Symptoms

Users can’t use Outlook on the web (OWA), Exchange Control Panel (ECP), or the Exchange admin center (EAC) for a long time after an authentication certificate is published for servers that are set to the UTC time zone or any UTC+<#> time zone.

The new authentication certificate remains invalid for the specific UTC+ hours that are configured on the server. For example, If server time zone is UTC+8, the certificate remains invalid for 8 hours.

Resolution

To fix this issue, install the following updates, as appropriate:

Cumulative Update 12 for Exchange Server 2019 or a later cumulative update for Exchange Server 2019

Cumulative Update 23 for Exchange Server 2016 or a later cumulative update for Exchange Server 2016

Need more help?

Expand your skills
Explore Training
Get new features first
Join Microsoft Insiders

Was this information helpful?

What affected your experience?

Thank you for your feedback!

×