Outlook 365 app error 1001 on RDS environment ( FSLogix)

Anonymous
2023-07-07T08:25:49+00:00

Hello,

We encounter an issue with M365 apps (Outlook, Work, Excel) on a specific environment ( Remote Desktop Service)

Sometime, when an user open his application (Outlook for instance) on a RDS, an authentification pop and ask for credentials. If the user enter his credentials, he encounter a 1001 error.

« We encountered an issue [1001] »

https://learn-attachment.microsoft.com/api/attachments/5a947921-955a-4688-ad93-acc305bf77c6?platform=QnA

We already try some step to resolve the issue that help in some case but not all the case, and not defintely for a same user ( Issue occur again) :

  • Clear folder C:\Users*yourusername*\AppData\Local\Microsoft\OneAuth and  C:\Users*yourusername*\AppData\Local\Microsoft\IdentityCache
  • Move the user from 1 TSE server to an other TSE)e
  • Clear FSlogix User profil ( The specific one link to FSLogix Office 365 Container technology )

The main issue is that the error can occur again few day laterfor the same user.

We also generate some log from M365 apps client during the signin process with this link to help : https://learn.microsoft.com/en-us/office/troubleshoot/diagnostic-logs/how-to-enable-office-365-proplus-uls-logging

In the log I find the reference to the 1001 error but the log is a bit complex to understand or analyse.

0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[MSAL:0004]\tERROR  \tErrorInternalImpl:134\tCreated an error: 58tm1, StatusInternal::Unexpected, InternalEvent::None, Error Code 2147942403, Context '(pii)'", "IsError": true}	

07/07/2023 09:04:21.440	OUTLOOK (0x8b30)	0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[OneAuth:Error:58tm1:db6d7d6e-a557-4465-a968-a874c5e456e5] (Code:1001) An unexpected error occurred.", "IsError": true}	

07/07/2023 09:04:21.440	OUTLOOK (0x8b30)	0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[OneAuth:Error:9vdpp:db6d7d6e-a557-4465-a968-a874c5e456e5] Unexpected error code: 1001", "IsError": true}	

Environment :

  • Microsoft FSLogix version : 2.9.7654.46150
  • Office version : version 2305 build 16501.20228
  • OS version : Windows Server 2019 Standard 1809 build 17763.4499
Outlook | Windows | Classic Outlook for Windows | For home

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

278 answers

Sort by: Newest
  1. Anonymous
    2025-02-21T07:10:50+00:00

    Anyone testet with new fslogix version? Does that solve this?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2025-02-05T13:09:52+00:00

    Holy moly!
    Thank you for the work and for sharing it with us.

    Acutally we have a similar situation but none of the steps you did could change the symptoms for us.

    Some steps were kind of different. I could run the scripts directly without any issues and also there were no files in the APPLocker.

    But anyway. Keep haveing issues with some old and all new AD Users (non FSLogix environment).

    Error Code 1067 and 5fcl8

    I really hope we can find a solution soon :(

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2025-01-20T14:28:43+00:00

    Hello Carlos,

    I tried this with some users.

    Result:

    • After logoff/logon on the same and/or different RDSH in the Collection no need to sign in again in Microsoft365 (Excel, Word, Outlook).
    • After some time authentication is still required and gave the error: Something went wrong. [4o6fs] Error Tag: 4o6fs Error Code: 2147942405

    And 2147942405 (Access denied) is explainable because their is only read-access to the folder ...\AC\TobekBroker\Accounts\

    Sadly this does not work in our situation.


    Summary of overall environment:

    Environment:

    • Collection of 4 Windows Server 2022 RDSH servers
    • UserProfileDisks
      • Exclude folders from storing in user profile disk
        • %LocalAppData%\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy
        • %LocalAppDat%Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy
        • %LocalAppData%\Microsoft\TokenBroker
        • %LocalAppData%\Microsoft\OneAuth
        • %LocalAppData%\Microsoft\IdentityCache
    • Register-items through GPO:
      • HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin
        • DWORD: BlockAADWorkplaceJoin Value: 1
        • DWORD: AutoWorkplaceJoin Value: 0
    • Microsoft 365 Build 2411 (18227.20222)

    The initial error was

    Something went wrong [1001]

    Error Tag: 48v35

    Error Code: 2147942402

    After applying regkey BlockAADWorkplaceJoin error 1001 turned into 48v35.

    Something went wrong [48v35]

    Error Tag: 48v35

    Error Code: 2147942402

    2147942402 = File Not Found

    The applied sollution for 48v35 was deleting

    • AppData\Local\Microsoft\OneAuth
    • AppData\Local\Microsoft\IdentityCache

    but would still have the result of signing in every time in Microsoft 365 (Word, Excel, Outlook) after logoff/logon on the same and different RDSH server within the collection using the same UserProfileDisk. And eventually give error 48v35 again shortly.


    In the situation a similair setup is still unresolved, what working setup dit you all end up with in production for the client for them to be acceptable?

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2025-01-16T13:49:41+00:00

    Hi

    First of all, I hope Carlo's reply will already help you out here.

    Not sure, but disabling the WAM component - which used to be a workaround in the past - is no longer supported. I think this was also mentioned by few others in this thread. At least we removed the keys from our environment and it appeared to be a part of the solution for us. The other part of course being the blockAADWorkplaceJoin and a small Citrix feature "ShellBridge" since we are dealing with Citrix CVAD instead of RDS.

    Good luck onwards!

    Grtz

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2025-01-16T08:54:14+00:00

    Good morning.

    Since I see you are as desperate as I am, and we have a similar configuration without fslogix, I'll give you what is working for me.

    Remove the user's write permissions to this folder, and once removed, you must add the user but with READ ONLY permissions. Do not delete the rest of the folder's permissions, from the rest of the users and accounts on the computer, only from the user of the account.

    c:\Users%username%\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\AC\TokenBroker\Accounts

    Only to the "Accounts" folder.

    Try it, it has removed almost 95% of the errors for me.

    Greetings.

    Was this answer helpful?

    0 comments No comments