Wednesday 30 November 2011

Default IIS Authentication for Exchange 2003, 2007 and 2010


Exchange Server 2003
Front End and Back End Topology
Virtual Directory
FE
SSL Required
BE
SSL Required
Default Web Site
Anonymous
Optional
Anonymous
No
Exadmin
Integrated
No
Integrated
No
Exchange
Basic
Optional
Basic/integrated
No
Exchweb
Anonymous
No
Anonymous
No
Active Sync
Basic
Optional
Basic
No
Public
Basic
No
Basic/integrated
No



Exchange Server 2003
Single Server Topology
Virtual Directory
Server
SSL Required
Default Web Site
Anonymous
Optional
Exadmin
Integrated
No
Exchange
Basic/integrated
No
If SSL is required then follow KB-817379
Exchweb
Anonymous
No
Active Sync
Basic
Optional
Public
Basic/integrated
No

·Default Authentication of IIS

Exchange 2007 Client Access Server
Location
Authentication
SSL Setting
Comments
Default Web Site
Anonymous
Required
"Enable HTTP Keep-Alives" setting should be enabled on Web Site tab
/Owa
Basic
Required
Management of authentication setting should be done in Exchange Management Console
/Exchange
Basic
Required
Management of authentication setting should be done in Exchange Management Console
/Public
Basic
Required
Management of authentication setting should be done in Exchange Management Console
/Exchweb
Basic
Required
Management of authentication setting should be done in Exchange Management Console
/Oab
Integrated
Not required
/Autodiscover
Basic and Integrated
Required
/Ews
Integrated
Required
/UnifiedMessaging
Integrated
Required
/Microsoft-Server-Activesync
Basic
Required
Management of authentication setting should be done in Exchange Management Console
/Rpc
Basic and Integrated
Required
Technically, this is a Windows component but I've added it here since Outlook Anywhere depends on the installation of this virtual directory



Exchange 2007 Mailbox Server
Location
Authentication
SSL Setting
Comments
Default Web Site
Anonymous
Not required
/Exadmin
Basic and Integrated
Not required
/Exchange
Basic and Integrated
Not required
Management of authentication setting should be done in Exchange Management Console
/Public
Basic and Integrated
Not required
Management of authentication setting should be done in Exchange Management Console



Exchange 2007 CAS + HUB + MBX
Location
Authentication
SSL Setting
Comments
Default Web Site
Anonymous
Required
"Enable HTTP Keep-Alives" setting should be enabled on Web Site tab
/Owa
Basic
Required
Management of authentication setting should be done in Exchange Management Console
/Exchange
Basic and Integrated
Required
Management of authentication setting should be done in Exchange Management Console
/Public
Basic and Integrated
Required
Management of authentication setting should be done in Exchange Management Console
/Exchweb
Basic and Integrated
Required
Management of authentication setting should be done in Exchange Management Console
/Oab
Integrated
Not required
/Autodiscover
Basic and Integrated
Required
/Ews
Integrated
Required
/UnifiedMessaging
Integrated
Required
/Microsoft-Server-Activesync
Basic
Required
Management of authentication setting should be done in Exchange Management Console
/Rpc
Basic and Integrated
Required
Technically, this is a Windows component but I've added it here since Outlook Anywhere depends on the installation of this virtual directory

Exchange 2010 All in One Box

Virtual Directory
Default Auth Setting
/Autodiscover
Anonymous, Basic, WIA
/ECP
Anonymous, Basic
/EWS
Anonymous, WIA
/MS-Server-Activesync
Basic
/OAB
WIA
/OWA
Basic
/PowerShell
Anonymous
/RPC
Basic, WIA