Article ID: 981541 - View products that this article applies to.
When you connect to Outlook Web App on a Microsoft Exchange Server 2010 Client Access Server (CAS), and you try to access a Microsoft Exchange Server 2007 mailbox, you are prompted two times for authentication.
The first prompt is the Forms-based authentication (FBA) page for the Exchange Server 2010 CAS. The second prompt is for the Microsoft Exchange Server 2007 CAS page.
Note When FBA is not used, a silent proxy to the Exchange Server 2007 CAS is not available.
This issue occurs when an authentication method other than FBA is set for the ExternalAuthenticationMethods parameter for Outlook Web App on the Exchange 2007 CAS.
To provide a silently proxy request for an Exchange 2007 mailbox when you connect through an Exchange Server 2010 CAS, FBA must be enabled for the /owa virtual directory on the Exchange Server 2007 CAS. This process is known as single sign-on (SSO).
Note The FormsAuthentication parameter for the /owa virtual directory must also be set to $true. This $true value reflects the setting in the Exchange Management Console user interface.
To change the ExternalAuthenticationMethods parameter on the Exchange Server 2007 CAS server to use FBA, follow these steps:
To verify the ExternalAuthenticationMethods parameter, run the following cmdlet from the Exchange Management Shell:
Get-owaVirtualDirectory "owa (default Web site)" | fl name, externalauthentication*The resulting output resembles the following:
Article ID: 981541 - Last Review: March 18, 2010 - Revision: 1.0