Solved

Can you restrict OWA access in Exchange 2003 to internal users?

Posted on 2006-07-17
3
245 Views
Last Modified: 2008-02-07
I am working on an Inter-Org migration from Exchange 5.5 to Exchange 2003.  The customer requires that OWA be available for some users via the Internet and Intranet, but for some users OWA should only be available on the Intranet (users have a VPN connection).  With Exchange 2000, there was a way to provision OWA access for internal use only.  Refer to following tech article for more details.  http://support.microsoft.com/default.aspx?scid=kb;%5Bln%5D;830827

However, this capability does not seem possible with Exchange 2003 because the Web DAV address check is not present in Exchange 2003.  I know I can disable the http protocol, but then users cannot access OWA at all.  Is there a way to allow some users to access OWA internally, and others to use OWA both via the Internet and Intranet?  We are migrating to Exchange 2003 SP2.  One workaround may be able to post two different URLS, and have the internal one only on the internal DNS, so it is not accessible from the outside.  But if users know what the external posted URL is, they will would be able to get into OWA from the Internet.

Thanks for any suggestions.

Robyn
0
Comment
Question by:rkopischke
  • 2
3 Comments
 
LVL 104

Expert Comment

by:Sembee
ID: 17124616
This question has come up before, but I cannot find the original question to post the link.

With Exchange 2003 the only control you have over OWA is on or off. If it is enabled for the user account then the user can access it anyway that they like. OWA doesn't care and you cannot control the access with Exchange.

The only way that I am aware that you could control access would be to use an ISA server. Publish OWA through the ISA and then have the users who are allowed to access OWA authenticate when they hit the ISA address.
Internal users would hit the Exchange directly so wouldn't be under the same control.

Simon.
0
 

Author Comment

by:rkopischke
ID: 17124691
Thank you so much for the quick response.  The Exchange server does sit behind an ISA server, so that may be an option.  I'm not familair with ISA configuration and how they would athenticate.  Would I set up a group or rule, and if they are a member of the group they can pass through?  I will look into this further.  Thanks again.

-Robyn
0
 
LVL 104

Accepted Solution

by:
Sembee earned 500 total points
ID: 17124725
My ISA skills are not very good either, so I can't really help you with that.

Simon.
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Not sure what the best email signature size is? Are you worried about email signature image size? Follow this best practice guide.
In this video we show how to create a mailbox database in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Servers >> Data…
To show how to generate a certificate request in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Servers >> Certificates‚Ķ

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now