How do I disable Outlook Anywhere Externally with Split-DNS?

Hello,
I am trying to disable Outlook Anywhere Externally. This issue is that we use split-dns and all of our Exchange services point to mail.domain.com both internally and externally. This can't be changed due to our SSL certificate not including the internal
server DNS name for the Exchange server, and we still have another two years on it.
Is there a way to white-list a range of IP Addresses (potentially through IIS since Outlook Anywhere uses HTTPS)? Would setting the External URL to null for Outlook Anywhere prohibit autodiscover from configuring the Outlook client, or would it do nothing
at all since the internal DNS name is the same as the external?
I could potentially add an internal SSL certificate and change the internal DNS name of Outlook Anywhere. Is this a good move?
Thank you for your time.

Hello,
I am trying to disable Outlook Anywhere Externally. This issue is that we use split-dns and all of our Exchange services point to mail.domain.com both internally and externally. This can't be changed due to our SSL certificate not including the internal
server DNS name for the Exchange server, and we still have another two years on it.
Is there a way to white-list a range of IP Addresses (potentially through IIS since Outlook Anywhere uses HTTPS)? Would setting the External URL to null for Outlook Anywhere prohibit autodiscover from configuring the Outlook client, or would it do nothing
at all since the internal DNS name is the same as the external?
I could potentially add an internal SSL certificate and change the internal DNS name of Outlook Anywhere. Is this a good move?
Thank you for your time.
The only way within Exchange is to set the internal Outlook Anywhere host name to something not resolvable externally and/or null out the external hostname or set to something bogus.
Twitter!:
Please Note: My Posts are provided “AS IS” without warranty of any kind, either expressed or implied.

Similar Messages

  • Exchange 2013 how to disable outlook anywhere

    Hi Team,
    I have migrated some mailboxes from Exchange 2010 to 2013. But i want to restrict some users to use outlook anywhere.
    How can i do this?
    Also, Some outlook 2010 clients are not able to open outlook after migrating to Exchange 2013. Please help.
    Thanks.
    Regards, Sunny Kewalramani.

    Hi,
    Firstly, I'm afraid that we cannot disable Outlook Anywhere for certain users only when they use OA externally. And if the property MAPIBLOCKOutlookRpcHttp of a user is set to true, the user cannot access Exchange server both internally and externally.
    Thanks,
    Angela Shi
    TechNet Community Support

  • Can it be possible to disable outlook anywhere for some few users who are working from home ?

    One of my customer wants to disable outlook anywhere for some of the users who are working from home.They have exchange server 2013 in their premises and also have outlook 2010/2013 on their clients machine.Please advice?

    Hi,
    In Exchange 2013, all Outlook connectivity (Internal and External) are using Outlook Anywhere anyways. It is not recommended to use the following command to disable Outlook Anywhere for a specific user:
    Set-CASMailbox UserA -MAPIBlockOutlookRpcHttp $True
    If you disable it, the UserA would not be able to access the mailbox from both Internal Outlook client (Office) and external Outlook client (Home).
    For your requirement about disable Outlook anywhere for some few users instead of all external users, there seems to be no method to achieve it directly in Exchange server. Sorry for any inconvenience.
    Regards,
    Winnie Liang
    TechNet Community Support

  • Outlook anywhere external Url

    Hello ,
    do I need to enable outlook anywhere External Url(or this optional)
    to autodiscover work
    thanks

    I have exchange 2010 and outlook 2010
    I can connected outlook form outside but with warning and I can send and receive
    and OWA working fine without error or warning and mobile connected without any problem
    but the strange thing when press view certificate button I see
    certificate issued to: my hosting company but my certificate issued to my domain
    and also certificate issued by digicert  but my certificate issued by geo cert Trust
    thanks
    The problem has existed since Exchange 2007. That article just illustrates the issue.
    Here is another.
    http://blogs.dirteam.com/blogs/davestork/archive/2014/08/13/optimizing-the-autodiscover-process-by-skipping-the-root-domain-query.aspx
    Try excluding the root domain autodiscover lookup and see if that resolves it.
    Twitter!: Please Note: My Posts are provided “AS IS” without warranty of any kind, either expressed or implied.

  • How do you disable iPod Auto Update with iTunes?

    How do you disable iPod Auto Update with iTunes? I know there is a key press combo that will do it but I forget which keys. Anyone?
    Intel Piii   Windows XP Pro  

    Keep iTunes from automatically updating your iPod
    Another Easier Alternative:
    While connecting the iPod to the computer, hold down the Shift + Ctrl keys in Windows (CMD + Option keys on a Mac). This will stop the iPod from auto-syncing with iTunes. The iPod will then appear in the iTunes source list. Wait until you are sure the iPod has mounted, and that it will not auto-sync and then you can release the keys. This action may take between 3 and 25 seconds depending on your computer.
    You can then ‘right-click‘ on the iPod icon in iTunes’ source column and select iPod Options, then check the box that says “Manually manage songs and playlists”. You can now manage your library without losing any songs on the iPod.
    Note: If connecting to a different computer than the ‘iPod’s Home Computer’, iTunes will ask you if you want to update your iPod and give you an opportunity to opt out. This will not happen if you connect to the ‘Home’ computer – iTunes will auto-sync without warning!. Best to know the difference.

  • How can I disable the memory sharing with the video?

    how can I disable the memory sharing with the graphic card? it makes me impossible to run a software, grandMA2, on windows 7 installed and run via bootcamp. where should I look for changing the preferences of memory and video, on lion or on windows7? thank you

    so what do you think. I run a software on windows 7 running via bootcamp on my mbp, but I can't open it. the software is compatible with windows 7 on mac. I tried opening it as administrator or changing the compatibility options, like running it as windows xp, and changing the resolution of the video. it can't build the window and then it crashes. on internet I found a compatibility list of the software where it says please do not use any shared memory for the graphic card. what does it mean? I have just to remove the check in automatic graphics switching? what should I try to do? thank you. 

  • Outlook Anywhere External Hostname

    Good dayI am busy doing a few tests in my Lab environment with regards to Exchange 2010 Outlook anywhere.Do any of you know if it possible to setup Outlook anywhere with an external hostname that differs from what the CAS hostname is?Taking into account that you have configured all the rest of the requirements for Outlook anywhere such as setting up the SAN certificate with all the correct FQDNs, setting up DNS etc.I have also configured the OutlookProvider (Set-OutlookProvider -Identity EXPR..) with the FQDN that I want to use for Outlook anywhere.What I have found is that when I configure my Outlook client to use this new proxy address instead of the CAS hostname it prompts for a password and does not accept the password that is given. I can see in Outlook clients connection status that it is indeed trying to connect to my Outlook...
    This topic first appeared in the Spiceworks Community

    Hi,
    According to your description, you have minimized the certificate names before you set the internal and external host names of Outlook Anywhere and other services' URLs. If I misunderstand your meaning, please feel free to let me know.
    If yes, As Martina said, I recommend you set all URLs and internal and external OA host names with the name mail.company.com. Then we can confirm the internal DNS record about the name. To test Autodisocver, we can directly access its URL which is set in
    the property AutodiscoverServiceInternalURI.
    Additionally, based on my research, for the error when you run the New-TestCasConnectivityUser.ps1 script, you can opened the script in notepad and found the line beginning “new-mailbox” – and deleted the parameter “–OrgainisationalUnit:$OrganistationalUnit”:
    http://www.definit.co.uk/2011/03/exchange-2010-createtestuser-mailbox-could-not-be-created-verify-that-ou-users-exists-and-that-password-meets-complexity-requirements/
    Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please make
    sure that you completely understand the risk before retrieving any suggestions from the above link.
    Thanks,
    Angela Shi
    TechNet Community Support

  • Outlook anywhere external issues

    Hi
    I have exchange 2013 installed FRESH.  I have configured all the URLs properly and autodiscover is published externally as an A record (autodiscover.domain.com)
    There are no issues inside.
    HOWEVER I can NOT access outlook anywhere from outside.  I get a pop up that says "Outlook can not log on.  Verify you are connected to the network and are using the proper server and
    server mailbox name.....".  exchange remote connectivity analyzer shows me this error "An HTTP 401 Unauthorized response was received from the remote Unknown server. This is usually the result of an incorrect username or password."
    I can access our OWA and autodiscover properly from outside.  I can also reach https://autodiscover.domain.com/autodiscover/autodiscover.xml.  When I use "test autoconfiguration" from outlook the tests are all successful.  IISauthentication
    is set to "basic,ntlm".  I tried both NTLM & basic.  I also tried multiple accounts.  Nothing works
    I appreciate your help.

    Hi,
    Firstly, I'd like to explain, restarting IIS just helps the new settings take effect faster.
    Addording to your description, all external users cannot use Outlook Anywhere.
    And to narrow down the cause I'd like to confirm the detail result of ExRCA Outlook Anywhere test, especially the partition which has the error.
    Thanks,
    If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Angela Shi
    TechNet Community Support

  • How can I sync Outlook Express email with Nokia 58...

    Hello -
    I'd like to know if/how I can sync my works outlook express emails with my nokia 5800?  Not via a web browser but setting up the sync in the messages area.  All the sites/manuals I've searched are too vague and don't seem to offer any explanations on what I need to do specifically for outlook.
    Can anyone help?
    Many Thanks

    In general you don't sync with a mail client's local message store (such as the Outlook Express message store on your Work PC).  You generally sync to a mail server.
    So what you can do is find out which server your Outlook Express mail client is configured for on your PC, and then use the same server settings on your Nokia Phone.
    For further questions, you may want search in, and post to the Mail, Messaging & Browsing discussion forum.
    Lumia 920, Lumia 800
    Nokia N8-00 (NAM, Product Code: 059C8T6), Symbian Belle, Type RM-596, 111.030.0609
    Nokia 5800 XpressMusic (NAM, Product Code: 0577454) Software v51.2.007, Type RM-428

  • How do i configure outlook for use with icloud and my iphone?

    I am at a loss at how to configure my outlook 2007 for the best synch and use with my icloud and or iphone. Any help out there?

    You can't write to it because it's formatted as NTFS which OS X will read but not write to. If you want to continue using the drive with both a PC and OS X you will need to download and install NTFS-3G so you can then write to it from your Mac. You can get NTFS-3G at:
    http://www.macupdate.com/app/mac/24481/ntfs-3g
    If you want to use the drive exclusively with your Mac then move the data off it and reformat it in Disk Utility (Applications - Utilities - Disk Utilities) as Mac OS Extended (Journaled.)

  • How can I disable Outlook 2010 addins using Group Policy

    I have downloaded and imported the templates to enable me to set a GPO for disabling Outlook  addins, but I am confused about how I disable things like the SharePoint addins (we do not use SharePoint so this is not needed). I have found several
    posts saying to do this via a registry change, which I can easily do via GPO, but it does not say how to add keys for the different addins.
    Does anyone have details of what I need to add into the registry or have a link to somewhere that gives a list of common ones I can use?

    Hi,
    >>Does anyone have details of what I need to add into the registry or have a link to somewhere that gives a list of common ones I can use?
    After searching around, I think the following article may give us some tips about how to manage application-level add-ins. To disable a specific add-in, we can try to set the value of
    LoadBehavior entry to 0 in the add-in's corresponding registry key. The registry key path for a specific add-in is as follows:
    HKEY_CURRENT_USER or HKEY_LOCAL_MACHINE\Software\Microsoft\Office\application name\Addins\add-in ID
    Registry Entries for Application-Level Add-Ins
    http://msdn.microsoft.com/en-us/library/vstudio/bb386106.aspx#LoadBehavior
    If this doesn't help, in order to get better help, it's recommended that we ask for suggestions in the following Outlook or SharePoint forums.
    Outlook IT Pro Discussions
    https://social.technet.microsoft.com/Forums/office/en-US/home?forum=outlook
    SharePoint forums
    https://social.msdn.microsoft.com/Forums/sharepoint/en-US/home?category=sharepoint
    TechNet Subscriber Support
    If you are TechNet Subscription user and have any feedback on our support quality, please send your feedback here.
    Best regards,
    Frank Shen

  • How can i disable faronics deep freeze with no username/password?

    how can I disable deepfreeze with no username or password?

    Basically you can't; that's the whole point of the software (or at least a large part of the point), so that unauthorized people can't make changes to the system. As Kappy said, you'll need to contact Faronics for assistance, but I don't remember any sort of "back door" to their software so there may be no solution short of erasing the drive and starting from scratch.
    Regards.

  • How do you disable a restrictions code with out resetting your iPhone and the password

    How do you disable your restrictions code without resetting your phone and without putting in the code?

    No, there isn't. But you can restore your stuff if you have a current backup to restore. Otherwise, you are S.O.L.

  • Exchange 2013 Split DNS, how to get WAN clients to use public Split DNS IP when inter-office link is DOWN?!

    Hello,
    I have an Exchange 2013 deployment and a LAN/WAN setup, we have many small remote WAN linked offices that can resolve to the Exchange Server's internal IP.
    Outlook clients in remote WAN offices work fine as long as the link is UP since the Split Brain DNS for Exchange will resolve the internal clients to the internal IP of the Exchange server, Outlook connects up without issues.
    However, in the event of loosing connection to our remote sites, they will no longer be able to resolve to the internal Exchange IP, but they still have a backup public internet that they can use. So should the inter-office connectivity fail we have it setup
    so clients in remote offices can still browse the internet, etc.
    However, their Outlook fails to connect because it has a cached DNS record for our Split Brain Exchange DNS setup and tries to resolve it to its internal IP, instead of refreshing the cache and grabbing the public IP of the Exchange server since now they
    would be resolving it over the public internet.
    Is there anything I can do with my existing configuration to allow the client to pick up the public IP of the Split DNS setup when our inter-office connection is down and the client is no longer able to use the internal IP they have cached for Exchange?
    I guess I could lower the TTL on the DNS record to something like 1 minute so it does not cache the DNS record / IP for long? Is this the best approach?

    http://public.wsu.edu/~brians/errors/lose.html
    I would suggest that the best approach is to either improve the reliability of the WAN link or to configure DNS to always use the Internet path.  You might want to work with your network guy, perhaps there's a way to have your gateways automatically
    switch to an Internet VPN backup when the WAN link is down or something like that.
    Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."

  • How to pop-up Outlook Email window with To: blank?

    Hi All,
    I currently have a page which shows multiple rows with checkboxes. I have an After Submit process which loops through the rows and stores some values of the checked rows into a variable to be used as the body of an email. I then call apex_mail.send() to send the email.
    Instead of prepopulating a TO: address within the process and have it send automatically, I would like to have Outlook pop-up the email window with the body prepopulated as mentioned above but with the TO: address box null so that the user can select the address from Outlook's Address Book.
    Any help/advice would be greatly appreciated!
    Thanks,
    Jason

    1: Yup.. It would look something like this:
    <a href="mailto:?body=aslkdjldfks">Open Email</a>  the # should read:
    "mailto:?body=aslkdjldfks"
    2: If you go this route, there are a few things you need to remember:
    The mailto tag is client side. So you would have to generate the javascript on the server and print it out on the client.
    If your users do not have Outlook, or another mail client, this will do nothing.
    If you have a really long message body it will not work.
    If you have weird characters you will need to encode these.
    So, if you still think that the mailto is what you need then here is some javascript that will auto open it for you:
    http://www.webmasterworld.com/javascript/3290040.htm

Maybe you are looking for

  • Remote not working with MBP lid closed

    My MBP OSX 10.8.2 is plugged in using the charger and connected via an HDMI adapter to my TV.  Apparently, the MBP will work in clamshell mode only if connected to a display and connected to a The Apple TV remote controller works fine if the lid is o

  • Transfer iweb site to another mac

    My hard drive broke and now I have a new one installed. I would like to download/manage my iweb-mobileme site from this new hard drive. How can I sync the new disc with my mobileme?

  • TS3147 How connect printer to the printer driver in system preference?

    I have an Epson SX600 printer, of which the software can't be found when Apple does the automated thing. However, it is part of the 1.4 gig that you can download from this site. Once unpacked, how does one actually install the driver for the printer?

  • How do you save edits to bookmarks in Adobe 10?

    After editing the bookmarks in a PDF file when the file is saved it appears that the bookmarks revert back to the original text.  Is there a specific way to save these bookmark changes?  Do you need to perform a Save As to capture the bookmark change

  • Downloading HTML data as excel spreadsheets

    I am encountering an issue where tabular HTML data needs to be downloaded onto a user's desktop in MS Excel format. Basically, the download link opens the data in a new JSP, which has the response contentType set to application/vnd.ms-excel. However,