Exchange 2016: How to exclude Exchange Server themselves from ADFS authentication on OWA and ECP

Joachim 26 Reputation points
2021-03-03T14:11:22.61+00:00

We successfully enabled ADFS authentication for OWA and ECP.
While this is what we want for the clients, we now have the problem that the local ECP of any exchange server cant be authenticated anymore: https://localhost/ecp/?ExchClientVer=15 or https://servername/ecp/?ExchClientVer=15

This leads to an ADFS error page because the cert is not valid.

We have to fall back to https://owa.ist.ac.at/ecp/?ExchClientVer=15

The problem with this is, for some tasks i need to know on which server I work. For instance to check if our OWA theme still works after a server upgrade.

So i need to make https://localhost/ecp/?ExchClientVer=15 work again locally on the servers. How I can exclude these servers or the admin users from ADFS authentication? I can apply the authentication in ADFS to groups, but now they are applied to everyone and I would love if I dont have to mess with the groups but somehow could just exclude the servers in a way that does not affect the whole infrastructure.

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,340 questions
0 comments No comments
{count} votes

Accepted answer
  1. Xzsssss 8,861 Reputation points Microsoft Vendor
    2021-03-04T07:39:26.48+00:00

    Hi @Joachim ,

    As Andy said, if you enabled ADFS auth for OWA/ECP, the basics and form auth are disabled, so you can't log in with your logon name and password.
    I think you can disable this then re-enable the basic/form auth, or you may have to fix the certificate problems.

    Regards,
    Lou


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


1 additional answer

Sort by: Most helpful
  1. Andy David - MVP 141.2K Reputation points MVP
    2021-03-03T14:31:23.163+00:00

    There is no way to do that unless you disable ADFS auth on the virtual dirs of those servers.

    Alternatively, set the local hosts file on your workstation for owa.ist.ac.at to a specific server's IP Address and connect that way when you want to verify things.

    0 comments No comments