Enabling activesync allows public access to Exchange server, is this true?
We currently run a BES server with Exchange. I would like to enable activesync so we can use Iphones and Windows phones. Access to OWA is locked down by authorized IP address or access over a VPN. The Exchange admin claims that since port 443 has to be opened in order to allow a smart phone to connect to the Exchange server via activesync anyone with an internet connection would be able to pull up our webmail page via OWA. Is this true? I find it hard to believe that there is not a way to restrict who can access the Outlook Web Access page but still allow smart phones to connect to the Exchange server via Activesync.
May 7th, 2011 1:45am

Hi, Only users that have OWA activated on there mailbox can access via OWA. also, users with active sync activated can access there mailbox by openning an owa connection. Any other person haven't this permission can't access to his mailbox with owa. best regardsBest Regards Don't forget to mark it as answer if it helps
Free Windows Admin Tool Kit Click here and download it now
May 7th, 2011 4:50am

@Alex 1. You can't restrict he actual webpage as it's external. i.e if users got o https://mail.mydomain.com anyone has browse to this. This is the purpose of OWA. 2. Only users who ae authenticated will be allowed access to OWA or use AcitvSynch. 3. You don't just put in the URL for ActiveSyn and get access, you have to authenticate. Sukh
May 7th, 2011 7:01am

We currently run a BES server with Exchange. I would like to enable activesync so we can use Iphones and Windows phones. Access to OWA is locked down by authorized IP address or access over a VPN. The Exchange admin claims that since port 443 has to be opened in order to allow a smart phone to connect to the Exchange server via activesync anyone with an internet connection would be able to pull up our webmail page via OWA. Is this true? I find it hard to believe that there is not a way to restrict who can access the Outlook Web Access page but still allow smart phones to connect to the Exchange server via Activesync. Whats the concern? Users still have to authenticate to get access to their mailbox.
Free Windows Admin Tool Kit Click here and download it now
May 7th, 2011 8:39am

You can always setup a reverse proxy and clients will connect to that instead of the Exchange Server directly.
May 7th, 2011 9:21am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics