Outlook and Skype saved credentials lock my different domain account on Windows 11

Alessandro Chiarotto 0 Reputation points
2025-01-09T03:19:14.45+00:00

Hi,

in my organization we have a domain used to manage access and distribute GPO and another domain where our Exchange server and other services are.

I'm rolling out Windows 11 LTSC 2024 and in this test phase i've given it to my self and other 2 collegues. These collegues present the same issue:

when storing credentials for Outlook and Skype for Business (Office LTSC Pro 2024) the applications keep sending requests to the PCs domain and not to the mailbox domain witch is correctly stated in the saved credentials.

I keep seeing bad password attempts in my PCs Domain Controller with the exact timestamp of Outlook.exe or UcMapi.exe event 4648 on the machine.

Anyone has had issues with somenthing like that before?

Thank you for your help.

Skype for Business
Skype for Business
A Microsoft communications service that provides communications capabilities across presence, instant messaging, audio/video calling, and an online meeting experience that includes audio, video, and web conferencing.
647 questions
Outlook
Outlook
A family of Microsoft email and calendar products.
4,432 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
10,666 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Alessandro Chiarotto 0 Reputation points
    2025-01-09T07:20:23.8533333+00:00

    Hi Jimmy,

    yes this is exactly my assumption.

    The issue is that in Credential manager and in the application settings all is set up as it should. I've already checked the places you suggested multiple times without noticing anithing wrong. Moreover our Windows 10 LTSC PCs have the same credential format and they work.

    I've also started to suspect that something goes wrong in the Kerberos and NTLM authentication. Since there is no trust between the two domains maybe the first behavior of windows 11 is to ask a Kerberos ticket in his domain and then try the NTLM one in another domain. This is just a theory at the moment.

    Let me know if you have other ideas. Thank you.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.