Outlook 365 app error 1001 on RDS environment ( FSLogix)

Anonymous
2023-07-07T08:25:49+00:00

Hello,

We encounter an issue with M365 apps (Outlook, Work, Excel) on a specific environment ( Remote Desktop Service)

Sometime, when an user open his application (Outlook for instance) on a RDS, an authentification pop and ask for credentials. If the user enter his credentials, he encounter a 1001 error.

« We encountered an issue [1001] »

https://learn-attachment.microsoft.com/api/attachments/5a947921-955a-4688-ad93-acc305bf77c6?platform=QnA

We already try some step to resolve the issue that help in some case but not all the case, and not defintely for a same user ( Issue occur again) :

  • Clear folder C:\Users*yourusername*\AppData\Local\Microsoft\OneAuth and  C:\Users*yourusername*\AppData\Local\Microsoft\IdentityCache
  • Move the user from 1 TSE server to an other TSE)e
  • Clear FSlogix User profil ( The specific one link to FSLogix Office 365 Container technology )

The main issue is that the error can occur again few day laterfor the same user.

We also generate some log from M365 apps client during the signin process with this link to help : https://learn.microsoft.com/en-us/office/troubleshoot/diagnostic-logs/how-to-enable-office-365-proplus-uls-logging

In the log I find the reference to the 1001 error but the log is a bit complex to understand or analyse.

0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[MSAL:0004]\tERROR  \tErrorInternalImpl:134\tCreated an error: 58tm1, StatusInternal::Unexpected, InternalEvent::None, Error Code 2147942403, Context '(pii)'", "IsError": true}	

07/07/2023 09:04:21.440	OUTLOOK (0x8b30)	0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[OneAuth:Error:58tm1:db6d7d6e-a557-4465-a968-a874c5e456e5] (Code:1001) An unexpected error occurred.", "IsError": true}	

07/07/2023 09:04:21.440	OUTLOOK (0x8b30)	0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[OneAuth:Error:9vdpp:db6d7d6e-a557-4465-a968-a874c5e456e5] Unexpected error code: 1001", "IsError": true}	

Environment :

  • Microsoft FSLogix version : 2.9.7654.46150
  • Office version : version 2305 build 16501.20228
  • OS version : Windows Server 2019 Standard 1809 build 17763.4499
Outlook | Windows | Classic Outlook for Windows | For home

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

278 answers

Sort by: Most helpful
  1. Anonymous
    2025-01-16T08:54:14+00:00

    Good morning.

    Since I see you are as desperate as I am, and we have a similar configuration without fslogix, I'll give you what is working for me.

    Remove the user's write permissions to this folder, and once removed, you must add the user but with READ ONLY permissions. Do not delete the rest of the folder's permissions, from the rest of the users and accounts on the computer, only from the user of the account.

    c:\Users%username%\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC\TokenBroker\Accounts

    Only to the "Accounts" folder.

    Try it, it has removed almost 95% of the errors for me.

    Greetings.

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2025-01-15T22:25:55+00:00

    Hello folks,

    First things first, thanks to all for providing valuable information in this topic !

    After reading these 27 pages probably two or three times, scratching my head days and nights, reinstalling, regediting, praying, ... I decided to post here.

    So, sorry about that but I don't have THE answer.

    To sum up, here is our setup :

    • AD on premise
    • 3 brand new RDS Windows Server 2022 / 1 RDCB
    • 120 users
    • UPD (VHDX), no Fslogix
    • New Teams (Yes I know, why making it simple)
    • All profiles reconfigured with shared mailboxes to get something clean. (users have only one Microsoft credential)
    • Last version of Microsoft Office (shared activation)

    and guess what ... I can't get this ****%$# thing work normally -_-

    Without customizing anything :

    >> 1001 errors (very random, but many users concerned, probably all)

    Adding exclusion in UPD profile as Microsoft says authentication roaming isn't supported :

    • AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
    • AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
    • AppData\Local\Microsoft\TokenBroker

    >> No more 1001 errors but users need to reauthenticate on almost every logon

    I try disabling WAM and Workplace join with these keys but I don't get anything better (does these keys even work with last Office version ?) :

    • HKCU\Software\Microsoft\Office\16.0\Common\Identity\DisableAADWAM = 1
    • HKCU\Software\Microsoft\Office\16.0\Common\Identity\DisableADALatopWAMOverride = 1

    and the Workplace thing :

    • HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin\BlockAADWorkplaceJoin = 1
    • HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin\AutoWorkplaceJoin = 1

    Last thing we try : downgrading Office to 16.0.15601.20538 (before WAM auth)

    I'll keep you informed ...

    And wanna get more :

    • Emails in Outbox sometimes stay stuck, users can recieve new emails but need to restart Outlook to empty the outbox directory
    • New Teams Outlook Addin which is a nightmare to install in RDS environnement (ALLUSERS=1), but each Teams update break the all thing

    I'm so pissed off at Microsoft, this architecture looks so familliar, I don't understand how is it possible to be in this situation since years.

    Is even this setup supported ? (probably not ...)

    Next try we'll be moving to Fslogix profiles but as I read in this topic it seems that some of you always get errors.

    Does someone here get a fully working RDS 2019/2022 (2 or more RDS servers, so with roaming profile involved) solution with last Office version ? If yes, can you quickly describe your setup ?

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2025-01-14T14:43:08+00:00

    Hello Grzegorz,

    Thank you for the summary of all actions and situations with diffrent clients.

    Can you confirm that your final conclusion is actually summarized as follows?

    Install new RDSH servers with an updated ISO and the latest Microsoft365 Apps Build and create a new Collection with these new RDSH servers?

    All with register keys applied, ofcourse:

    [HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin]

    "BlockAADWorkplaceJoin"=dword:00000001

    [HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin]

    "autoWorkplaceJoin"=dword:00000000"

    According to your text:

    "3. First Client

    In the end, there was no other way than to rebuild the RDS host from scratch and build a new collection based on it
    After 6 months, the solution seems to be stable

    4. Second client affected

    I applied the newest updates to the OS and O365, but the issue persisted.

    Eventually, I had to build a new RDS from scratch the same way I did with the First affected Client."

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2025-01-07T18:10:30+00:00

    Again, wondering if anyone on Server 2025 have experienced these authentication issues that plague 2019 and 2022.

    Thanks

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2024-12-13T17:02:23+00:00

    Has anyone experienced these issues with Server 2025? I'm going to be migrating my RDS farm to 2025 before October of next year since 365 apps will no longer be supported on 2019.

    Was this answer helpful?

    0 comments No comments