USB key security for OWA

Posted on 2008-10-27
Last Modified: 2013-12-04
Hi Everyone,

I'm just wondering is it possible for one to use USB key loaded up with certificate for a "token" like security measure without using smart card to access OWA ?

Question by:jjoz
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2

Accepted Solution

DBT_Support earned 250 total points
ID: 22811648
Is this the kind of solution you are looking for?
Authenex 2Factor authentication can be done with a usb dongle, and then the username and password.
Also client side security certificates generated from an internal CA will provide a second factor.
This certificate will need to be loaded into the certificate store, and is not eaily USB portable.
LVL 31

Assisted Solution

Paranormastic earned 250 total points
ID: 22812814
If you aren't looking for 'traditional' smartcard styled USB token access, you could export the certificate (presumably including the private key so they could decrypt files) to file and copy that to a USB token or email it, etc., and then import it to another box (e.g. their home system).  It would stay installed, but would not have the same level of security as a regular smartcard solution which would copy over the public key but keep the private key safe.  Doing it with the export/import method would work fine, but if their home system got compromised then their private key could become compromised, resulting in having to reissue the cert - this would also technically allow someone that had the cert access to decrypt whatever was encrypted with it.  How much this matters is up to your corporate security policy.

Author Comment

ID: 22827015
yeah, sort of like that.

i wonder if anyone ever use this RSA SecurID® 6100 USB Token for securing the OWA system.
Office 365 Advanced Training for Admins

Special Offer:  Buy 1 course, get 2nd free!  Buy the 'Managing Office 365 Identities & Requirements' course w/ Accelerated TestPrep, and automatically receive the 'Enabling Office 365 Services' course FREE!

LVL 31

Assisted Solution

Paranormastic earned 250 total points
ID: 22830261
That should work fine for housing client certs - this is a smart USB token - essentially a smartcard in a different form factor with a virtual reader instead of a physical one.  Pretty much every smartcard company has added smart tokens to their lineup years ago.  Maybe I misunderstood your initial question - I thought you were looking at attempting a non-smartcard solution meaning using a standard usb flash thumb drive instead of a usb smart token.  

USB smart tokens are pretty neat - try to negotiate a deal with the vendors as most of them have enormous markups on these things - a company I used to test for made them for about 11 bucks and sells them for about 80!  I know they need to make a profit, but I think a 700% markup is a bit extreme.  I would say 30-40 bucks is a decent deal, that's about the price of a standard smartcard.  Its the exact same chip inside - literally - just a different interface.

Author Comment

ID: 22836807

Paranormastic that's the way i want "would it be possible to secure our OWA using our own USB key ?" that's the question in other words.

but thanks for all who contribute to this thread, now i know that 2-Factor security is possible for securing OWA.

Author Closing Comment

ID: 31510216
Thanks for the info.

Featured Post

Webinar: Aligning, Automating, Winning

Join Dan Russo, Senior Manager of Operations Intelligence, for an in-depth discussion on how Dealertrack, leading provider of integrated digital solutions for the automotive industry, transformed their DevOps processes to increase collaboration and move with greater velocity.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Many businesses neglect disaster recovery and treat it as an after-thought. I can tell you first hand that data will be lost, hard drives die, servers will be hacked, and careless (or malicious) employees can ruin your data.
Ransomware continues to grow in reach and sophistication, putting data everywhere at risk. Learn how to avoid being caught in its sinister clutches with these 11 key tips.
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit If you want to manage em…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question