Sign in with Microsoft
Sign in or create an account.
Select a different account.
You have multiple accounts
Choose the account you want to sign in with.


You try to access the Microsoft Outlook Web App (OWA) through Microsoft Forefront Unified Access Gateway 2010. If you are close to the idle session time-out period, you do not see the session time-out warning message. Instead, you receive the following error code 109 message:

You have attempted to access a restricted URL.

Additionally, you may receive the following error code 152 message:

You are not a member of an ADFS group.

Note This problem occurs only if you have an HTTP redirect trunk and if users access Forefront Unified Access Gateway by using this trunk instead of going direct to the HTTPS trunk.


This problem occurs because the SessionTimeout.asp file includes This include file contains code that retrieves session information by using your Unified Access Gateway session cookie. When these conditions are met, the code tries to use the HTTP session cookie instead of the HTTPS session cookie. Therefore, the required session information is not found.


This problem is fixed in Rollup 1 for Forefront Unified Access Gateway 2010 Service Pack 4.


Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.


Learn about the terminology that Microsoft uses to describe software updates.

Need more help?

Want more options?

Explore subscription benefits, browse training courses, learn how to secure your device, and more.

Communities help you ask and answer questions, give feedback, and hear from experts with rich knowledge.

Was this information helpful?

What affected your experience?
By pressing submit, your feedback will be used to improve Microsoft products and services. Your IT admin will be able to collect this data. Privacy Statement.

Thank you for your feedback!