OWA Exchange 2019 500 Internal Server Error

Kmcnet 1,421 Reputation points
2026-02-28T12:43:28.0966667+00:00

Hello everyone and thanks for the help in advance. I am running an onsite Exchange 2019 Server on Windows Server 2022. For no apparent reason, clients are now attempting to login and are receiving a 500 Internal Server Error at the login screen. I confirmed the Exchange Server is operational and can be accessed on the Exchange Server itself via Edge or Chrome. Database is intact and all mailboxes are accessible and can send and receive email. Additionally, there is a small test site running on IIS that is completely inaccessible, even on the local machine, also serving 500 error. Event logs show no errors of any type with one exception in the System log:

Could not retrieve an OCSP response.

   The Failure Reason is: REASON_OCSP_RESPONSE_RETRIEVAL_ERROR
    The OCSP Url is: http://ocsp.godaddy.com/
   The previous OCSP response contained the following times:
      ThisUpdate: ‎1601‎-‎01‎-‎01T00:00:00.000000000Z
      NextUpdate: ‎1601‎-‎01‎-‎01T00:00:00.000000000Z

The attached data contains the certificate.

I'm really not sure where to go from here. Any help would be appreciated.

Exchange | Exchange Server | Other
Exchange | Exchange Server | Other

A robust email, calendaring, and collaboration platform developed by Microsoft, designed for enterprise-level communication and data management.Miscellaneous topics that do not fit into specific categories.

0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-02-28T12:43:48.48+00:00

    The 500 errors on OWA/ECP with Exchange 2019 are commonly caused by one of the following conditions described in the context. Work through these checks on the Exchange server:

    1. Verify the admin mailbox and arbitration mailboxes
      • If the admin signing in to EAC/OWA does not have a mailbox, or arbitration mailboxes are unhealthy, HTTP 500 can occur.
      • In Exchange Management Shell, run:
             Get-Mailbox -Arbitration
        
        • Healthy output should list seven arbitration mailboxes with no warnings or errors.
      • If the admin account has no mailbox, enable it:
             Enable-Mailbox -Identity <admin ID>
        
      • If any arbitration mailboxes are missing or unhealthy, re-create/fix them by following the steps in “Re-create missing arbitration mailboxes.”
    2. Check for HTTP 500 after Exchange updates
      • If a recent CU or Security Update was installed, HTTP 500 in OWA/ECP can be caused by a failed or partially applied update, especially if you see errors like: Could not load file or assembly 'Microsoft.Exchange.Common, Version=15.0.0.0'...
      • In that case, reinstall the latest security update from an elevated command prompt:
        1. Open Command Prompt as Administrator.
        2. Run the .msp file for the Exchange security update by typing its full path and pressing Enter.
        3. Restart the server after installation completes.
    3. Check for OAuth certificate issues
      • If users cannot sign in to OWA/ECP and the browser hangs, loops, or shows redirect/blank-page behavior, an expired or missing Exchange OAuth certificate can cause 500/redirect errors and Event ID 1003.
      • If Event 1003 from MSExchange Front End HTTPS Proxy appears with ParseCadataCookies or Object reference not set to an instance of an object, follow the guidance in “Can't sign in to Outlook on the web or EAC” to renew the Exchange Server authorization (OAuth) certificate.
      • Similarly, if you see ASSERT: HMACProvider.GetCertificates:protectionCertificates.Length<1, renew the OAuth certificate as described in the same article.
    4. Ensure all Exchange servers behind any load balancer are consistently updated
      • If a load balancer is in use and some Exchange servers have the July 2021 (or later) security update while others do not, OWA/ECP logons can fail or loop.
      • Make sure all servers in the load-balancer pool are updated to at least the July 2021 SU or later.
      • As a temporary workaround, configure persistence to “source-ip” on the load balancer so a user stays on the same backend server.
    5. Confirm you are on a supported CU level for known OWA issues
      • If running Exchange 2019 CU12 with extended protection enabled in a coexistence topology, OWA logon can fail. Installing CU13 or later resolves this.
      • If SSL offloading is used and OWA logon fails or loops in Chrome, install CU11 (or later) for Exchange 2019 or CU22 (or later) for Exchange 2016 to fix SameSite cookie handling.

    Given that:

    • OWA/ECP show HTTP 500,
    • IIS test site also returns 500,
    • Exchange itself works locally,

    start with step 1 (admin/arbitration mailboxes) and step 2 (reinstall latest Exchange security update) because they directly address HTTP 500 in OWA/ECP after changes or issues on the server. Then validate OAuth certificate health and CU/update level as in steps 3–5.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    1 person found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.