remotewebaccess.com Anywhere access broken on Server 2016 Again?

ChrisWY27 136 Reputation points
2022-05-04T19:46:51.657+00:00

Last year a similar issue occurred and by manually applying the registry edits from these two threads most seemed to resolve their issues:

https://learn.microsoft.com/en-us/answers/questions/319165/remotewebaccesscom-down-again.html?childToView=836766#answer-836766

https://learn.microsoft.com/en-us/answers/questions/318584/are-the-problems-with-remotewebaccesscom-domain-an.html?page=2&pageSize=10&sort=oldest

The problem is as of yesterday (May 3 2022) I am now experiencing the issue again. Re-applying the registry tweaks does not solve the issue either unfortunately. More so, I am not able to un-register my domain through the wizard or change to a new one, I am seeing the same issue as this user on their fresh install: https://learn.microsoft.com/en-us/answers/questions/814489/cloud-services-integration-amp-anywhere-access-not.html?childToView=836816#answer-836816

Looking at my Dashboard.log in the ProgramData\Microsoft\Windows Server\Logs folder I see the below:

[5840] 220504.122339.7059: DomainConfigWizard: Next Page: progressPage
[6024] 220504.122340.0497: DomainManagerObjectModel: InvokeAsync: action resulted in exception: System.ServiceModel.FaultException1[Microsoft.WindowsServerSolutions.RemoteAccess.Domains.DomainManagerFault]: The creator of this fault did not specify a Reason. (Fault Detail is equal to DomainManagerFault:[Reason:CommunicationFailure, Message:CommitDomain failed, Detail:System.Web.Services.Protocols.SoapException: Live Dynamic DNS has encountered an internal error. This error has been logged. ---> Microsoft.Rest.Azure.CloudException: The access token is from the wrong issuer 'https://sts.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/'. It must match the tenant 'https://sts.windows.net/33e01921-4d64-4f8c-a055-5bdaffd5e33d/' associated with this subscription. Please use the authority (URL) 'https://login.windows.net/33e01921-4d64-4f8c-a055-5bdaffd5e33d' to get the token. Note, if the subscription is transferred to another tenant there is no impact to the services, but information about new tenant could take time to propagate (up to an hour). If you just transferred your subscription and see this error message, please try back later. at Microsoft.WindowsServerSolutions.DDNS.AzureRmDnsServer.GetARecords(String domainName) in E:\WSE-ServicesAndTools\src\ServicesAndTools\DDNS\DDNS\AzureR...). [6024] 220504.122340.0497: DomainManagerObjectModel: InvokeAsync: handling exception by transferring to eventArgs [5840] 220504.122340.0653: DomainConfigWizard: Error occurred in Domain Manager Object Model operations: System.ServiceModel.FaultException1[Microsoft.WindowsServerSolutions.RemoteAccess.Domains.DomainManagerFault]: The creator of this fault did not specify a Reason. (Fault Detail is equal to DomainManagerFault:[Reason:CommunicationFailure, Message:CommitDomain failed, Detail:System.Web.Services.Protocols.SoapException: Live Dynamic DNS has encountered an internal error. This error has been logged. ---> Microsoft.Rest.Azure.CloudException: The access token is from the wrong issuer 'https://sts.windows.net/72f988bf-86f1-41af-91ab-2d7cd011db47/'. It must match the tenant 'https://sts.windows.net/33e01921-4d64-4f8c-a055-5bdaffd5e33d/' associated with this subscription. Please use the authority (URL) 'https://login.windows.net/33e01921-4d64-4f8c-a055-5bdaffd5e33d' to get the token. Note, if the subscription is transferred to another tenant there is no impact to the services, but information about new tenant could take time to propagate (up to an hour). If you just transferred your subscription and see this error message, please try back later.
at Microsoft.WindowsServerSolutions.DDNS.AzureRmDnsServer.GetARecords(String domainName) in E:\WSE-ServicesAndTools\src\ServicesAndTools\DDNS\DDNS\AzureR...).
[5840] 220504.122340.0653: DomainConfigWizard: FailReason from Domain Manager Object Model operations: CommunicationFailure

This gives some insight to the root cause but I am not sure how to go from here to fix this.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,726 questions
{count} votes

Accepted answer
  1. Samriddhi Chaturvedi 231 Reputation points Microsoft Employee
    2022-05-14T00:32:02.177+00:00

    We were able to get things working on our local test setups.
    Can you please verify your setups and see if the issue went away for you.

    Thanks and Regards
    Samriddhi

    5 people found this answer helpful.

17 additional answers

Sort by: Most helpful
  1. Samriddhi Chaturvedi 231 Reputation points Microsoft Employee
    2022-05-12T23:04:44.693+00:00

    We are working actively on this issue and will keep you all posted.
    Thanks a lot for your patience!

    Thanks, and Regards
    Samriddhi

    1 person found this answer helpful.

  2. Samriddhi Chaturvedi 231 Reputation points Microsoft Employee
    2023-09-18T20:48:10.1+00:00

    We got a hold of the issue and we should be able to correct it in a day.

    Since we have some 3rd party godaddy certs in play, it will take a day to get things back in shape.

    1 person found this answer helpful.

  3. Samriddhi Chaturvedi 231 Reputation points Microsoft Employee
    2023-09-22T17:56:38.18+00:00

    Are you still facing issues or is it resolved on your setups ?

    1 person found this answer helpful.

  4. Samriddhi Chaturvedi 231 Reputation points Microsoft Employee
    2025-02-19T23:31:35.4166667+00:00

    We have stabilized the Issue and the new SSL certs for the RWA/anywhere access should be working fine. There might still be some scenarios where we may see failures saying "CertificateNotTrusted". This in most cases is due to delay in CA being able to verify the newly issued certificate. We have released a hotfix for this problem, and it is a client-side fix and would be available in the 3B i.e March Windows Update for Server 2016/1607 platforms. Please make sure to take the next Windows Update so that the client-side fix for this problem is available.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.