Outlook 365 app error 1001 on RDS environment ( FSLogix)

Anonymous
2023-07-07T08:25:49+00:00

Hello,

We encounter an issue with M365 apps (Outlook, Work, Excel) on a specific environment ( Remote Desktop Service)

Sometime, when an user open his application (Outlook for instance) on a RDS, an authentification pop and ask for credentials. If the user enter his credentials, he encounter a 1001 error.

« We encountered an issue [1001] »

https://learn-attachment.microsoft.com/api/attachments/5a947921-955a-4688-ad93-acc305bf77c6?platform=QnA

We already try some step to resolve the issue that help in some case but not all the case, and not defintely for a same user ( Issue occur again) :

  • Clear folder C:\Users*yourusername*\AppData\Local\Microsoft\OneAuth and  C:\Users*yourusername*\AppData\Local\Microsoft\IdentityCache
  • Move the user from 1 TSE server to an other TSE)e
  • Clear FSlogix User profil ( The specific one link to FSLogix Office 365 Container technology )

The main issue is that the error can occur again few day laterfor the same user.

We also generate some log from M365 apps client during the signin process with this link to help : https://learn.microsoft.com/en-us/office/troubleshoot/diagnostic-logs/how-to-enable-office-365-proplus-uls-logging

In the log I find the reference to the 1001 error but the log is a bit complex to understand or analyse.

0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[MSAL:0004]\tERROR  \tErrorInternalImpl:134\tCreated an error: 58tm1, StatusInternal::Unexpected, InternalEvent::None, Error Code 2147942403, Context '(pii)'", "IsError": true}	

07/07/2023 09:04:21.440	OUTLOOK (0x8b30)	0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[OneAuth:Error:58tm1:db6d7d6e-a557-4465-a968-a874c5e456e5] (Code:1001) An unexpected error occurred.", "IsError": true}	

07/07/2023 09:04:21.440	OUTLOOK (0x8b30)	0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[OneAuth:Error:9vdpp:db6d7d6e-a557-4465-a968-a874c5e456e5] Unexpected error code: 1001", "IsError": true}	

Environment :

  • Microsoft FSLogix version : 2.9.7654.46150
  • Office version : version 2305 build 16501.20228
  • OS version : Windows Server 2019 Standard 1809 build 17763.4499
Outlook | Windows | Classic Outlook for Windows | For home

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

278 answers

Sort by: Newest
  1. Anonymous
    2024-01-23T13:05:21+00:00

    @JMSA85 Can I just confirm that you're simply just running the WPJCleanUp script on every logon per users. Is that how you've set this up?

    We have this issue on a number of RDP solutions and would love to finally solve it.

    Just as a heads-up, WPJCleanUp has done wonders so far, did not encounter other 1001 issue after running it in users sessions.

    @WhoaDukeOfAwesome, I did not create a script yet, I started by letting a shortcut on the desktop pointing to the exec and instructed our users to run it if any 1001 issues. I was just being safe, as that could be quickly removed if that created any other side issue.

    Now, I would deploy it at a larger scale by simple running the executable in user context, at logon, and only a single time as it doesn't need to be run at every login if BlockWorkplaceJoin registry has been properly set up.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-01-23T06:13:09+00:00

    I easily see it used as an automated script at user logon, running once. The only thing it doesn't do it deleting computer object in Entra, so there will be it will need to be done by scripting or manually to get rid of those stale entries.

    Sources:
    Reset activation state for Microsoft 365 Apps for enterprise - Microsoft 365 Apps | Microsoft Learn https://download.microsoft.com/download/8/e/f/8ef13ae0-6aa8-48a2-8697-5b1711134730/WPJCleanUp.zip
    Error “Something Went Wrong [1001]” signing in to Microsoft 365 Desktop Applications - Microsoft Support
    Identité d’appareil et virtualisation de bureau - Microsoft Entra ID | Microsoft Learn

    @JMSA85 Can I just confirm that you're simply just running the WPJCleanUp script on every logon per users. Is that how you've set this up?

    We have this issue on a number of RDP solutions and would love to finally solve it.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2024-01-18T17:39:00+00:00

    So far, in our situation, the root-cause seems related to the fact the user had Workplace-Joined their sessions when configuring Office because we aren't fully hybrid-join. And that action also created a computer object in Entra with the user as the owner for the SSO. That doesn't seem to be an issue when the session is persistent, but long-story-short, Workplace Join is unsupported in a non-persistent session (as per Microsoft updated documentation).

    The BlockWorkplaceJoin registry key did help by not creating more 1001 issues. But did nothing for those who previously had done it. Manually deleting those folders alone, we see with "dsregcmd.exe /status" that the user state still is WorkplaceJoined. So, it's not enough to correct a profile and the error will come back.

    • C:\Users%username%\AppData\Local\Microsoft\OneAuth\
    • C:\Users%username%\AppData\Local\Microsoft\IdentityCache\

    By recreating the Fslogix profile and Blocking Workplace join, we do eliminate this and the issue is yet to occurs again for us. But we had some implication about recreating that for all of our user.

    Microsoft has a tool to clear the Workplace-Join accounts when it's unavailable in the Settings, Accounts section (like in our case). So far it's working very well for us as we don't need to recreate the profile, and it's get rid of the user state.

    I easily see it used as an automated script at user logon, running once. The only thing it doesn't do it deleting computer object in Entra, so there will be it will need to be done by scripting or manually to get rid of those stale entries.

    Sources:
    Reset activation state for Microsoft 365 Apps for enterprise - Microsoft 365 Apps | Microsoft Learn https://download.microsoft.com/download/8/e/f/8ef13ae0-6aa8-48a2-8697-5b1711134730/WPJCleanUp.zip
    Error “Something Went Wrong [1001]” signing in to Microsoft 365 Desktop Applications - Microsoft Support
    Identité d’appareil et virtualisation de bureau - Microsoft Entra ID | Microsoft Learn

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  4. Anonymous
    2024-01-10T11:15:18+00:00

    This was my solution:

    Create the following regkey on all RDS session hosts:

    HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin

    DWORD: BlockAADWorkplaceJoin Value: 1

    Remove the FSLogix profile for the users and recreated the FSLogix profile.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2024-01-09T15:58:26+00:00

    I tried all of the below but non of these resolved the issue

    • Initial Workaround: Deleted two JSON files from the Outlook Appdata user folder, followed by signing out and back in from:
      • C:\Users%username%\AppData\Local\Microsoft\Outlook\16\
      • *** Email address is removed for privacy ***
      • *** Email address is removed for privacy ***
    • Secondary Step: When the initial workaround was inconsistent, we removed the same JSON files along with the 'OneAuth' and 'IdentityCache' folders, then repeated the sign-out/in the process:
      • C:\Users%username%\AppData\Local\Microsoft\OneAuth\
      • C:\Users%username%\AppData\Local\Microsoft\IdentityCache\
    • Further Measures: If the previous actions failed, as extensively discussed in this thread, we signed the user out, deleted the 'Microsoft.AAD.BrokerPlugin' folder from the User Profile Disk, and then reconnected to the RDS.
    • Last Resort: Attempted to recreate the user session.

    I then added the below regkeys and removed any entries within Microsoft Entra dating back before 2020 and the issue was resolved

    We are now investigating a solution that involves blocking the 'WorkplaceJoined' option by adding the following registry keys:

    • HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin
      • DWORD: BlockAADWorkplaceJoin Value: 1
    • HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin
      • DWORD: AutoWorkplaceJoin Value: 0

    This was on 2 x RDS servers, no reboot was required. This fixed it for all users after around 30 minutes of adding the rekeys

    Was this answer helpful?

    0 comments No comments