Outlook 365 app error 1001 on RDS environment ( FSLogix)

Anonymous
2023-07-07T08:25:49+00:00

Hello,

We encounter an issue with M365 apps (Outlook, Work, Excel) on a specific environment ( Remote Desktop Service)

Sometime, when an user open his application (Outlook for instance) on a RDS, an authentification pop and ask for credentials. If the user enter his credentials, he encounter a 1001 error.

« We encountered an issue [1001] »

https://learn-attachment.microsoft.com/api/attachments/5a947921-955a-4688-ad93-acc305bf77c6?platform=QnA

We already try some step to resolve the issue that help in some case but not all the case, and not defintely for a same user ( Issue occur again) :

  • Clear folder C:\Users*yourusername*\AppData\Local\Microsoft\OneAuth and  C:\Users*yourusername*\AppData\Local\Microsoft\IdentityCache
  • Move the user from 1 TSE server to an other TSE)e
  • Clear FSlogix User profil ( The specific one link to FSLogix Office 365 Container technology )

The main issue is that the error can occur again few day laterfor the same user.

We also generate some log from M365 apps client during the signin process with this link to help : https://learn.microsoft.com/en-us/office/troubleshoot/diagnostic-logs/how-to-enable-office-365-proplus-uls-logging

In the log I find the reference to the 1001 error but the log is a bit complex to understand or analyse.

0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[MSAL:0004]\tERROR  \tErrorInternalImpl:134\tCreated an error: 58tm1, StatusInternal::Unexpected, InternalEvent::None, Error Code 2147942403, Context '(pii)'", "IsError": true}	

07/07/2023 09:04:21.440	OUTLOOK (0x8b30)	0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[OneAuth:Error:58tm1:db6d7d6e-a557-4465-a968-a874c5e456e5] (Code:1001) An unexpected error occurred.", "IsError": true}	

07/07/2023 09:04:21.440	OUTLOOK (0x8b30)	0xa3e4	Microsoft Outlook	Identity Authentication Client	48cmb	Monitorable	OneAuth log {"Message": "[OneAuth:Error:9vdpp:db6d7d6e-a557-4465-a968-a874c5e456e5] Unexpected error code: 1001", "IsError": true}	

Environment :

  • Microsoft FSLogix version : 2.9.7654.46150
  • Office version : version 2305 build 16501.20228
  • OS version : Windows Server 2019 Standard 1809 build 17763.4499
Outlook | Windows | Classic Outlook for Windows | For home

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

278 answers

Sort by: Oldest
  1. Anonymous
    2023-11-08T17:32:32+00:00

    Hello everyone,

    First of all, I would like to thank all the participants of this forum for the various workarounds and remedies attempted to resolve an issue that has persisted for several months now.

    On our side, we've been facing Office Error 1001 within our RDS environment, affecting numerous users across different collections. Unfortunately, the error remains despite our extensive efforts.

    Environment:

    • RDS farm using UPD
    • OS: Windows Server 2019 Datacenter (1809 build 17763.4974)
    • MS 365 Apps version: From 2302 to the latest release, 2310

    Here’s a detailed account of the actions we’ve taken:

    • Initial Workaround: Deleted two JSON files from the Outlook Appdata user folder, followed by signing out and back in from:
      • C:\Users%username%\AppData\Local\Microsoft\Outlook\16\
      • ******@domain.com.json
      • ******@domain.com.json
    • Secondary Step: When the initial workaround was inconsistent, we removed the same JSON files along with the 'OneAuth' and 'IdentityCache' folders, then repeated the sign-out/in the process:
      • C:\Users%username%\AppData\Local\Microsoft\OneAuth\
      • C:\Users%username%\AppData\Local\Microsoft\IdentityCache\
    • Further Measures: If the previous actions failed, as extensively discussed in this thread, we signed the user out, deleted the 'Microsoft.AAD.BrokerPlugin' folder from the User Profile Disk, and then reconnected to the RDS.
    • Last Resort: Attempted to recreate the user session.

    Despite these efforts, the issue persists. Additional measures that we tested but found unsuccessful include:

    • Deleting the ADAL registry key, which proved ineffective.
    • Removing Multi-Factor Authentication (MFA), which only slightly reduced the occurrence of the error.
    • Updating Office to the latest release, decreased the frequency of the error initially but did not resolve it.
    • Repairing Windows Account Manager (WAM) following Microsoft's recommendation, which had no effect.
    • Excluding the AAD.BrokerPlugin folder from Trend Micro's real-time search, Behavior Monitoring Approved list, and Trusted Program List.
    • Disabling antivirus software for a specific RDS Collection.

    We are now investigating a solution that involves blocking the 'WorkplaceJoined' option by adding the following registry keys:

    • HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin
      • DWORD: BlockAADWorkplaceJoin Value: 1
    • HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin
      • DWORD: AutoWorkplaceJoin Value: 0

    I will update here if this leads to any improvements. Thank you all for your help and feedback.

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2023-11-08T21:22:50+00:00

    Hi,

    Exactly same actions and workarounds applied here. The registry keys seem to work as workaround instead of renaming/deleting Microsoft.AAD.BrokerPlugin folder located in profile user disk. This fix was recently applied for new users at first logon, waiting to see if this could defintively resolve this issue related to WAM authentication...

    I'll posting my results soon !

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2023-11-08T21:59:10+00:00

    There's a registry key to prevent those firewall rules from accumulating:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy DeleteUserAppContainersOnLogoff (DWORD)Value: 1

    Was this answer helpful?

    2 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2023-11-08T22:01:04+00:00

    We are now investigating a solution that involves blocking the 'WorkplaceJoined' option by adding the following registry keys:

    • HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin
      • DWORD: BlockAADWorkplaceJoin Value: 1
    • HKLM\SOFTWARE\Policies\Microsoft\Windows\WorkplaceJoin
      • DWORD: AutoWorkplaceJoin Value: 0

    I have deployed those registry keys 2 months ago thinking it would help resolve the issue but it still persisted.

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2023-11-08T22:05:24+00:00

    Though it may work, the reason I didn't push this is for security and also to find a permanent fix. Appreciate the suggestion though!

    Was this answer helpful?

    0 comments No comments