Outlook 365 app error 1001 on RDS environment ( FSLogix)

Anonymous
2023-07-07T08:25:49+00:00

Hello,

We encounter an issue with M365 apps (Outlook, Work, Excel) on a specific environment ( Remote Desktop Service)

Sometime, when an user open his application (Outlook for instance) on a RDS, an authentification pop and ask for credentials. If the user enter his credentials, he encounter a 1001 error.

« We encountered an issue [1001] »

https://learn-attachment.microsoft.com/api/attachments/5a947921-955a-4688-ad93-acc305bf77c6?platform=QnA

We already try some step to resolve the issue that help in some case but not all the case, and not defintely for a same user ( Issue occur again) :

  • Clear folder C:\Users*yourusername*\AppData\Local\Microsoft\OneAuth and  C:\Users*yourusername*\AppData\Local\Microsoft\IdentityCache
  • Move the user from 1 TSE server to an other TSE)e
  • Clear FSlogix User profil ( The specific one link to FSLogix Office 365 Container technology )

The main issue is that the error can occur again few day laterfor the same user.

We also generate some log from M365 apps client during the signin process with this link to help : https://learn.microsoft.com/en-us/office/troubleshoot/diagnostic-logs/how-to-enable-office-365-proplus-uls-logging

In the log I find the reference to the 1001 error but the log is a bit complex to understand or analyse.

0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[MSAL:0004]\tERROR  \tErrorInternalImpl:134\tCreated an error: 58tm1, StatusInternal::Unexpected, InternalEvent::None, Error Code 2147942403, Context '(pii)'", "IsError": true}	

07/07/2023 09:04:21.440	OUTLOOK (0x8b30)	0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[OneAuth:Error:58tm1:db6d7d6e-a557-4465-a968-a874c5e456e5] (Code:1001) An unexpected error occurred.", "IsError": true}	

07/07/2023 09:04:21.440	OUTLOOK (0x8b30)	0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[OneAuth:Error:9vdpp:db6d7d6e-a557-4465-a968-a874c5e456e5] Unexpected error code: 1001", "IsError": true}	

Environment :

  • Microsoft FSLogix version : 2.9.7654.46150
  • Office version : version 2305 build 16501.20228
  • OS version : Windows Server 2019 Standard 1809 build 17763.4499
Outlook | Windows | Classic Outlook for Windows | For home

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

278 answers

Sort by: Oldest
  1. Anonymous
    2023-11-08T13:22:56+00:00

    We have been running this command along with 2 others for a year now to clear out all the firewall rules. We still unfortunately have the problem of 1001. We have 4 RDS Servers running 2019. Not running FSLogix.

    Here are the other 2 commands.

    reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules /va /f

    reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\Configurable\System /va /f

    Hi,

    Possible solution?

    We hade the same problem in one of our customers environment. We are running two RDS-host on Windows Server 2019 using User Profile Disks.

    Our solution was running the following command "reg delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\RestrictedServices\AppIso\FirewallRules /va /f"

    This reg-key contained around 30.000 firewall rules which caused the regedit to hang when browsing. Running the command took about 15min for us. After that Outlook worked like a charm for all users. This also fixed the problem with our start menu not working as well as speeding up reboot and login times.

    Managed to extract the regkeys and it contained 15K of fw-rules for "Microsoft.AAD.BrokerPlugin_1000.17763.1.0" so it might been this that caused our 1001-error.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2023-11-08T13:36:27+00:00

    Same as Anthony Manniello above we also have to run the same commands to clear out the build up of firewall rules. Been doing it every 3/4 months since we got our RDS servers. I think it's a known issue/bug with RDS.

    From our perspective it doesn't have any relation to the 1001 Outlook errors.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-11-08T13:42:08+00:00

    On our end with 4 AVD session hosts we turned off RoamIdentity setting for FSlogix. This seems to have the opposite effect in our environment, with it turned off we haven't heard a peep from any user having to re authenticate their primary or secondary exchange account when switching between session hosts. Going on two weeks now with no issues as it was at minimum issues every other day.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2023-11-08T13:52:41+00:00

    Guys why so complicated just follow my Post 4.October Just downgrade Office and setup the GPO for FSLogix and Office365 new that's it for the moment, we did this change on our server farm no issue or 1001 Error, i know its not so cool to downgrade the Office but seems the only working solution for the moment.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  5. Anonymous
    2023-11-08T15:19:34+00:00

    I haven't posted on this for a few weeks now and wanted to give a quick update. Unfortunately, this is likely not going to help many but our client was so frustrated with the situation, we had to do something drastic and migrate everyone off of FSLogix and back onto roaming profiles. Combined with all our other implemented fixes and moving to roaming profiles, the issue is gone.

    However, part of me feels we put in an adequate workaround beforehand, but it was one of those situations where the client was fed up with testing and wouldn't let us continue. From what I saw, I think we did figure it out, but it was too late. I wish I had more details / testing under my belt, but here's the list of things we did.

    1. Computer GPO to deploy reg key to block AAD Workplace Join

    HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin; BlockAADWorkplaceJoin DWORD = 1

    HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin; AutoWorkplaceJoin DWORD = 0

    1. Microsoft 365 Apps for Business EN-US (x86) = 16.0.16827.20166
    2. FSLogix version BEFORE uninstalling = 2.9.8612.60056
    3. Computer GPO to block and hide Office updates

    Computer Configuration\Policies\Administrative Templates\Microsoft Office 2016\Updates

    Enable automatic updates = Disabled

    Hide option to enable or disable updates = Enabled

    Hide update notifications = Enabled

    1. User and Computer GPO to deploy reg key to alter the behavior for a federated user account so that the password is saved in Credential Manager (not sure if this did much honestly, but it was a live policy we added somewhere along the way).

    Computer + User Configuration\Preferences\Windows Settings\Registry

    HKCU\Software\Microsoft\Office\16.0\Common\Identity; NoDomainUser = 1

    1. FSLogix RoamIdentity = Enabled
    2. Users that were problematic before we made the above change, we scripted the removal of the following folders at next login until they were all purged. Once these were removed, the next login, 1001s were gone.

    C:\users$user\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy

    C:\users$user\AppData\Local\Microsoft\IdentityCache

    C:\users$user\AppData\Local\OneAuth

    A few other notes... with all the above changes we made, during our troubleshooting, we DID downgrade Office and FSLogix to a version another one of our clients was using with no issues, and it still didn't fix things. In regards to downgrading Office, it actually made things worse because instead of being prompted to log in every single time they open Office, it wouldn't prompt at all, but it would also consider their login not working, so users were completely locked out when we did this. I don't recall the versions without digging through months of tickets and emails. We also tried Office 2019 and it also did not work.

    Hope this helps. I'm moving on from this issue, it's been close to 6 weeks of pain, stress, and frustration, and I don't have it in me anymore to think about this. GG Microsoft. Thanks everyone who helped along the way.

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments