    Same problem but different implementation. I'm front-ending and external connection inbound to Exchange via EWS to pull mailbox info. Once EP was enabled it broke the NTLMv2 auth via APM.... Looking for a way to capture the user account making the request to allow/deny based on the user. Exchange is looking for NTLM auth so basic on APM for EWS won't work... 

  • Extended protection is not supported:

  • Its working when you only use OWA and use form-based SSO or basic-auth for active-sync