Outlook prompts for password using ADFS 3.0

%3CLINGO-SUB%20id%3D%22lingo-sub-43805%22%20slang%3D%22en-US%22%3EOutlook%20prompts%20for%20password%20using%20ADFS%203.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-43805%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20an%20environment%20with%20Exchange%202010%20in%20a%20hybrid%20setup%20with%20Office%20365.%3CBR%20%2F%3EWe%20have%20ADFS%203.0%20running%20which%20is%20working%20fine%20when%2C%20for%20example%2C%20we%20logon%20to%20portal.office.com.%3CBR%20%2F%3EWe%20migrated%20a%20few%20test%20users%20to%20Office%20365%2F%20Exchange.%20That%20is%20all%20working%20fine.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EOne%20thing%20I%20see%20and%20I%20wonder%20if%20that%20is%20normal%20behaviour%20with%20AD%20FS%3B%3CBR%20%2F%3EWhen%20a%20migrated%20user%20opens%20Outlook%202016%20(fully%20patched)%20for%20the%20first%20time%20on%20a%20domain%20joined%20Windows%2010%20PC%20on%20the%20internal%20network%2C%20he%20is%20asked%20for%20his%20password%20with%20a%20screen%20for%20basic%20authentication.%20Is%20expected%20a%20SSO%20experience%2C%20because%20modern%20authentication%20is%20turned%20on%20for%20Exchange%20and%20did%20this%20setting%20on%20the%20ADFS%20Server%20Enable-AdfsEndpoint%20-TargetAddressPath%20%22%2Fadfs%2Fservices%2Ftrust%2F13%2Fwindowstransport%22%26nbsp%3B%3CBR%20%2F%3EIt%20is%20probably%20hitting%20the%20old%20Exchange%202010%20first%20when%20running%20the%20autodiscover%20process%2C%20which%20is%20causing%20the%20prompt.%20The%20autodiscover%20points%20at%20the%20internal%20Exchange%20server%20and%20not%20to%20O365%2C%20becuase%20are%20other%20mailboxes%20are%20on-prem.%3CBR%20%2F%3E%3CBR%20%2F%3EIs%20their%20a%20solution%20to%20prevent%20this%20behaviour%20of%20Office%202016%3F%3CBR%20%2F%3E%3CBR%20%2F%3EThank%20you!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-43805%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-139324%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20prompts%20for%20password%20using%20ADFS%203.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-139324%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20peter%2C%20do%20you%20get%20SSO%20to%20your%20internal%20Autodiscover%20website%3F%20if%20not%20then%20that's%20the%20problem%2C%20add%20your%20internal%20Autodiscover%20website%20to%20local%20intranet%20sites.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-136532%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Outlook%20prompts%20for%20password%20using%20ADFS%203.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-136532%22%20slang%3D%22en-US%22%3E%3CP%3EOffice%202010%20doesn't%20support%20Modern%20authentication%20though.%20It%20might%20be%20better%20if%20you%20describe%20your%20specific%20issue%20in%20a%20separate%20post.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-136358%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Outlook%20prompts%20for%20password%20using%20ADFS%203.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-136358%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20Vasil!%20This%20solved%20my%20problem.%20I%20enabled%20the%20modern%20auth%20on%20O365%20tenant%20but%20not%20on%20my%20Outlook%202013%20client.%20After%20doing%20that%20no%20prompts%20anymore%20and%20it%20worked.%20Outlook%202016%20has%20this%20already%20setup%20and%20now%20checking%20the%20need%20for%20Outlook%202010.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2FEnable-Modern-Authentication-for-Office-2013-on-Windows-devices-7dc1c01a-090f-4971-9677-f1b192d6c910%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2FEnable-Modern-Authentication-for-Office-2013-on-Windows-devices-7dc1c01a-090f-4971-9677-f1b192d6c910%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-45352%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Outlook%20prompts%20for%20password%20using%20ADFS%203.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-45352%22%20slang%3D%22en-US%22%3E%3CP%3EIt%20is%20because%20of%20the%20autodiscover%20cache%20which%20points%20the%20client%20to%20the%20old%20Exchange%202010%20server.%20When%20I%20delete%20the%20autodiscover%20cache%20(manually)%20from%20the%20users%20profile%20and%20reboot%20the%20device%20I%20don%60t%20see%20the%20basic%20auth%20popup%20and%20the%20user%20is%20logged%20on%20seamless%20to%20Outlook.%3CBR%20%2F%3EI%20have%20also%20setup%20a%20few%20test%20users%20on%20the%20Exchange%202016%20server%2C%20when%20they%20are%20moved%20to%20Office%20365%2C%20they%20don%60t%20see%20the%20popup%2C%20just%20restart%20Outlook%20and%20they%20are%20logged%20on%20to%20Outlook.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3ESo%20when%20I%20move%20users%20at%20night%20and%20the%20next%20morning%20the%20users%20starts%20his%20device%2C%20the%20autodiscover%20cache%20should%20be%20renewed%20and%20don%60t%20see%20a%20popup.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-43987%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Outlook%20prompts%20for%20password%20using%20ADFS%203.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-43987%22%20slang%3D%22en-US%22%3E%3CP%3EIt%20should%20be%20the%20expected%20behavior%20in%20hybrid%20setup.%20Autodiscover%20will%20and%20should%20point%20to%20your%20on-premises%20Exchange%20setup.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20article%20here%20talks%20about%20the%20autodiscover%20lookup%20process%20in%20detail%3A%20%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Frmilne%2F2015%2F04%2F29%2Foffice-365-autodiscover-lookup-process%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.technet.microsoft.com%2Frmilne%2F2015%2F04%2F29%2Foffice-365-autodiscover-lookup-process%2F%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-43915%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Outlook%20prompts%20for%20password%20using%20ADFS%203.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-43915%22%20slang%3D%22en-US%22%3EModern%20auth%20is%20enabled%20for%20Exchange%20Online%20and%20using%20Outlook%202016%2C%20it%20is%20used%20by%20Outlook.%3CBR%20%2F%3EThis%20is%20set%20on%20ADFS%3A%20Enable-AdfsEndpoint%20-TargetAddressPath%20%E2%80%9C%2Fadfs%2Fservices%2Ftrust%2F13%2Fwindowstransport%E2%80%9D%3CBR%20%2F%3E%3CBR%20%2F%3EWhen%20I%20use%20the%20hosts%20file%20on%20a%20workstation%20to%20point%20autodiscover%20to%20autodiscover.outlook.com%20everything%20is%20working%20as%20expected%2C%20with%20SSO%20experience%2C%20not%20asking%20for%20a%20password.%3CBR%20%2F%3ESo%20I%20think%20the%20behavior%20is%20caused%20because%20autodiscover%20points%20to%20our%20on-prem%20Exchange%20server%20and%20during%20the%20autodiscover%20process%20it%20hits%20this%20server%20first.%20But%20I%20cannot%20find%20an%20article%20which%20agrees%20with%20my%20thought%2C%20or%20a%20solution%2F%20workaround%20for%20this.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-43914%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Outlook%20prompts%20for%20password%20using%20ADFS%203.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-43914%22%20slang%3D%22en-US%22%3E%3CP%3EOh%2C%20and%20Modern%20auth%20needs%20to%20be%20enabled%20both%20client-side%20and%20server-side.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-43913%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Outlook%20prompts%20for%20password%20using%20ADFS%203.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-43913%22%20slang%3D%22en-US%22%3E%3CP%3EFor%20real%20SSO%20experience%20in%20Outlook%20you%20need%20Modern%20authentication%20enabled.%20Otherwise%20you%20get%20the%20basic%20auth%20prompt%2C%20that's%20the%20expected%20behavior.%20If%20you%20want%20more%20info%20check%20the%20AD%20FS%20whitepapers%3A%20%3CA%20href%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fdownload%2Fdetails.aspx%3Fid%3D36391%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fdownload%2Fdetails.aspx%3Fid%3D36391%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-43911%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Outlook%20prompts%20for%20password%20using%20ADFS%203.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-43911%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3E%3CBR%20%2F%3EYes%20I%20did.%20Adfs%20itself%20works%20fine%20by%20using%20the%20browser%2C%20but%20only%20not%20when%20using%20Outlook%202016%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-43901%22%20slang%3D%22en-US%22%3ERE%3A%20Outlook%20prompts%20for%20password%20using%20ADFS%203.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-43901%22%20slang%3D%22en-US%22%3EDid%20you%20try%20troubleshooting%20steps%20shown%20here%3F%20-%20%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F2535227%2Fa-federated-user-is-prompted-unexpectedly-to-enter-their-work-or-school-account-credentials%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F2535227%2Fa-federated-user-is-prompted-unexpectedly-to-enter-their-work-or-school-account-credentials%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1137842%22%20slang%3D%22en-US%22%3ERe%3A%20RE%3A%20Outlook%20prompts%20for%20password%20using%20ADFS%203.0%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1137842%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F3194%22%20target%3D%22_blank%22%3E%40Peter%20Klapwijk%3C%2FA%3E%26nbsp%3BAlthough%20this%20is%20an%20old%20article.%20I%20just%20wanted%20to%20add%20my%20findings%20as%20i%20have%20experienced%20exactly%20this.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20solved%20my%20problem%20was%20%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-gb%2Fhelp%2F3126599%2Foutlook-prompts-for-password-when-modern-authentication-is-enabled%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-gb%2Fhelp%2F3126599%2Foutlook-prompts-for-password-when-modern-authentication-is-enabled%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20fix%20was%3A%3C%2FP%3E%3COL%3E%3CLI%3E%3CSTRONG%3EHKEY_CURRENT_USER%5CSoftware%5CMicrosoft%5CExchange%3CBR%20%2F%3E%3C%2FSTRONG%3E%3C%2FLI%3E%3CLI%3EOn%20the%20%3CSTRONG%3EEdit%20%3C%2FSTRONG%3Emenu%2C%20point%20to%20%3CSTRONG%3ENew%3C%2FSTRONG%3E%2C%20and%20then%20click%20%3CSTRONG%3EDWORD%20Value%3C%2FSTRONG%3E.%3C%2FLI%3E%3CLI%3EType%20%3CSPAN%20class%3D%22sbody-userinput%22%3EAlwaysUseMSOAuthForAutoDiscover%3C%2FSPAN%3E%2C%20and%20then%20press%20Enter.%3C%2FLI%3E%3CLI%3ERight-click%20%3CSTRONG%3EAlwaysUseMSOAuthForAutoDiscover%3C%2FSTRONG%3E%2C%20and%20then%20click%20%3CSTRONG%3EModify%3C%2FSTRONG%3E.%3C%2FLI%3E%3CLI%3EIn%20the%20%3CSTRONG%3EValue%20data%20%3C%2FSTRONG%3Ebox%2C%20type%20%3CSPAN%20class%3D%22sbody-userinput%22%3E1%3C%2FSPAN%3E%2C%20and%20then%20click%20%3CSTRONG%3EOK%3C%2FSTRONG%3E.%3C%2FLI%3E%3C%2FOL%3E%3C%2FLINGO-BODY%3E
Highlighted
Regular Contributor

Hi all,

 

I have an environment with Exchange 2010 in a hybrid setup with Office 365.
We have ADFS 3.0 running which is working fine when, for example, we logon to portal.office.com.
We migrated a few test users to Office 365/ Exchange. That is all working fine.


One thing I see and I wonder if that is normal behaviour with AD FS;
When a migrated user opens Outlook 2016 (fully patched) for the first time on a domain joined Windows 10 PC on the internal network, he is asked for his password with a screen for basic authentication. Is expected a SSO experience, because modern authentication is turned on for Exchange and did this setting on the ADFS Server Enable-AdfsEndpoint -TargetAddressPath "/adfs/services/trust/13/windowstransport" 
It is probably hitting the old Exchange 2010 first when running the autodiscover process, which is causing the prompt. The autodiscover points at the internal Exchange server and not to O365, becuase are other mailboxes are on-prem.

Is their a solution to prevent this behaviour of Office 2016?

Thank you!

11 Replies
Highlighted
Hi,

Yes I did. Adfs itself works fine by using the browser, but only not when using Outlook 2016
Highlighted

For real SSO experience in Outlook you need Modern authentication enabled. Otherwise you get the basic auth prompt, that's the expected behavior. If you want more info check the AD FS whitepapers: https://www.microsoft.com/en-us/download/details.aspx?id=36391

Highlighted

Oh, and Modern auth needs to be enabled both client-side and server-side.

Highlighted
Modern auth is enabled for Exchange Online and using Outlook 2016, it is used by Outlook.
This is set on ADFS: Enable-AdfsEndpoint -TargetAddressPath “/adfs/services/trust/13/windowstransport”

When I use the hosts file on a workstation to point autodiscover to autodiscover.outlook.com everything is working as expected, with SSO experience, not asking for a password.
So I think the behavior is caused because autodiscover points to our on-prem Exchange server and during the autodiscover process it hits this server first. But I cannot find an article which agrees with my thought, or a solution/ workaround for this.
Highlighted

It should be the expected behavior in hybrid setup. Autodiscover will and should point to your on-premises Exchange setup.

 

 

This article here talks about the autodiscover lookup process in detail: https://blogs.technet.microsoft.com/rmilne/2015/04/29/office-365-autodiscover-lookup-process/

Highlighted

It is because of the autodiscover cache which points the client to the old Exchange 2010 server. When I delete the autodiscover cache (manually) from the users profile and reboot the device I don`t see the basic auth popup and the user is logged on seamless to Outlook.
I have also setup a few test users on the Exchange 2016 server, when they are moved to Office 365, they don`t see the popup, just restart Outlook and they are logged on to Outlook.


So when I move users at night and the next morning the users starts his device, the autodiscover cache should be renewed and don`t see a popup.

Highlighted

Thanks Vasil! This solved my problem. I enabled the modern auth on O365 tenant but not on my Outlook 2013 client. After doing that no prompts anymore and it worked. Outlook 2016 has this already setup and now checking the need for Outlook 2010.

 

https://support.office.com/en-us/article/Enable-Modern-Authentication-for-Office-2013-on-Windows-dev...

Highlighted

Office 2010 doesn't support Modern authentication though. It might be better if you describe your specific issue in a separate post.

Highlighted

Hi peter, do you get SSO to your internal Autodiscover website? if not then that's the problem, add your internal Autodiscover website to local intranet sites.

Highlighted

@Peter Klapwijk Although this is an old article. I just wanted to add my findings as i have experienced exactly this.

 

What solved my problem was https://support.microsoft.com/en-gb/help/3126599/outlook-prompts-for-password-when-modern-authentica...

 

This fix was:

  1. HKEY_CURRENT_USER\Software\Microsoft\Exchange
  2. On the Edit menu, point to New, and then click DWORD Value.
  3. Type AlwaysUseMSOAuthForAutoDiscover, and then press Enter.
  4. Right-click AlwaysUseMSOAuthForAutoDiscover, and then click Modify.
  5. In the Value data box, type 1, and then click OK.