Exchange Server SE / 2019 OWA Authentication Deep Dive – Part 5: Managed Availability and OWA Health Probes

Exchange Server SE / 2019 OWA Authentication Deep Dive – Part 5: Managed Availability and OWA Health Probes

Exchange
Applies to: Exchange Server SE / 2019 / 2016 Summary: Exchange generates its own OWA traffic through Managed Availability, and that traffic can look confusing when it is mixed with real user requests. In this part, we separate health probes from interactive logons and look at exhealth.check, SelfTest, DeepTest, OWADEEPTEST, EACBACKENDLOGON, HealthMailbox traffic, backend 401 challenges, and the 241 response captured during testing. Exchange's own health traffic can look surprisingly similar to failed user authentication. Knowing how to recognize Managed Availability probes prevents normal 401 challenges, HealthMailbox activity, and synthetic tests from becoming false troubleshooting leads. Part 1: How OWA Authentication Really WorksPart 2: Forms-Based and Basic Authentication – What Really Changes?Part 3: Frontend vs Backend Authentication – Controlled A/B TestsPart 4: Troubleshooting OWA Authentication with IIS and HttpProxy LogsPart…
Read More
Exchange Server SE / 2019 OWA Authentication Deep Dive – Part 4: Troubleshooting OWA Authentication with IIS and HttpProxy Logs

Exchange Server SE / 2019 OWA Authentication Deep Dive – Part 4: Troubleshooting OWA Authentication with IIS and HttpProxy Logs

Exchange
Applies to: Exchange Server SE / 2019 / 2016 Summary: OWA authentication troubleshooting gets much easier when the same request is followed through all three log layers instead of reading one HTTP status in isolation. In this part, we compare successful FBA, a bad password, and a backend authentication failure across frontend IIS, Exchange HttpProxy, and backend IIS. If you troubleshoot Exchange OWA by searching for 401 responses or treating every 302 as a successful sign-in, you can easily chase the wrong layer. This part gives you a repeatable way to correlate W3SVC1, HttpProxy, and W3SVC2 so the same request shows where it actually failed. Part 1: How OWA Authentication Really WorksPart 2: Forms-Based and Basic Authentication – What Really Changes?Part 3: Frontend vs Backend Authentication – Controlled A/B TestsPart…
Read More
Exchange Server SE / 2019 OWA Authentication Deep Dive – Part 3: Frontend vs Backend Authentication – Controlled A/B Tests

Exchange Server SE / 2019 OWA Authentication Deep Dive – Part 3: Frontend vs Backend Authentication – Controlled A/B Tests

Exchange
Applies to: Exchange Server SE / 2019 / 2016 Summary: In Part 2, we changed the frontend authentication methods and watched the browser behavior change with them. In this part, the frontend stays on the normal FBA configuration while we change only the backend OWA authentication settings. The goal is to separate “the user authenticated at the frontend” from “the request reached the backend successfully.” A user can enter valid credentials and still be returned to the Exchange OWA logon page because the failure happened after frontend authentication. This part shows how to prove where the failure occurs instead of assuming the password or the frontend authentication method is the problem. Part 1: How OWA Authentication Really WorksPart 2: Forms-Based and Basic Authentication – What Really Changes?Part 3: Frontend vs…
Read More
Exchange Server SE / 2019 OWA Authentication Deep Dive – Part 2: Forms-Based and Basic Authentication – What Really Changes?

Exchange Server SE / 2019 OWA Authentication Deep Dive – Part 2: Forms-Based and Basic Authentication – What Really Changes?

Exchange, Exchange Server SE / 2019 / 2016
Applies to: Exchange Server SE / 2019 / 2016 Summary: In Part 1, we mapped the OWA authentication layers and captured the default configuration. In this part, we change only the frontend OWA authentication settings and watch what happens in Exchange, IIS, and the browser. Changing one Exchange OWA authentication setting can completely change what IIS allows and what the browser shows. Understanding those differences makes it much easier to tell a real authentication failure from an expected 401 challenge, a Basic prompt, or the normal Exchange OWA sign-in flow. Part 1: How OWA Authentication Really WorksPart 2: Forms-Based and Basic Authentication – What Really Changes? — you are herePart 3: Frontend vs Backend Authentication – Controlled A/B TestsPart 4: Troubleshooting OWA Authentication with IIS and HttpProxy LogsPart 5: Managed…
Read More
Exchange Server SE / 2019 OWA Authentication Deep Dive – Part 1: How OWA Authentication Really Works

Exchange Server SE / 2019 OWA Authentication Deep Dive – Part 1: How OWA Authentication Really Works

Exchange, Exchange Server SE / 2019 / 2016
Applies to: Exchange Server SE / 2019 / 2016 Summary: OWA authentication is easier to troubleshoot once the frontend, Exchange authentication layer, HttpProxy, and backend are treated as separate parts of the same request. This first part sets the baseline, shows the main commands, and explains which settings matter before we start changing anything. Exchange OWA authentication problems are easy to misdiagnose because the browser, frontend IIS, Exchange authentication layer, HttpProxy, and backend do not tell the same story. Before changing any setting, you need to know which layer actually owns the failure. Version scope: The controlled tests in this series were performed on Exchange Server 2019 CU15 and Exchange Server Subscription Edition (SE) RTM. Microsoft states that SE RTM is code-equivalent to Exchange 2019 CU15 apart from the license…
Read More
Get Exchange Server URLs and Authentication Settings with PowerShell

Get Exchange Server URLs and Authentication Settings with PowerShell

Exchange, Exchange Server SE / 2019 / 2016
Applies to: Exchange Server SE / 2019 / 2016 The original GetExchangeURLs.ps1 script was written by Paul Cunningham to provide a simple way to display Exchange Server Client Access URLs from a single PowerShell script. Ali Tajran later updated the script to version 1.10, adding the PowerShell virtual directory and reorganizing the output. I recently revisited the script and decided to continue the same approach rather than create a completely new one. The result is GetExchangeURLs-v2.ps1. Download GetExchangeURLs-v2.ps1 Download from GitHub  |  Direct Download from Here Questions and feedback are welcome in the comments below. For script issues or feature requests, please use GitHub Issues. Current version: 2.1 (September 14, 2026). See What Changed below for the version history. In This Article 1. What Changed 2. Get Exchange Server URLs…
Read More
Get-ExchangeCertificate Returns Blank with a Valid Auth Certificate

Get-ExchangeCertificate Returns Blank with a Valid Auth Certificate

Exchange, Exchange Server SE / 2019 / 2016
Applies to: Exchange Server 2019 CU15 While validating a fresh Exchange Server 2019 CU15 installation, I started capturing the default configuration before making any namespace, certificate, or authentication changes. One of the first checks was Get-ExchangeCertificate. Unexpectedly, the cmdlet returned only the column headers and no certificate objects, even though the Exchange Admin Center showed the certificates normally. PowerShellGet-ExchangeCertificateGet-ExchangeCertificate Thumbprint Services Subject ---------- -------- ------- At first, this looked like the known Exchange Auth Certificate issue associated with PowerShell Serialization Payload Signing. However, the Auth Certificate was present, valid, correctly configured, and Microsoft's validation script reported no problem. What initially looked like a certificate problem eventually turned out to be related to the timing of certificate activation and HMAC key selection. In This Article 1. Certificates Were Present and the…
Read More
Troubleshooting Microsoft Entra Pass-through Authentication in Multi-Forest Environments

Troubleshooting Microsoft Entra Pass-through Authentication in Multi-Forest Environments

Hybrid Identity, Identity, Microsoft Entra ID
Applies to: Microsoft Entra ID | Microsoft Entra Connect Pass-through Authentication | Multi-Forest Active Directory Microsoft Entra Pass-through Authentication (PTA) allows users to sign in to Microsoft Entra ID using passwords that are validated directly against on-premises Active Directory. In a single Active Directory forest, this password validation path is usually straightforward. In a multi-forest environment, however, the PTA agent may need to validate users located in another forest through an Active Directory forest trust. In this scenario, the PTA agent itself can be healthy and successfully validate users in one forest, while Microsoft Entra sign-ins for users in another forest fail through the same agent. In this article, we will look at how Forest Trust and Name Suffix Routing can affect cross-forest password validation with Microsoft Entra Pass-through Authentication.…
Read More
Handling External Disclaimer Exceptions for Trusted Application Relays in Exchange Hybrid

Handling External Disclaimer Exceptions for Trusted Application Relays in Exchange Hybrid

Exchange, Exchange Online, Exchange Server SE / 2019 / 2016, Hybrid, Security & Hardening
Applies to: Exchange Server SE / 2019 / 2016 | Exchange Online | Hybrid In Exchange Hybrid environments, it is common to use mail flow rules to add an external disclaimer or warning banner to messages received from outside the organization. A typical warning may look like this: WARNING: This email originated from outside the organization. Do not click links or open attachments unless you recognize the sender. This is a good security control. It helps users identify messages that came from external sources. However, there are some scenarios where messages generated by internal application servers may also receive this external disclaimer. This usually happens when an internal application server submits email anonymously to Exchange Server on-premises, and Exchange then routes the message to Exchange Online. In this article, we…
Read More