Home > Ask the Microsoft Exchange Experts > Richard Luckett: Spam and Security Questions & Answers > Enhance OWA logon security using Microsoft ISA Server
Ask The Exchange Expert: Questions & Answers
EMAIL THIS

Enhance OWA logon security using Microsoft ISA Server

Richard Luckett EXPERT RESPONSE FROM: Richard Luckett

Pose a Question
Other Exchange Categories
Meet all Exchange Experts
Become an Expert for this site


Exchange Server tips, tutorials and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 18 September 2007
I have one Exchange server and one Microsoft ISA server. Outlook Web Access (OWA) is published through the ISA server. When anybody tries to access OWA, it prompts for username and password, and then you can log on. However, after logging on you can input any username in the address bar and that user's Exchange mailbox will open. I'm using a Secure Sockets Layer (SSL) certificate (e.g., https://mail.abc.com/exchange/Username), so I'm stumped as to why this isn't secure.

>
EXPERT RESPONSE

The default security model in Exchange Server 2003 prevents all user accounts from being able to open more than their own mailbox. A change to the default security settings is the only way this could happen.

For example, if you were to follow the steps in the Microsoft article, "How to assign service account access to all mailboxes in Exchange Server 2003," an account could be given access to all mailboxes. If you are logging on using such an account, then it might be possible to do what you have described without being prompted for a separate set of credentials.

You'll want to look at enabling forms-based authentication (FBA) on the ISA server. This will enhance the security for each logon. It will also force each session to log on with a new set of credentials.

For step-by-step instructions on configuring the listener for FBA, take a look at Outlook Web Access Server Publishing Walk-through Procedure 4: "Secure Outlook Web Access through the listener."

Do you have comments on this Ask the Expert Q&A? Let us know.

Related information from SearchExchange.com:

  • Tip: Protecting Outlook Web Access from keystroke loggers
  • Expert Advice: Securing Exchange mailboxes from internal attacks
  • Administration Guide: Outlook Web Access security
  • Reference Center: ISA server tips and resources

  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    ISA Server and Firewalls for Microsoft Exchange Server
    Why Exchange ActiveSync fails with NAT firewalls
    Deploying ISA Server as a firewall for Exchange Server mobile devices
    Adjust your firewall to avoid Exchange 2007 Direct Push failures
    OWA stops working from external network connection
    Firewall problems with Exchange Server 2007 email attachments
    How and why to disable certain ESMTP verbs
    Creating an ethical firewall in Exchange Server 2007
    Beware of firewalls that block Exchange Server's SMTP/POP3 communications
    How HTTP verbs can 'hang' Outlook Web Access
    Protect Exchange ActiveSync from premature firewall connection timeouts

    Outlook Web Access
    Repairing damaged OWA virtual directories in Exchange Server 2003
    Customizing an Outlook Web Access 2003 email signature
    Outlook Web Access limitations using Exchange Server public folders
    OWA won't load after applying Exchange 2007 SP1 security patch
    Minimize remote and mobile Outlook Web Access (OWA) security risks
    How to improve Outlook Web Access (OWA) security
    Alleviate Outlook Web Access (OWA) email attachment security issues
    Customizing Outlook Web Access (OWA) in Exchange Server 2007
    Fix OWA message size limit issue after Exchange 2007 SP1 upgrade
    How to customize OWA authentication logon in Exchange Server 2003

    Richard Luckett: Spam and Security
    Selectively set email permissions for Exchange groups
    What event log tracks user access to Exchange Server?
    Public folder permissions fail in Exchange mixed mode
    Locate 'missing' SPF record on an external DNS domain
    Native Exchange Server 2003 antispam solutions
    Configure IMF's Gateway SCL to improve spam filtering
    POP3 server filters all email into Junk folder as spam
    Setting up an SSL certificate for OWA without a public IP address
    Creating one password for both local and Microsoft Outlook user accounts
    Should Exchange Server utilize the SMTP connector for internal email?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    reverse proxy server  (SearchExchange.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts