Active Roles fails to authenticate with Microsoft Exchange when the HTTPS option is enabled for remote PowerShell sessions. Per Microsoft documentation, on-premises Exchange connections must use HTTP over port 80. The connection remains secure because the payload is natively encrypted using Kerberos tokens, removing the need for a HTTPS configuration.
Microsoft explicitly designs on-premises Exchange remote PowerShell sessions to use HTTP. The session is already fully encrypted by the Kerberos token in the payload
No changes or actions are required on the Active Roles side. Active Roles connects to Exchange using HTTP paired with Kerberos authentication. This configuration is inherently secure, fully encrypted, and represents the officially supported Microsoft architecture. Changing Active Roles to use HTTPS is unnecessary and will break functionality.
© 2026 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center