Solved

Exchange '10 CAS OWA (Default Web Site) Properties for Authentication

Posted on 2014-10-16
5
191 Views
Last Modified: 2014-10-21
Looking for the best recommendation on what the authentication settings of OWA for Exchange 2010 under the Default Web Site properties should be set to.

Goal is to have OWA exposed out to the Internet via SSL only and to have all mailbox access login with domain\user name is fine. Would like to have this passed through from a single sign-on for Citrix so would Integration Windows be required or could that be form-based?
0
Comment
Question by:RTM2007
  • 3
  • 2
5 Comments
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 40385500
Forms Based Authentication is the preferred method for authentication on OWA, as access is controlled by a cookie. That means when you sign out, the session is closed. Any other method allows access back in again.

However single sign on from Citrix would probably require Windows authentication. Therefore if you want to do both, you will need to create a second web site for the different authentication methods.

This is covered by an Exchange team blog.
http://blogs.technet.com/b/exchange/archive/2011/01/17/configuring-multiple-owa-ecp-virtual-directories-on-exchange-2010-client-access-server.aspx

Simon.
0
 
LVL 2

Author Comment

by:RTM2007
ID: 40385553
Thank you. For the standard authentication methods, is the basic authentication (password is sent in clear text) on by default? This seems not as secure that it is transmitted in plain text but not sure if undoing that setting would break authentication somehow.
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40385560
By default it should be forms based authentication - I am talking about Exchange authentication here, not whatever you see in IIS manager. FBA will use plain text, because the password will be within an SSL session.

Simon.
0
 
LVL 2

Author Comment

by:RTM2007
ID: 40385570
Yes, I meant the OWA default site permissions under the authentication tab. The top setting is to use basic and the third check box is that password is sent in plain text (basic)
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40385584
In a default configuration those would be greyed out and the forms based authentication methods enabled.

Simon.
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
Scam emails are a huge burden for many businesses. Spotting one is not always easy. Follow our tips to identify if an email you receive is a scam.
In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now