Authentication for federated users is slow or fails for Office 365 rich clients that use the AD FS 2.0 WS-Metadata Exchange (MEX) endpoint

Article ID: 2461794 - View products that this article applies to.

Not sure what release of Office 365 you're using? Go to the following Microsoft website:
Am I using Office 365 after the service upgrade?
Expand all | Collapse all

PROBLEM

Authentication of single sign-on (SSO)-enabled users is slow and may eventually fail when users use Microsoft Office 365 rich client applications that connect to the Active Directory Federation Services (AD FS) 2.0 WS-Metadata Exchange (MEX) endpoint. This issue affects the following rich client applications when these applications are used to connect to Office 365 resources:
  • Microsoft Lync 2010
  • Microsoft Office Professional Plus
  • Windows Azure Active Directory Module for Windows PowerShell
  • Microsoft Dynamics CRM Online for Outlook add-in
When this issue occurs, SSO-enabled user authentication works as expected through other client applications (such as Microsoft Outlook or Internet browsers) that connect to Office 365 resources.

CAUSE

The issue may occur as the result of a memory leak that's associated with the /adfs/services/trust/mex Internet Information Services (IIS) endpoint. This endpoint is associated with AD FS 2.0. Rich client applications use this endpoint to determine whether the client computer is connecting to an AD FS 2.0 proxy service from the Internet or to the AD FS 2.0 Federation service from inside the on-premises corporate network.

When this problem occurs, and you direct a web browser to the MEX endpoint, the webpage returns the following error message:
500 Internal Server Error

SOLUTION

To resolve this issue, install the update that's described in the following Microsoft Knowledge Base article:
2607496 Description of Update Rollup 1 for Active Directory Federation Services (AD FS) 2.0

MORE INFORMATION

Still need help? Go to the Office 365 Community website.

Properties

Article ID: 2461794 - Last Review: May 15, 2013 - Revision: 12.0
Applies to
  • Microsoft Office 365 for enterprises (pre-upgrade)
  • Microsoft Office 365 for education  (pre-upgrade)
  • Windows Azure Active Directory
Keywords: 
o365 o365a o365e o365022013 after upgrade o365062011 pre-upgrade o365m KB2461794

Give Feedback