- You deploy Microsoft Exchange Server 2010 in multiple Active Directory Domain Services (AD DS) sites.
- AD DS Site A is Internet-facing.
- AD DS Site B is not Internet-facing.
- Microsoft Outlook Web App (OWA) is published in Site A.
- Windows Integrated Authentication is enabled on the Client Access server (CAS) in Site B.
- A user in Site B tries to log on to OWA.
Source: MSExchange OWA
Event ID: 41
Task Category: Proxy
Level: Error
Description:
The Client Access server "https://mail.contoso.com/owa" attempted to proxy Outlook Web App traffic for mailbox <UserDN>. This failed because no Client Access server with an Outlook Web App virtual directory configured for Kerberos authentication could be found in the Active Directory site of the mailbox. The simplest way to configure an Outlook Web App virtual directory for Kerberos authentication is to set it to use Integrated Windows authentication by using the Set-OwaVirtualDirectory cmdlet in the Exchange Management Shell, or by using the Exchange Management Console. If you already have a Client Access server deployed in the target Active Directory site with an Outlook Web App virtual directory configured for Kerberos authentication, the proxying Client Access server may not be finding that target Client Access server because it does not have an internalUrl parameter configured. You can configure the internalUrl parameter for the Outlook Web App virtual directory on the Client Access server in the target Active Directory site by using the Set-OwaVirtualDirectory cmdlet.