Forum Discussion
APM Domain Membership Restriction?
Is this possible?
Thanks,
Josh
- hooleylistCirrostratusHi Josh,
- Josh_41258NimbostratusAaron,
- Mike_61719CirrusYou're going to have to set it up like activesync. Outlook anywhere uses pretty much the same components as Acticesync.
- I think that the requirement here was to allow only DOMAIN-joined machines to access OutlookAnywhere. Josh's second post is right on the money - the only way to do it is to have a client to connect to a web-based VIP first that will perform the inspection of the end-point and authenticate the user and confirm he's coming from domain-joined machines. THen it will create a "holding" session for that username for a short period of time, so that when the user launches Outlook client and OA connection is established, APM will authenticate those credentials and make sure that that username has been verified as coming from domain-joined machine within last x seconds or minutes - and let the connection through.
- Baron_of_StrathHistoric F5 Account
http://www.microsoft.com/en-us/download/confirmation.aspx?id=22723 - an article by Microsoft which shows how to use Kerberos and certificates inside of Outlook Anywhere via TMG or TMG/UAG to provide access. This could, I'm sure, be replicated through APM.
Baron,
As a matter of fact, APM can certainly do everything that is described in the doc you are referencing, but using client certificate for authenticating OutlookAnywhere traffic is not described there. Can you please perhaps point me to the page in the doc where it's buried? Thanks.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com