How to Configure CBA for exchange 2019 on premise??

Anonymous
2025-01-15T09:33:49+00:00

Good day,

I was setting up CBA for active sync and owa on exchange on premise 2019 following this guide https://learn.microsoft.com/en-us/exchange/plan-and-deploy/post-installation-tasks/configure-certificate-based-auth?view=exchserver-2019 on my test environment.

Everything went smoothly, but when I Check OWA or ActiveSync virtual directory to require client certificate and connect through browser and prompt to choose user certificate I get error 403 "You don't have the user rights to view this page." Without virtual directory set to requiring client certificate everything works great.

Here is log of 403 in IIS: 2025-01-15 09:15:24 ::1 GET /OWA/auth.owa &encoding=; 443 - ::1 AMProbe/Local/ClientAccess - 403 7 5 19.

For CA I am using AD CA installed on domain controller, and for certificates issuance to user I use copy of user template and autoenrollment. User certificate picture is attached.

Server certificate is generated on offline Linux server CA, and this CA is trusted on domain. I really have no idea what else to do to make CBA work, maybe somebody can give some more suggestions???

![](https://filestore.community.support.microsoft.com/api/images/cd0396fc-66eb-4bc0-8ca8-fc9bbe3333ed?upload=true&fud_access=hC1SxZhn7m%2FZQJkOIiOVstu10yTQgXS4A%2FDBzZTg8nbaCgIogkrcDydMeI5Y4za2dOqDdWtsG2JNS3E35V60i9TiGHR7STMpJHheeXuDvO8nwjUlqCBHhJ0NDvuYN7OSZGC6TP86qsrJaoCPCyfBMHy5LfC5A%2FpcVObdAD9q9dau9aXODHVaHWeR0v14dhZOAXqTgaGH%2BEfL%2FwUaiAgZASbPduLp%2F1LQd96XbaMgpbDQTlnaM2PXbpj5v%2BuY96BwegTV2OJwj1QIoVA7ReQEtB%2BGwVwyuy14qhb6%2FktXsdyDkMwK4hZGyc%2FaJ41Hsvl8jSpR57LX9MKQbqNAmZGLAbRJM4beb0EvqWHlpmEdkkKJKMHQvbvDv078Ahfp7TpZgy79e4R9nN40FpQIPxL9pbpC6ZV25HlnS9YFmJ34h38%3D)

Windows Server Identity and access Certificates and public key infrastructure (PKI)

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2025-01-15T11:44:05+00:00

    Hello Evald_En,

    Thank you for posting in Microsoft Community forum.

    From the description above, I understand your question is related to Exchange.

    Since there are no engineers dedicated to Exchange in this forum. in order to be able to get a quick and effective handling of your issue, I recommend that you repost your question in the Q&A forum, where there will be a dedicated engineer to give you a professional and effective reply.

    Here is the link for Q&A forum.
    Questions - Microsoft Q&A

    Click the "Ask a Question" button in the upper right corner to post your question and type "Exchange" tag and select any tags related to your productions.

    I hope the information above is helpful.

    If you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    0 comments No comments