intermittent nature and the fact that it's not impacting all users has me frustrated and running out of places to look. Do I need to look at installing and configuring FSLogix and have the RD Session Host users transition to Outlook with cached mode? As far as I know this is the only client where we are having this issue and I'm having trouble figuring out what's unique about them. 

0 Replies