<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Publishing Exchange 2007 Autodisover in ISA 2006 &#8211; Part 2</title>
	<atom:link href="http://www.shudnow.net/2009/08/05/publishing-exchange-2007-autodisover-in-isa-2006-part-2/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.shudnow.net/2009/08/05/publishing-exchange-2007-autodisover-in-isa-2006-part-2/</link>
	<description>Just another IT guy!</description>
	<lastBuildDate>Fri, 30 Jul 2010 14:25:06 -0600</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Publishing Exchange 2007 Autodisover in ISA 2006 - Persian Networks</title>
		<link>http://www.shudnow.net/2009/08/05/publishing-exchange-2007-autodisover-in-isa-2006-part-2/comment-page-1/#comment-9690</link>
		<dc:creator>Publishing Exchange 2007 Autodisover in ISA 2006 - Persian Networks</dc:creator>
		<pubDate>Thu, 25 Feb 2010 12:12:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1188#comment-9690</guid>
		<description>[...] detail on the different methods you can use to publish Exchange Services including Autodiscover here. In Exchange versions previous to Exchange 2007, users would store data inside a public folder. [...]</description>
		<content:encoded><![CDATA[<p>[...] detail on the different methods you can use to publish Exchange Services including Autodiscover here. In Exchange versions previous to Exchange 2007, users would store data inside a public folder. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: halfluke</title>
		<link>http://www.shudnow.net/2009/08/05/publishing-exchange-2007-autodisover-in-isa-2006-part-2/comment-page-1/#comment-9120</link>
		<dc:creator>halfluke</dc:creator>
		<pubDate>Thu, 10 Dec 2009 20:08:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1188#comment-9120</guid>
		<description>ok, everything is working fine now. I think one of the main issue was that ISA was not joined to any domain and I was using FBA with AD in the listener, now I&#039;ve configured FBA with LDAP. I also removed the anonymous authentication from autodiscover. Now everything works with one rule only, one listener, just adding the autodiscover fqdn to the Public tab in the rule. To tell the truth, I&#039;m using Exchange 2010, not 2007, with all the roles on the same machine, and as I said before, FTMG 2010. OWA is fine as well. Haven&#039;t tried ActiveSync. Happy to share! :) </description>
		<content:encoded><![CDATA[<p>ok, everything is working fine now. I think one of the main issue was that ISA was not joined to any domain and I was using FBA with AD in the listener, now I&#039;ve configured FBA with LDAP. I also removed the anonymous authentication from autodiscover. Now everything works with one rule only, one listener, just adding the autodiscover fqdn to the Public tab in the rule. To tell the truth, I&#039;m using Exchange 2010, not 2007, with all the roles on the same machine, and as I said before, FTMG 2010. OWA is fine as well. Haven&#039;t tried ActiveSync. Happy to share! :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: halfluke</title>
		<link>http://www.shudnow.net/2009/08/05/publishing-exchange-2007-autodisover-in-isa-2006-part-2/comment-page-1/#comment-9104</link>
		<dc:creator>halfluke</dc:creator>
		<pubDate>Thu, 10 Dec 2009 01:37:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1188#comment-9104</guid>
		<description>ok, don-t worry... I&#039;ve just found out I have many other problems along with that one... :-s </description>
		<content:encoded><![CDATA[<p>ok, don-t worry&#8230; I&#039;ve just found out I have many other problems along with that one&#8230; :-s</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: halfluke</title>
		<link>http://www.shudnow.net/2009/08/05/publishing-exchange-2007-autodisover-in-isa-2006-part-2/comment-page-1/#comment-9103</link>
		<dc:creator>halfluke</dc:creator>
		<pubDate>Thu, 10 Dec 2009 00:49:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1188#comment-9103</guid>
		<description>Unfortunately not... 
my config works only with Basic in the authentication delegation and FBA with AD in the listener. 
That way, the autodiscover works, but only AFTER you have created a profile. 
When you create a profile on an external client, you have to use manual settings the first time. 
Then, you can successfully test autodiscover in outlook, download OAB, use OOF etc.. 
In the public name I added autodiscover.domain.com to make it work this way. 
But I can&#039;t find a way to create a new profile with autodiscover... 
any idea? </description>
		<content:encoded><![CDATA[<p>Unfortunately not&#8230;<br />
my config works only with Basic in the authentication delegation and FBA with AD in the listener.<br />
That way, the autodiscover works, but only AFTER you have created a profile.<br />
When you create a profile on an external client, you have to use manual settings the first time.<br />
Then, you can successfully test autodiscover in outlook, download OAB, use OOF etc..<br />
In the public name I added autodiscover.domain.com to make it work this way.<br />
But I can&#039;t find a way to create a new profile with autodiscover&#8230;<br />
any idea?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2009/08/05/publishing-exchange-2007-autodisover-in-isa-2006-part-2/comment-page-1/#comment-9100</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Thu, 10 Dec 2009 00:16:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1188#comment-9100</guid>
		<description>Turn Anonymous off.  I think that may be breaking it. </description>
		<content:encoded><![CDATA[<p>Turn Anonymous off.  I think that may be breaking it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: halfluke</title>
		<link>http://www.shudnow.net/2009/08/05/publishing-exchange-2007-autodisover-in-isa-2006-part-2/comment-page-1/#comment-9099</link>
		<dc:creator>halfluke</dc:creator>
		<pubDate>Wed, 09 Dec 2009 23:46:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1188#comment-9099</guid>
		<description>Hi, 
 
problem here is that when I use the Basic method for Outlook anywhere, and I create a new rule for Autodiscover with the same listener set on FBA, when I want to create a new profile externally, it doesn&#039;t work. 
It keeps prompting me for password 3 times then it fails... 
the new rule has No delegation, but client may authenticate directly. 
In iis autodiscover has anonymous, integrated and basic. 
This is with Forefront threat management gateway 2010, which looks to me almost identical to isa 2006 for this aspect. 
Is it a problem with SAN certificates? Should I request a new certificate to be used for Autodiscover, and create a new Web listener? See here: &lt;a href=&quot;http://www.isaserver.org/tutorials/Publishing-Exchange-2007-Outlook-Autodiscover-2006-ISA-Firewalls.html&quot; target=&quot;_blank&quot;&gt;http://www.isaserver.org/tutorials/Publishing-Exc...&lt;/a&gt; </description>
		<content:encoded><![CDATA[<p>Hi, </p>
<p>problem here is that when I use the Basic method for Outlook anywhere, and I create a new rule for Autodiscover with the same listener set on FBA, when I want to create a new profile externally, it doesn&#039;t work.<br />
It keeps prompting me for password 3 times then it fails&#8230;<br />
the new rule has No delegation, but client may authenticate directly.<br />
In iis autodiscover has anonymous, integrated and basic.<br />
This is with Forefront threat management gateway 2010, which looks to me almost identical to isa 2006 for this aspect.<br />
Is it a problem with SAN certificates? Should I request a new certificate to be used for Autodiscover, and create a new Web listener? See here: <a href="http://www.isaserver.org/tutorials/Publishing-Exchange-2007-Outlook-Autodiscover-2006-ISA-Firewalls.html" target="_blank"></a><a href="http://www.isaserver.org/tutorials/Publishing-Exc.." rel="nofollow">http://www.isaserver.org/tutorials/Publishing-Exc..</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2009/08/05/publishing-exchange-2007-autodisover-in-isa-2006-part-2/comment-page-1/#comment-7848</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Wed, 19 Aug 2009 23:00:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1188#comment-7848</guid>
		<description>Yes, “Bypass Pre-auth” = “No delegation, but client may authenticate directly”</description>
		<content:encoded><![CDATA[<p>Yes, “Bypass Pre-auth” = “No delegation, but client may authenticate directly”</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://www.shudnow.net/2009/08/05/publishing-exchange-2007-autodisover-in-isa-2006-part-2/comment-page-1/#comment-7844</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Wed, 19 Aug 2009 18:36:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1188#comment-7844</guid>
		<description>I&#039;m obviously missing something or mis-understanding something.  I&#039;m missing where you set the &quot;Bypass Pre-auth&quot; piece.  Is this the same as setting &quot;No delegation, but client may authenticate directly&quot;?  Or is it different?

Also, I&#039;m using Basic authentication versus NTLM.</description>
		<content:encoded><![CDATA[<p>I&#8217;m obviously missing something or mis-understanding something.  I&#8217;m missing where you set the &#8220;Bypass Pre-auth&#8221; piece.  Is this the same as setting &#8220;No delegation, but client may authenticate directly&#8221;?  Or is it different?</p>
<p>Also, I&#8217;m using Basic authentication versus NTLM.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Elan Shudnow</title>
		<link>http://www.shudnow.net/2009/08/05/publishing-exchange-2007-autodisover-in-isa-2006-part-2/comment-page-1/#comment-7822</link>
		<dc:creator>Elan Shudnow</dc:creator>
		<pubDate>Tue, 18 Aug 2009 15:29:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1188#comment-7822</guid>
		<description>Adam, when Autodiscover is on its own rule and you set to bypass preauth, you don&#039;t modify the autodiscover virtual directory at all on Exchange.  You&#039;re just telling the client to auth via NTLM directly to the virtual directory.  That&#039;s the entire point.  You still allow NTLM to Autodiscover without ISA being a man in the middle.</description>
		<content:encoded><![CDATA[<p>Adam, when Autodiscover is on its own rule and you set to bypass preauth, you don&#8217;t modify the autodiscover virtual directory at all on Exchange.  You&#8217;re just telling the client to auth via NTLM directly to the virtual directory.  That&#8217;s the entire point.  You still allow NTLM to Autodiscover without ISA being a man in the middle.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://www.shudnow.net/2009/08/05/publishing-exchange-2007-autodisover-in-isa-2006-part-2/comment-page-1/#comment-7803</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Mon, 17 Aug 2009 20:16:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.shudnow.net/?p=1188#comment-7803</guid>
		<description>When you say &quot;I will typically put Autodiscover in its own rule and set that to bypass pre-auth while all other services are not bypassing pre-auth.&quot; under the section about Basic Authentication, are you setting the selection on the Authentication Delegation tab?  If so, are you setting it to &quot;No delegation, but client may authenticate directly&quot; or &quot;No delegation and client cannot authenticate directly&quot;?

Also, if you are choosing the later, do you set the IIS Virtual Directory for AutoDiscover to accept anonymous connections?

Thanks!</description>
		<content:encoded><![CDATA[<p>When you say &#8220;I will typically put Autodiscover in its own rule and set that to bypass pre-auth while all other services are not bypassing pre-auth.&#8221; under the section about Basic Authentication, are you setting the selection on the Authentication Delegation tab?  If so, are you setting it to &#8220;No delegation, but client may authenticate directly&#8221; or &#8220;No delegation and client cannot authenticate directly&#8221;?</p>
<p>Also, if you are choosing the later, do you set the IIS Virtual Directory for AutoDiscover to accept anonymous connections?</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
