Jump to content

Recommended Posts

Posted

There is currently a known problem where Outlook prompts for login credentials each time when loading for Staffmail accounts. Normally these credentials are saved, and you only have to put in your password if it's been changed.

 

Atomwide service desk have acknowledged this is a problem for Staffmail, but their registry fix doesn't work for us.

 

HKEY_CURRENT_USER\Software \Microsoft\Office\16.0\Outlook\AutoDiscoverHere you should create a new DWORD parameter labelled ExcludeExplicitO365EndpointThe value of this should be set to 1

 

Reading around the subject, this fix is for versions 16.0.6xxx and above, ie, the O365 channel - https://docs.microsoft.com/en-us/outlook/troubleshoot/profiles-and-accounts/unexpected-autodiscover-behavior. We're using the standalone version though, which is currently at 16.0.5xxx.

 

Are any other LGfL schools suffering from this, and has anyone found a workable solution?

Posted
I have noticed the same problem as well. I have come across a GPO setting which can block AutoDis - not sure if this can do the trick instead of the Regedit...https://support.microsoft.com/en-us/topic/after-migration-to-office-365-outlook-doesn-t-connect-or-web-services-don-t-work-3d9df009-597b-5d75-460c-4b7c64c833a1
Posted

Hi Dave,

 

I had the same problem yesterday and again this morning for several users. LGFL gave me exactly the same registry suggestions which I have not implemented as yet.

I then received a call from a nominated contact who could not remember their password and after resetting it was able to logon via StaffMail\OWA but not using the Outlook desktop client. I called LGFL again only to be told that the two issues were related and that i should make the registry changes. We too are all on 16.0.5xxx as well.

I managed to fix the issue by creating a new outlook profile and closing it down as soon as outlook started loading, then going back into the original outlook profile and entering the password again. Only time will tell but the user does not seem to have got the login prompt again since.

Posted

As far as I can see, there does seem to be some confusion between Staffmail and Office 365, hence the ExcludeExplicitO365Endpoint registry change. We do have our email domain registered in O365, although we're not using it yet.

 

I think it's something in autodiscovery and/or the Outlook profile. Junking the Outlook profile and starting again looks to fix it, but I don't want to be doing that for every member of staff...

Posted
I have noticed the same problem as well. I have come across a GPO setting which can block AutoDis - not sure if this can do the trick instead of the Regedit...https://support.microsoft.com/en-us/topic/after-migration-to-office-365-outlook-doesn-t-connect-or-web-services-don-t-work-3d9df009-597b-5d75-460c-4b7c64c833a1

 

I've tried this one as well, ExcludeLastKnownGoodUrl doesn't seem to fix it for us.

Posted

Hi Guys,

 

I believe this issue can be overcome by updating to the latest Office 2016 ADMX files and using a GPO, the extracted .xlsx file shows on line 2269 that enabling the "Disable AutoDiscover " switch gives us the ability to "Exclude initial check to Office 365 Autodiscover URL" which is the same thing is making the the registry change on each device.

 

I have made this change on a GPO which applies to my user account and will report back tomorrow along with some screenshots if it is successful.

Posted

I did not get the password prompt this morning when starting Outlook.

Some of my users who were also getting the prompt got it again this morning while others did not. I have rolled out the GPO to the entire estate so lets see how things progress after a couple of reboots.

Posted

I'm not LGFL but when we first moved to Office 2019, we had the same issues as you're reporting.

 

After much faffing, the two keys below were the combination we required:

 

Windows Registry Editor Version 5.00

 

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Setup]

"DisableOffice365SimplifiedAccountCreation"=dword:00000001

 

[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\AutoDiscover]

"ExcludeExplicitO365Endpoint"=dword:00000001

Note the breaking space half way through Outlook if displayed on this forum.

Posted

I haven't had much luck with the "Disable AutoDiscover" GPO settings. I updated my ADMX files this morning to get all the new settings, and I've tried several of them, to no avail.

 

BUT, I did get a Windows Update for Outlook in the background, KB5001980. After installing and rebooting, my test machine stopped asking for login in Outlook.

 

Bit muddied by the fact that I was playing with GPO settings at the same time, but, I think this update might be the fix.

  • Thanks 1
Posted

Let me know if you see overall success and we can suggest it also.

 

We have had a very recent influx of cases, starting maybe late last week but certainly a big chunk this week. Our end hasn't changed so it looks like updates on clients or similar... so keen to get to the bottom of it!

Posted

I think you are potentially solving the wrong problem, especially if your mailboxes are On O365.

 

newish versions of outlook2016 will potentially ignore autodiscover and reach out to O365 and say 'hey got a mailbox for this user'. This is actually sometime a real get-out-of-jail feature that you're turning off.

 

What I think is happening is

 

IF outlook encounters a authentication prompt along the way from (say) a proxy server, that gets pushed to the end user and you'll see the auth prompt. Use fiddler through outlook and see what is triggering that 401 prompt.

Posted
I haven't had much luck with the "Disable AutoDiscover" GPO settings. I updated my ADMX files this morning to get all the new settings, and I've tried several of them, to no avail.

 

BUT, I did get a Windows Update for Outlook in the background, KB5001980. After installing and rebooting, my test machine stopped asking for login in Outlook.

 

Bit muddied by the fact that I was playing with GPO settings at the same time, but, I think this update might be the fix.

 

I've had another user here who was getting prompted for login each time, but after installing KB5001980 and rebooting earlier today, no longer has the issue.

 

So either something has changed Microsoft's end, or that patch is fixing it (for us anyway).

Posted
I think you are potentially solving the wrong problem, especially if your mailboxes are On O365.

 

newish versions of outlook2016 will potentially ignore autodiscover and reach out to O365 and say 'hey got a mailbox for this user'. This is actually sometime a real get-out-of-jail feature that you're turning off.

 

What I think is happening is

 

IF outlook encounters a authentication prompt along the way from (say) a proxy server, that gets pushed to the end user and you'll see the auth prompt. Use fiddler through outlook and see what is triggering that 401 prompt.

 

These schools are mainly on our hosted exchange and there are no proxies here, most if not all of our schools are proxy free for the most part. It's very widespread even affecting our home machines when testing for users.

Posted
These schools are mainly on our hosted exchange and there are no proxies here, most if not all of our schools are proxy free for the most part. It's very widespread even affecting our home machines when testing for users.

 

 

any chance the domain is registered to an O365 tenant? conditional access? new website for the domain? the geek in me would want to see what's triggering the 401 auth required

 

Probably not the root cause, but it reminds me of a large financial institution where they unwittingly created a mailbox in o365 for all their users despite being 100% on prem

Posted
any chance the domain is registered to an O365 tenant? conditional access? new website for the domain? the geek in me would want to see what's triggering the 401 auth required

 

Probably not the root cause, but it reminds me of a large financial institution where they unwittingly created a mailbox in o365 for all their users despite being 100% on prem

 

In our case, yes, our email domain is also registered in O365, which may be where some of the confusion comes in.

Posted
I haven't had much luck with the "Disable AutoDiscover" GPO settings. I updated my ADMX files this morning to get all the new settings, and I've tried several of them, to no avail.

 

BUT, I did get a Windows Update for Outlook in the background, KB5001980. After installing and rebooting, my test machine stopped asking for login in Outlook.

 

Bit muddied by the fact that I was playing with GPO settings at the same time, but, I think this update might be the fix.

 

 

I also released KB5001980 & KB5001971 yesterday and since then no issues reported - still keeping an eye on it and it's looking promising!

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...