Solved

Securing / Hardening OWA

Posted on 2008-10-08
4
1,100 Views
Last Modified: 2010-05-18
Hi All,

I'm just wondering if there's any way to make OWA more secure after i purchased UCC certificate from COMODO RC4-128 bit

but my boss explained that he can log in at an internet cafe with no problems.
I have logged in with my home desktop and found the only security to be the normal login and password required.

Can anyone here please share on how we might address this to secure and hardening the OWA access.

- thanks
0
Comment
Question by:jjoz
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 9

Assisted Solution

by:Housammuhanna
Housammuhanna earned 250 total points
ID: 22667501
You may have a UCC
but you MUST force the Connection to use only SSL
if the users are using SSL HTTPS then the connection is secure
are you able to view the site using HTTP, NO
what is the Security your boss is looking for
A lock and prevention from accessing the OWA from anywhere
then you can use the VPN
0
 
LVL 23

Assisted Solution

by:ormerodrutter
ormerodrutter earned 250 total points
ID: 22669233
OWA is designed for, well, convenience. It is there so that users can access their own emails while on the road. What is the point of using OWA if your users can't access their emails say, while in a business trip abroad?

Yes there is a way to further tighten OWA but you have to think about the cost vs benefit.

The most secure way is to get your user(s) to create a long & complex password. Use Group Policy to enforce such as your users will have to use a password over 8 characters with a combination of upper/lower case, numbers & letters.

0
 
LVL 1

Author Comment

by:jjoz
ID: 22674252
Yes,

Currently my OWA is using HTTPS and it is accessible from anywhere around the world.

i guess that UCC cert. is should be enough then.
0
 
LVL 1

Accepted Solution

by:
jjoz earned 0 total points
ID: 22675524
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This article will help to fix the below error for MS Exchange server 2010 I. Out Of office not working II. Certificate error "name on the security certificate is invalid or does not match the name of the site" III. Make Internal URLs and External…
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
Suggested Courses

622 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question