Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Removing OWA2003 access as default

Status
Not open for further replies.

Peepo

Technical User
Dec 20, 2003
32
GB
We have OWA 2003 configured for external access, however, we want to be able to control which users can actually use the service. I'd like to know how OWA access can be disabled by default when creating a new user - and how to disable access for all the current Exchange 2003 users. I realise this will also stop them being able to use OWA from internally, but that is not an issue as all our users use full Outlook client.
We have an Exchange 2003 cluster with an extra server as a Front-end server which is accessed via an ISA 2004 server which is in the DMZ. (Incase you need to know how we have it configured)
Many thanks for anyone who can help with this.
 
The IIS virtual folder /exchange has the everyone group accessing it. Remove this and add in a group called "OWA users". Populate this group.
 
Zelandakh,

I also am interested in doing this but I dont seem to be following your steps.

In IIS, the Exchange virtual folder, I do not know where you are stating 'everyone' group is applied?
 
There's a flag on each user account which specifically allows or denies access to "HTTP". You can find this setting in AD Users & Computers on the user account on the protocols (I think) tab.

Now... If you want to disable all of your users en masse, there's a couple of ways to do this. The easiest being this way:

1) Create a query under save queries. Use the "Exchange Recipients" option from the drop down at the top. The select "users with mailboxes" only from all the checkboxes. This will yield a list of all users with mailboxes.

2) Hit ctrl-a to select all the users in the list. Then right-click on the list and select "Exchange Tasks".

3) Select the change protocol options and select disabled.

4) Select the user who should have access to OWA and re-enable HTTP protocol for them.
******************
After thinking about Zelandakh's comment above, you could modify the NTFS permissions on the ...\Exchsrvr\Exchweb folder on your exchange server. I've never tried this, but you may be able to tweak it so that only users you want to allow can access it through the webserver.

PSC
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top