Solved

Exchange '10 CAS OWA (Default Web Site) Properties for Authentication

Posted on 2014-10-16
5
194 Views
Last Modified: 2014-10-21
Looking for the best recommendation on what the authentication settings of OWA for Exchange 2010 under the Default Web Site properties should be set to.

Goal is to have OWA exposed out to the Internet via SSL only and to have all mailbox access login with domain\user name is fine. Would like to have this passed through from a single sign-on for Citrix so would Integration Windows be required or could that be form-based?
0
Comment
Question by:RTM2007
  • 3
  • 2
5 Comments
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 40385500
Forms Based Authentication is the preferred method for authentication on OWA, as access is controlled by a cookie. That means when you sign out, the session is closed. Any other method allows access back in again.

However single sign on from Citrix would probably require Windows authentication. Therefore if you want to do both, you will need to create a second web site for the different authentication methods.

This is covered by an Exchange team blog.
http://blogs.technet.com/b/exchange/archive/2011/01/17/configuring-multiple-owa-ecp-virtual-directories-on-exchange-2010-client-access-server.aspx

Simon.
0
 
LVL 2

Author Comment

by:RTM2007
ID: 40385553
Thank you. For the standard authentication methods, is the basic authentication (password is sent in clear text) on by default? This seems not as secure that it is transmitted in plain text but not sure if undoing that setting would break authentication somehow.
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40385560
By default it should be forms based authentication - I am talking about Exchange authentication here, not whatever you see in IIS manager. FBA will use plain text, because the password will be within an SSL session.

Simon.
0
 
LVL 2

Author Comment

by:RTM2007
ID: 40385570
Yes, I meant the OWA default site permissions under the authentication tab. The top setting is to use basic and the third check box is that password is sent in plain text (basic)
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40385584
In a default configuration those would be greyed out and the forms based authentication methods enabled.

Simon.
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
Are you unable to connect or configure Hotmail email account in Microsoft Outlook 2010, 2007? Or Outlook.com emails are not downloading to Outlook? Lets’ see the problem and resolve Outlook Connector error syncing folder hierarchy (0x8004102A).
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
Many of my clients call in with monstrous Gmail overloading issues with Outlook. A quick tip is to turn off the All Mail and Important folders from synching. Here is a quick video I made to show you how to turn off these and other folders in Gmail s…

825 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question