A robust email, calendaring, and collaboration platform developed by Microsoft, designed for enterprise-level communication and data management.Miscellaneous topics that do not fit into specific categories.
The 500 errors on OWA/ECP with Exchange 2019 are commonly caused by one of the following conditions described in the context. Work through these checks on the Exchange server:
- Verify the admin mailbox and arbitration mailboxes
- If the admin signing in to EAC/OWA does not have a mailbox, or arbitration mailboxes are unhealthy, HTTP 500 can occur.
- In Exchange Management Shell, run:
• Healthy output should list seven arbitration mailboxes with no warnings or errors.Get-Mailbox -Arbitration - If the admin account has no mailbox, enable it:
Enable-Mailbox -Identity <admin ID> - If any arbitration mailboxes are missing or unhealthy, re-create/fix them by following the steps in “Re-create missing arbitration mailboxes.”
- Check for HTTP 500 after Exchange updates
- If a recent CU or Security Update was installed, HTTP 500 in OWA/ECP can be caused by a failed or partially applied update, especially if you see errors like:
Could not load file or assembly 'Microsoft.Exchange.Common, Version=15.0.0.0'... - In that case, reinstall the latest security update from an elevated command prompt:
- Open Command Prompt as Administrator.
- Run the
.mspfile for the Exchange security update by typing its full path and pressing Enter. - Restart the server after installation completes.
- If a recent CU or Security Update was installed, HTTP 500 in OWA/ECP can be caused by a failed or partially applied update, especially if you see errors like:
- Check for OAuth certificate issues
- If users cannot sign in to OWA/ECP and the browser hangs, loops, or shows redirect/blank-page behavior, an expired or missing Exchange OAuth certificate can cause 500/redirect errors and Event ID 1003.
- If Event 1003 from MSExchange Front End HTTPS Proxy appears with
ParseCadataCookiesorObject reference not set to an instance of an object, follow the guidance in “Can't sign in to Outlook on the web or EAC” to renew the Exchange Server authorization (OAuth) certificate. - Similarly, if you see
ASSERT: HMACProvider.GetCertificates:protectionCertificates.Length<1, renew the OAuth certificate as described in the same article.
- Ensure all Exchange servers behind any load balancer are consistently updated
- If a load balancer is in use and some Exchange servers have the July 2021 (or later) security update while others do not, OWA/ECP logons can fail or loop.
- Make sure all servers in the load-balancer pool are updated to at least the July 2021 SU or later.
- As a temporary workaround, configure persistence to “source-ip” on the load balancer so a user stays on the same backend server.
- Confirm you are on a supported CU level for known OWA issues
- If running Exchange 2019 CU12 with extended protection enabled in a coexistence topology, OWA logon can fail. Installing CU13 or later resolves this.
- If SSL offloading is used and OWA logon fails or loops in Chrome, install CU11 (or later) for Exchange 2019 or CU22 (or later) for Exchange 2016 to fix SameSite cookie handling.
Given that:
- OWA/ECP show HTTP 500,
- IIS test site also returns 500,
- Exchange itself works locally,
start with step 1 (admin/arbitration mailboxes) and step 2 (reinstall latest Exchange security update) because they directly address HTTP 500 in OWA/ECP after changes or issues on the server. Then validate OAuth certificate health and CU/update level as in steps 3–5.
References:
- HTTP server error status (500) when signing in to EAC
- Fix failed Exchange Server updates
- Cannot log in to OWA or ECP after July 2021 SU for Exchange Server 2019, 2016, and 2013 (KB 5005341)
- Can't log on to OWA in Chrome if SSL is offloaded in Exchange Server 2019 and 2016 (KB5006993)
- Can't sign in to OWA or EAC after you install Exchange Server 2019 CU2 with AD FS
- OWA stops responding in an Exchange 2019 and 2016 coexistence topology
- Users get a security warning when trying to connect OWA and ECP