ISA replacement for Exchange services?

Hi,
Talked to a customer today that still uses ISA server for publishing OWA and ActiveSync for their Exchange 2010 environment.
Is Web Application Proxy within Windows Server 2012 R2 a good replacement?
Not that familiar with the ISA/TMG but is it using pre-auth meaning that the requests from the browser or mobile devices does not hit the Exchange CAS directly but instead is opened on the reverse proxy and then a new connection is made to the CAS?
What are the pros and cons? 
Do one need any other services for OWA/HTTPS and ActiveSync/HTTPS to work? AD FS a requirement?
Multi-factor authentication is not a requirement.

ISA/TMG can use pre-auth, but doesn't need to - it's going to depend on how the proxy is configured.  The con to these is that they are no longer being developed (and I believe they are also out of support).
As for Web Application Proxy, if I was considering it, I'd go straight to the Windows 2012 incarnation of the tool.  It allows useful configurations that aren't available in the Windows 2008 R2 version, and will be supported longer.  That being
said, WAP will support Exchange connections and can replace an ISA server.  Here's a web page with more information on it: 
https://technet.microsoft.com/en-us/library/dn765473.aspx?f=255&MSPPError=-2147217396
As for what services you need, that depends on your organization - if you don't support other services, you don't need to deploy them.

Similar Messages

  • Rollup 5 update for Exchange service pack 3 issues

    Hi,
    I have exchange server 2010 Service pack 3 servers. Planning to install rollup 5 updated for exchange sp3. Anybody faces any issues after installing rollup 5 for exchange sp3...
    Please share...

    When we updated our servers to SP3, we had the choice between going with UR4 and UR5 (which had been released less than a week earlier).  Due to possible issues with UR4 that were fixed in UR5, we went with UR5, and I am glad to say that we have had
    no issues since the update was installed.  We have two DAGs supporting 14,000 mailboxes, with >18 TB of live data, and are running smoothly.

  • Is ISA required for exchange deployment?

    I just read the iphone exchange/enterprise pdfs on apple website and the documentation said that ISA is required for exchange activesync to work. Is this true? Why? What if my company uses another firewall technology? Anyone have any success without ISA?

    Easy...port 80 and port 443. If you force SSL only, then you only need port 443. Open that port up on the firewall.
    Otherwise, you can do port 80 to the OWA server via firewall rule. Although data is sent unencrypted.
    You need a valid SSL cert from one of the major players for SSL to work correctly. People with self-signed internal SSL don't work often.
    ActiveSync is just a Virtual Directory on the Windows Exchange Server under IIS and your Activesync on the phone knows which one it is to navigate to for mail sync and authentication.

  • Looking for exchange service

    I currently have my iPhone configured with a mobile me Account which I have been pleased with for the Most part. The mobile me syncs with the iPhone and a local outlook client on my ms windows desktop. Calendar contacts and mail all work correctly. I am sure you are wondering why I want to switch....let me explain.
    I own my own domain (mydomain.com) all of my mail from here is fwd to my mobile me account. The issue is that my mail provider auto enables a spam filter if u fwd email I don't want this because I obviously have to check my webmail for misplaced spam. In addition to the spam issue I had rather not use the mobile me address at all as I do not feel that it is proff as myeomain.com
    So here is my thought if I can find a online exchage service to host my email from my domain that will support an iPhone sync I van do away with mobile me and just use my domain email addy.
    Now my question. Does anyone currently use a service like this and what are you experiences. Who do you have this service with. Thanks for your help.

    intermedia.net
    I use the exchange 2007 server with 122 users.
    31 Active sync users.
    8 Blackberry users.
    2 good moble users.
    I love it.
    Very easy. never have issues.
    Been a customer for 3 years.
    5 Star service
    My domian is "dwl-usa.com"

  • Is SOA Suite replacement for Oracle Service Bus 10gR3 (10.3.1.0) ?

    I am confused if i have SOA Suite do I need Oracle Service Bus 10gR3 (10.3.1.0) for my ESB ?

    Right now there are eclipse plug-ins for OSB. In a default OSB installation you should have workshop installed with the OSB plug-ins.
    For the next release, OSB 11g, JDeveloper will incorporate these features.

  • Certificates with no Exchange Services assigned - what to do with them?

    In the Exchange Control Panel, I see 6 certificates - 3 are used for Exchange Services, three have no services assigned to them. 
    If we delete these certificates from the ECP, will they also get deleted from the Computer's Personal store, or are they just removed from use for Exchange?
    For the sake of cleaning up the environment, I'd like to remove these certs from the ECP - assuming this removal doesn't delete the cert from the Computer's Personal Store. The certificates are still required on the Exchange Server for other purposes, so
    we don't want them removed from the Personal Store - just removed from Exchange.
    Thoughts?

    They will be deleted from the computer's personal store.  If they are not enabled for any services, Exchange will not use them.
    Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."

  • What is the cost of replacing a battery for an Ipad 2 in India? On asking the service centre, I was informed the entire Ipad would be replaced for 20K which is exorbitant. Is it advisable to buy the Apple protection program in this case?

    What is the cost of replacing a battery for an Ipad 2 in India? On asking the service centre, I was informed the entire Ipad would be replaced for 20K which is exorbitant. The same is done in US for a paltry (comparably) 100 dollars. Is it advisable to buy the Apple protection program in this case?

    Battery Replacement
    http://www.apple.com/batteries/replacements.html

  • Reporting Services through ISA server for All Authenticated Users

    Hello colleagues.
    I have MS SQL 2012 server with Reporting Services and it work via link:
    https://reports2.domain.com/reports
    In LAN all work fine, but I want publish this resource via ISA for All Authenticated Users.
    When in publish rule I configure (in Condition) "All users" - all work fine, but when I configure "All Authenticated Users" - I have trouble on web form on
    https://reports2.domain.com/reports/Pages/Report.aspx?ItemPat...  - scripts not work, because it run how "anonymous" (I see on ISA logging) and ISA block scripts.
    I can't use "All Users", because it's not secure.
    Maybe somebody publish Reporting Services through ISA server for All Authenticated Users?
    OR maybe - how on Reporting Services configure Negotiate authenticated for scripts?

    Hi Alexander,
    All users or applications who request access to report server content or operations must be authenticated using the authentication type configured on the report server before access is allowed. The AuthenticationType named RSWindowsNegotiate is supported
    by Reporting Services. To configure Windows Authentication on the Report Server, please see:
    http://msdn.microsoft.com/en-us/library/cc281253(v=sql.110).aspx
    Besides, we can publish report server via ISA server. Please note that you should use a new web port number with a new listener which shouldn’t be used by other web site for report server. Reference:
    http://social.technet.microsoft.com/Forums/forefront/en-US/1cc68996-1ce6-4d88-a30d-2bfd13fba06e/how-to-publish-ssrs-2008-through-isa-2006?forum=Forefrontedgegeneral
    Hope this helps.
    Thanks,
    Katherine Xiong
    Katherine Xiong
    TechNet Community Support
    Katherine thanks for answer.
    Report Server service started as Domain account.
    I have in RSReportServer.config this:
    <Authentication>
    <AuthenticationTypes>
    <RSWindowsNegotiate />
    </AuthenticationTypes>
    <RSWindowsExtendedProtectionLevel>Allow</RSWindowsExtendedProtectionLevel>
    <RSWindowsExtendedProtectionScenario>Proxy</RSWindowsExtendedProtectionScenario>
    <EnableAuthPersistence>true</EnableAuthPersistence>
    </Authentication>
    In web.config I have this:
    <authentication mode="Windows" />
        <identity impersonate="true" />
    I can go (from Internet through ISA) to
    https://reports2.domain.com/reports  and LogOn Authentication is work, but scripts not work, because it run how "anonymous" (I see this on ISA logging) and ISA block scripts.
    Do you know where in Reporting Services configure run scripts with Negotiate authentication?

  • Microsoft Forefront Server Protection for Exchange Registration Service does not start automatically

    Hello,
    I am having an issue when I start my TMG 2010 machine:
    (*TMG 2010 + Forefront protection for Exchange + Exchange Edge server role, acting like a SMTP relay and Antispam filter)
    The service "Microsoft Forefront Server Protection for Exchange Registration Service"
    does not start, it is set to "Manual".
    I tried to find some information about which services should be started and which should not, but I cannot find such information, not even in Technet (my fault probably).
    Thanks in advance.
    Luis Olías Técnico/Admon Sistemas . Sevilla (España - Spain)

    Hi,
    Have you received any errors in event logs when
    you started the Microsoft Forefront Server Protection for Exchange Registration Service?
    Based on my research,
    Microsoft Forefront Server Protection Controller service is a dependency of the Microsoft Forefront Server Protection Registration service and the Microsoft Forefront
    Server Protection Registration service is a dependency of the Microsoft Exchange Transport service.
    The Microsoft Forefront Server Protection Registration service normally only runs for a brief time (less than a minute) when FPE initializes. It then shuts
    down and does not need to be running for transport scanning to occur.
    You can refer to the link below:
    Services
    Best regards,
    Susie

  • SP1 for Exchange 2013 install fails with ECP virtual directory issues and now transport service won't start and mail is unavailable

    SP1 for Exchange 2013 install failed on me with ECP virtual directory issues:
    Error:
    The following error was generated when "$error.Clear();
              $BEVdirIdentity = $RoleNetBIOSName + "\ecp (name)";
              $be = get-EcpVirtualDirectory -ShowMailboxVirtualDirectories -Identity $BEVdirIdentity -DomainController $RoleDomainController -ErrorAction SilentlyContinue;
              if ($be -eq $null)
              new-EcpVirtualDirectory -Role Mailbox -WebSiteName "name" -DomainController $RoleDomainController;
              set-EcpVirtualdirectory -Identity $BEVdirIdentity -FormsAuthentication:$false -WindowsAuthentication:$true;
              set-EcpVirtualdirectory -Identity $BEVdirIdentity -InternalUrl $null -ExternalUrl $null;
              . "$RoleInstallPath\Scripts\Update-AppPoolManagedFrameworkVersion.ps1" -AppPoolName:"MSExchangeECPAppPool" -Version:"v4.0";
            " was run: "The virtual directory 'ecp' already exists under 'server/name'.
    Parameter name: VirtualDirectoryName".
    Error:
    The following error was generated when "$error.Clear();
              $BEVdirIdentity = $RoleNetBIOSName + "\ECP (name)";
              $be = get-EcpVirtualDirectory -ShowMailboxVirtualDirectories -Identity $BEVdirIdentity -DomainController $RoleDomainController -ErrorAction SilentlyContinue;
              if ($be -eq $null)
              new-EcpVirtualDirectory -Role Mailbox -WebSiteName "name" -DomainController $RoleDomainController;
              set-EcpVirtualdirectory -Identity $BEVdirIdentity -FormsAuthentication:$false -WindowsAuthentication:$true;
              set-EcpVirtualdirectory -Identity $BEVdirIdentity -InternalUrl $null -ExternalUrl $null;
              . "$RoleInstallPath\Scripts\Update-AppPoolManagedFrameworkVersion.ps1" -AppPoolName:"MSExchangeECPAppPool" -Version:"v4.0";
            " was run: "The operation couldn't be performed because object 'server\ECP (name)' couldn't be found on 'DC0xx.domain.com'.".
    Error:
    The following error was generated when "$error.Clear();
              $BEVdirIdentity = $RoleNetBIOSName + "\ECP (name)";
              $be = get-EcpVirtualDirectory -ShowMailboxVirtualDirectories -Identity $BEVdirIdentity -DomainController $RoleDomainController -ErrorAction SilentlyContinue;
              if ($be -eq $null)
              new-EcpVirtualDirectory -Role Mailbox -WebSiteName "name" -DomainController $RoleDomainController;
              set-EcpVirtualdirectory -Identity $BEVdirIdentity -FormsAuthentication:$false -WindowsAuthentication:$true;
              set-EcpVirtualdirectory -Identity $BEVdirIdentity -InternalUrl $null -ExternalUrl $null;
              . "$RoleInstallPath\Scripts\Update-AppPoolManagedFrameworkVersion.ps1" -AppPoolName:"MSExchangeECPAppPool" -Version:"v4.0";
            " was run: "The operation couldn't be performed because object 'server\ECP (name)' couldn't be found on 'DC0xx.domain.com'.".
    !! And now transport service won't start and mail is unavailable !!
    Any help would be appreciated.
    I have removed the ecp site from default site and attempting to rerun SP1 now. I do not have high hopes. :(

    Hi,
    Thanks for your response.
    From the error description, you need to manually remove the ECP with IIS manager in both the Default Web Site and the Exchange Back End firstly. And then continue the upgrade to check the result.
    Hope this can be helpful to you.
    Best regards,
    Amy Wang
    TechNet Community Support

  • Ramifications of assigning a wildcard certificate to the SMTP service (needed for Exchange 2010 Hybrid Configuration - Office 365)

    Hello All:
    I am receiving an error when I run the Manage Hybrid Configuration wizard - ERROR:Updating hybrid configuration failed with error 'Subtask NeedsConfiguration execution failed: Configure Recipient Settings. I have opened a SR, but figured I'd try the forums,
    too. I have a wildcard certificate from GoDaddy (MS says they support wildcards from GoDaddy) & that cert has only the IIS service applied to it on the CAS. I've read in the Exchange Server Deployment Assistant that it should have the SMTP & IIS services
    assigned to it, but my question is - SMTP on the CAS (separate server) or on the Mailbox/Hub Transport (separate server)? And what are the ramifications of assigning the SMTP service to, let's say, the CAS? We have had multiple issues every time the servers
    get updated/changed; I do not want to disrupt services further, as the Manage Hybrid Configuration will be done during business hours.
    If anyone can provide any assistance/clarification, it would be most appreciated.
    Thank you.

    Hi,
    We can enable a Wildcard certificate with SMTP service for Exchange Hybird Deployment. The SMTP service can be assigned to multiple certificates. For some Exchange services such as OWA, Ecp, ActiveSync, Autodiscover service, OOF, it is used with Exchange
    certificate with IIS service. And there is usually only one certificate can be assigned with IIS service.
    Please just make sure your Wildcard certificate can contain all namespaces which are used for all internal URL and External URL configuration in Exchange services. About how to import an existing wildcard certificate on the Exchange 2010 Hybird servers,
    please refer to the Import & Enable Third Party Certificate on Hybrid Servers
    part in the following article:
    http://www.msexchange.org/articles-tutorials/office-365/exchange-online/configuring-exchange-hybrid-deployment-migrating-to-office-365-exchange-online-part9.html
    Note: Microsoft is providing this information as a convenience to you. The sites are not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please
    make sure that you completely understand the risk before retrieving any suggestions from the above link.
    Regards,
    Winnie Liang
    TechNet Community Support

  • Security Update for exchange server 2013SP1 KB3011140 Stops all services and failes to install

    Hi All,
    Over the past 2 days this update has tried to run on the server in the evening but ends up failing. When it fails it is causing all of our exchange services to stop working and when we try to check e-mails the following day we find out the e-mail service
    has been offline since the update.
    Is there anything specific we need to do before running this update?
    Cheers,

    Hi,
    As what Hotaka says, this update is available from
    Windows Update. If it fails, we can also download and install the updates manually. The following stand-alone file is available for download from the Microsoft Download Center:
    Download the security update for Exchange 2013 Service Pack 1 package now.
    Download the security update for Exchange 2013 Cumulative Update 6 package now.
    Regards,
    Winnie Liang
    TechNet Community Support

  • Any known issue reported for "Rollup 8 for Exchange Server 2010 Service Pack 2"

    Hello,
    Currently our servers are running with "Exchange 2010 SP2 RU7", we are planning to update the Rollup version to RU8 for SP2.
    Is there any knows issues reported for "Rollup 8 for Exchange Server 2010 Service Pack 2" till now ? is it safe to update the RU8 ?
    http://www.microsoft.com/en-us/download/details.aspx?id=41394

    (1)  I had to roll it back:
    The rollup released Tuesday the 9th caused random problems with systems ranging from general slow down to operation failed errors.  It didn’t impact everyone at once and seemed to take 48hrs for everyone to have a problem.  Rolling
    back the update and rebooting the server seemed to resolve the issue.
    Issues reported before the general mailflow stopping for everyone:
    Nothing major … an occasional operation failed when I hit send but, it will go thru after I hit the send button a couple of times.
    A MICROSOFT OUTLOOK BOX APPEARS WITH A TRIANGLE WITH A ! INSIDE IT. THE MESSAGE SAYS THE OPERATION FAILED.
    (2)   
    ANOTHER CODE APPEARED WHEN I TRIED TO SEND THIS E-MAIL SO I CLOSED OUTLOOK AND RE-STARTED OUTLOOK. THE MESSAGE READ, CANNOT CREATE THE E-MAIL MESSAGE BECAUSE A DATA FILE TO SEND AND RECEIVE MESSAGE CANNOT BE FOUND. CHECK YOUR SETTINGS IN THIS MICROSOFT
    OUTLOOK PROFILE. IN MICROSOFT WINDOWS, CLICK CONTROL PANEL.CLICK USER ACCOUNTS AND THEN CLICK MAIL. CLICK SHOW PROFILE, AND THEN CLICK PROPERTIES.
    When he tries to open an e-mail, he gets an error message.
    If he tries to mark an e-mail unread, he gets a different message.
    Thanks Ben

  • Error Installing Service Pack 3 for Exchange Server 2010 (Hub Transport)

    I get the following error;
    "[ERROR] Couldn't remove product with code 4934d1ea-be46-48b1-8847-f1af20e892c1. Fatal error during installation. Error code is 1603.
    This is one of two Hub Transport only servers. The Client Access servers upgrade without a problem.
    Thanks,
    Randel

    Hi,
    Based on my research, to remove the error, here is a solution you can refer to:
    1. Run the MsiExec.exe /X {4934d1ea-be46-48b1-8847-f1af20e892c1} to uninstall the Microsoft Full Text Indexing Engine for Exchange.
    2.  Manually start the World Wide Web Publishing Service and IIS Admin Service then run the setup again.
    Thanks,
    Angela Shi
    TechNet Community Support

  • OS X Server fills out wrong PayloadType for Exchange Web Services

    Hi,
    I've noticed a problem with OS X Server, v 3.0.2, when you configure it to setup a user with a Mac OS X Exchange Web Services (EWS) account.
    There is a drop down to choose between iOS (for Exchange Active Sync) or OS X (for Exchange Web Services).
    If you select EWS and fill out the fields, the generated .mobileconfig file has
    PayloadType com.apple.eas.account
    followed by your EWS settings.
    When you install it on the Mac it also reports it as an iOS setting and does not add the account.
    If you manually edit the mobileconfig file, changing PayloadType to
    com.apple.ews.account
    before trying to load it onto the mac, it accepts the EWS account and you can then see it listed in System Preferences->Internet accounts.
    Cheers,
    faz_uk.

    Hi,
    I've noticed a problem with OS X Server, v 3.0.2, when you configure it to setup a user with a Mac OS X Exchange Web Services (EWS) account.
    There is a drop down to choose between iOS (for Exchange Active Sync) or OS X (for Exchange Web Services).
    If you select EWS and fill out the fields, the generated .mobileconfig file has
    PayloadType com.apple.eas.account
    followed by your EWS settings.
    When you install it on the Mac it also reports it as an iOS setting and does not add the account.
    If you manually edit the mobileconfig file, changing PayloadType to
    com.apple.ews.account
    before trying to load it onto the mac, it accepts the EWS account and you can then see it listed in System Preferences->Internet accounts.
    Cheers,
    faz_uk.

Maybe you are looking for

  • Where can I buy install discs for my macbook pro 4,1 ?

    My wife recently was given her old work computer. It was replaced by a brand new 15" MBP Retina. The old one, a 15" MBP 4,1 early 2008 will be given to our daughter. I would like to do a fresh install of the OS and upgrade to stop at Snow Leopard. My

  • How do I get an image background transparent in pages?

    I was wondering how to get the white solid background of an image transparent in pages, keynote has this feature but does pages? I can't seem to find it. Thanks for the help

  • ITunes viewing on iOS4.3 iPad - TV shows

    Hi, can someone help me to see what shows come up in Shared/ my library/ TV Shows? All that is listed is "Season 1" of which there are about 30 and the same for "Season 2" etc. The show names are not given. Can anyone help to show the shows' names?

  • Show Comment & Markup Toolbar automatically with Browser Based Review

    Hi, We have a web-based application which displays PDFs in a browser-window for review using a SOAP collaboration. In all versions of Acrobat prior to v8.2, once the Comment & Markup toolbar was set to show for a PDF in the browser-window - the toolb

  • Oracle XSQL Servlet Page Processor 0.9.9.1 (Technology Preview)

    I trying XSQL Servlet in oracle8.1.6,Java Web Server. When I access http://localhost:8080/xsql/index.html I am getting this error. "Oracle XSQL Servlet Page Processor 0.9.9.1 (Technology Preview) XSQL-013: XSQL Page URI is null or has an invalid form