<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Inside Entourage by Amir : Microsoft</title><link>http://blogs.technet.com/amir/archive/tags/Microsoft/default.aspx</link><description>Tags: Microsoft</description><dc:language>en</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>How To Setup Exchange 2007 Account Automatically in Entourage 2008 Thru Autodiscover</title><link>http://blogs.technet.com/amir/archive/2009/01/31/how-to-setup-exchange-2007-account-automatically-in-entourage-2008-thru-autodiscover.aspx</link><pubDate>Sat, 31 Jan 2009 18:42:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3195274</guid><dc:creator>amir</dc:creator><slash:comments>12</slash:comments><comments>http://blogs.technet.com/amir/comments/3195274.aspx</comments><wfw:commentRss>http://blogs.technet.com/amir/commentrss.aspx?PostID=3195274</wfw:commentRss><wfw:comment>http://blogs.technet.com/amir/rsscomments.aspx?PostID=3195274</wfw:comment><description>&lt;p&gt;Entourage 2008 with &lt;a href="http://support.microsoft.com/kb/952331"&gt;SP1&lt;/a&gt; can use Autodiscover Service available on Exchange 2007 Server to configure your Exchange account automatically. In this post I will talk about this new feature from Entourage user perspective. I have also recorded a screencast to actually show you how you can do it in Entourage 2008. Please keep in mind that this feature is not available in earlier versions of Entourage (2004 and earlier) &amp;amp; Exchange (2003 &amp;amp; earlier).&lt;/p&gt;  &lt;p&gt;&lt;b&gt;What’s Autodiscover Service?&lt;/b&gt;     &lt;br /&gt;Microsoft Exchange Server 2007 includes a new Microsoft Exchange service named the Autodiscover service. The Autodiscover service configures client computers for Exchange mailbox access that are running Microsoft Office Outlook 2007 or Microsoft Entourage 2008 for Mac. The Autodiscover service can also configure supported mobile devices (Windows Mobile or iPhone). The Autodiscover service provides access to Microsoft Exchange features for Outlook 2007 or Entourage 2008 clients that are connected to your Microsoft Exchange messaging environment. The Autodiscover service must be deployed and configured correctly for Outlook or Entourage clients to automatically connect to Microsoft Exchange features, such as the Availability service (used for Free/Busy info pull-up), OOF Assistant and Delegate management. Additionally, these Exchange features must be configured correctly to provide their respective functionality for Outlook &amp;amp; Entourage clients. You can go &lt;a href="http://technet.microsoft.com/en-us/library/bb124251.aspx"&gt;here&lt;/a&gt; for more info.&lt;/p&gt;  &lt;p&gt;Now a couple of important points:&lt;/p&gt;  &lt;p&gt;&lt;b&gt;1. Entourage Version&lt;/b&gt; – Check to see which version of Entourage you are using. You should be using the latest released version (build), currently its 12.1.5 (081119). In order to check for that, launch Entourage, go to ‘Entourage’ menu on top left hand corner and then click on ‘About Entourage’, the top potion of resulting window should look like this:&lt;/p&gt;  &lt;p&gt;&lt;font size="3"&gt;&lt;font face="Calibri"&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;img title="How To Setup Exchange Account Automatically in Entourage 2008 Thru Autodiscover-1" style="display: block; float: none; margin-left: auto; margin-right: auto" height="169" alt="How To Setup Exchange Account Automatically in Entourage 2008 Thru Autodiscover-1" src="http://erage.members.winisp.net/images/HowToSetupExchange2007AccountAutomatical_8E68/HowToSetupExchangeAccountAutomaticallyinEntourage2008ThruAutodiscover1.png" width="396" /&gt; &lt;/p&gt;  &lt;p&gt;If your version (build) does not match, you need to install all available updates for Office 2008 for Mac. You can do that by going to ‘Help’ menu and clicking on ‘Check for Updates’. ‘Microsoft AutoUpdate’ application will launch and you can then click on ‘Check for Updates’ button there to have it look for all available updates. It will check for released updates, will come back and report to you about them and you can then install them one by one. You can also download and install all updates from &lt;a href="http://www.microsoft.com/mac/downloads.mspx"&gt;Mactopia&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;b&gt;2. Exchange Version&lt;/b&gt; – Check to see which version of Exchange Server is hosting your mailbox. You can do so by logging into your mailbox thru OWA or ‘Outlook Web Access’ (explained in screencast video). Generally organizations publish a website for this purpose, like Microsoft has published this &lt;a href="https://mail.microsoft.com"&gt;website&lt;/a&gt; for its employees to log into their mailboxes thru OWA. You should have one as well, if you don’t know its address or URL, you should talk to your Exchange Server Administrator or IT Help Desk/Support in your organization.&lt;/p&gt;  &lt;p&gt;The very first mention of Exchange Server version can be found on the main login page for OWA, it looks like this if it’s not published thru Microsoft ISA Firewall Server (see ‘Microsoft Exchange’ &amp;amp; ‘2007’ in the screenshot below):&lt;/p&gt;  &lt;p&gt;&lt;font face="Calibri" size="3"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;img title="E2K7 OWA Login Page Mac" style="border-top-width: 0px; display: block; border-left-width: 0px; float: none; border-bottom-width: 0px; margin-left: auto; margin-right: auto; border-right-width: 0px" height="547" alt="E2K7 OWA Login Page Mac" src="http://erage.members.winisp.net/images/HowToSetupExchange2007AccountAutomatical_8E68/E2K7OWALoginPageMac.png" width="504" border="0" /&gt; &lt;/p&gt;  &lt;p&gt;Screencast video also talks about this in the beginning, where OWA has been published thru Microsoft ISA Firewall Server thus the login page looks a bit different. Let’s watch the screencast now.&lt;/p&gt;  &lt;p align="center"&gt;&lt;font face="Calibri" color="#0000ff" size="2"&gt;Make sure you have Microsoft &lt;/font&gt;&lt;a href="http://www.microsoft.com/silverlight/resources/install.aspx"&gt;&lt;font face="Calibri" color="#0000ff" size="2"&gt;Silverlight&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" color="#0000ff" size="2"&gt; installed on your machine.      &lt;br /&gt;This screencast video is recorded in HD (Resolution: 1280x720) with 16:9 Aspect Ratio.       &lt;br /&gt;Please watch it in ‘Full Screen’ mode for better experience.       &lt;br /&gt;To go 'Full Screen', just double click on the video.       &lt;br /&gt;To exit 'Full Screen' mode, double click on video again or press 'Esc' button on your keyboard.&lt;/font&gt;&lt;/p&gt;  &lt;p align="center"&gt;&lt;font face="Calibri" color="#0000ff" size="2"&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p align="center"&gt;&lt;iframe style="width: 550px; height: 390px" src="http://silverlight.services.live.com/invoke/88163/ENT1/iframe.html" frameborder="0" scrolling="no"&gt;&lt;/iframe&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Note&lt;/b&gt;: If you meet the requirements listed above and automatic Exchange account configuration still does not work for you, then it could be because your Exchange Server Administrator has not published Autodiscover Service properly. You should then contact your administrator to verify that. You can provide &lt;a href="http://technet.microsoft.com/en-us/library/bb332063.aspx"&gt;this&lt;/a&gt; link to get him started on that.&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3195274" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/amir/archive/tags/Entourage/default.aspx">Entourage</category><category domain="http://blogs.technet.com/amir/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/amir/archive/tags/Macintosh/default.aspx">Macintosh</category><category domain="http://blogs.technet.com/amir/archive/tags/Exchange/default.aspx">Exchange</category><category domain="http://blogs.technet.com/amir/archive/tags/Entourage+2008/default.aspx">Entourage 2008</category><category domain="http://blogs.technet.com/amir/archive/tags/Feature/default.aspx">Feature</category><category domain="http://blogs.technet.com/amir/archive/tags/Mail/default.aspx">Mail</category><category domain="http://blogs.technet.com/amir/archive/tags/Authentication/default.aspx">Authentication</category><category domain="http://blogs.technet.com/amir/archive/tags/Connectivity/default.aspx">Connectivity</category><category domain="http://blogs.technet.com/amir/archive/tags/Directory+Access/default.aspx">Directory Access</category><category domain="http://blogs.technet.com/amir/archive/tags/Public+Folders/default.aspx">Public Folders</category><category domain="http://blogs.technet.com/amir/archive/tags/WebDAV/default.aspx">WebDAV</category><category domain="http://blogs.technet.com/amir/archive/tags/Exchange+2007/default.aspx">Exchange 2007</category></item><item><title>Client Certificate-based Authentication in Entourage 2008</title><link>http://blogs.technet.com/amir/archive/2008/06/12/client-certificate-based-authentication-in-entourage-2008.aspx</link><pubDate>Fri, 13 Jun 2008 00:46:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3070175</guid><dc:creator>amir</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/amir/comments/3070175.aspx</comments><wfw:commentRss>http://blogs.technet.com/amir/commentrss.aspx?PostID=3070175</wfw:commentRss><wfw:comment>http://blogs.technet.com/amir/rsscomments.aspx?PostID=3070175</wfw:comment><description>&lt;P&gt;&lt;IMG alt="" src="http://erage.members.winisp.net/061208_2145_ClientCerti1.png" align=left mce_src="http://erage.members.winisp.net/061208_2145_ClientCerti1.png"&gt;Recently Microsoft released Service Pack 1 (&lt;A href="http://support.microsoft.com/kb/952331" target=_blank mce_href="http://support.microsoft.com/kb/952331"&gt;SP1&lt;/A&gt;) for Office 2008 for Mac. There are some new features in SP1 for Entourage 2008 users, one of them is 'Client Certificate-based Authentication'. In this post we will walk thru the setup on server &amp;amp; client sides so that it will be helpful to those who want to use this feature in Entourage. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Introduction&lt;/STRONG&gt;&lt;BR&gt;Entourage connects to an Exchange mailbox thru 'Exchange' virtual directory under 'Default Website' in IIS (Internet Information Server) installed on an Exchange Server. IIS provides several authentication methods and they are all discussed &lt;A href="http://msdn.microsoft.com/en-us/library/aa292114(VS.71).aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/aa292114(VS.71).aspx"&gt;here&lt;/A&gt; &amp;amp; &lt;A href="http://technet2.microsoft.com/windowsserver/en/library/e91631b4-e2f9-4e1d-a4c7-522ad74e7a611033.mspx?mfr=true" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/e91631b4-e2f9-4e1d-a4c7-522ad74e7a611033.mspx?mfr=true"&gt;here&lt;/A&gt;. One of them is 'Client Certificate-based Authentication' (CCA) which works thru 'Client Certificate Mapping' on server side. Most conventional ways of authentication require the provision of username, domain &amp;amp; password (3-tier credentials) but CCA does not require users to provide their domain credentials. It works thru a mapping of user certificates to their accounts in Windows Active Directory. It is used where high level of security is required and domain password policies are very strict or administrators simply do not want their users to remember/enter their domain credentials for any kind of access. In those environments '&lt;A href="http://en.wikipedia.org/wiki/Two-factor_authentication" target=_blank mce_href="http://en.wikipedia.org/wiki/Two-factor_authentication"&gt;Two Factor Authentication&lt;/A&gt;' (RSA, Smart Card) is also used &amp;amp; CCA helps in its implementation. Now with the new support for CCA in Entourage, you can have your Entourage users utilize 'Two Factor Authentication' when they connect to their Exchange mailbox. Let's see how we can set it up. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Setup Details&lt;/STRONG&gt;&lt;BR&gt;To keep things simple, I have a single box server with Windows 2003 SP2 &amp;amp; Exchange 2003 SP2 (most common versions out there). It also has 'Certificate &lt;A href="http://technet2.microsoft.com/windowsserver/en/library/d01a80dd-479a-444b-8893-68c40d61dd9c1033.mspx?mfr=true" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/d01a80dd-479a-444b-8893-68c40d61dd9c1033.mspx?mfr=true"&gt;Services&lt;/A&gt;' (a Windows component) installed on it to act as my 'Private Root Certification Authority' (one can go with Public Root CAs like VeriSign, etc.). You can install an '&lt;A href="http://technet2.microsoft.com/windowsserver/en/library/4ffc15cf-f42f-43db-8eb9-fcd8c3102d621033.mspx?mfr=true" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/4ffc15cf-f42f-43db-8eb9-fcd8c3102d621033.mspx?mfr=true"&gt;Enterprise&lt;/A&gt; Root CA' or a '&lt;A href="http://technet2.microsoft.com/windowsserver/en/library/36d03e33-c9e8-4eca-b948-addab1e22c531033.mspx?mfr=true" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/36d03e33-c9e8-4eca-b948-addab1e22c531033.mspx?mfr=true"&gt;Standalone&lt;/A&gt; Root CA' (&lt;A href="http://www.isaserver.org/img/upl/vpnkitbeta2/installstandaloneca.htm" target=_blank mce_href="http://www.isaserver.org/img/upl/vpnkitbeta2/installstandaloneca.htm"&gt;steps&lt;/A&gt; with screenshots), if you want to read more before installation, go &lt;A href="http://technet2.microsoft.com/windowsserver/en/library/9d4e23f7-f72d-48a1-bd17-236eb5de9a8a1033.mspx" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/9d4e23f7-f72d-48a1-bd17-236eb5de9a8a1033.mspx"&gt;here&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;I installed an 'Enterprise Root CA' on my server. I used it to issue an identity certificate to IIS (Default Website) so that secured connections (SSL) can be established over port 443 by Entourage clients when they connect to 'Exchange' virtual directory to get access to their Exchange mailbox. This is a pre-requisite for CCA, steps are &lt;A href="http://technet2.microsoft.com/windowsserver/en/library/87e27bae-a060-4bf9-a4ff-98fbf227cea71033.mspx" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/87e27bae-a060-4bf9-a4ff-98fbf227cea71033.mspx"&gt;here&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;I also used it to issue client certificates to individual Entourage users so that they can use it for CCA when connecting to their Exchange mailbox (more details later in 'Client Side Setup' section below). &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Server Side Setup&lt;/STRONG&gt;&lt;BR&gt;There are several ways to set 'Client Certificate Mapping' on IIS, they are all discussed &lt;A href="http://technet2.microsoft.com/windowsserver/en/library/7b6b8444-e893-4534-9089-dfe860b644a91033.mspx?mfr=true" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/7b6b8444-e893-4534-9089-dfe860b644a91033.mspx?mfr=true"&gt;here&lt;/A&gt;. I used the 'Windows Directory Service Mapper' for my setup, as its most popular &amp;amp; simple to setup. I followed the steps listed &lt;A href="http://technet2.microsoft.com/windowsserver/en/library/7cce4299-28f2-45fa-8730-4e0cbe3be8561033.mspx?mfr=true" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/7cce4299-28f2-45fa-8730-4e0cbe3be8561033.mspx?mfr=true"&gt;here&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;&lt;SPAN style="TEXT-DECORATION: underline"&gt;Note&lt;/SPAN&gt;: I tested this feature successfully with '1-to-1 Mapping' as well, no issues, however I didn't test it with 'Many-to-1 Mapping', I assume that scenario will also work without any issues. &lt;/P&gt;
&lt;P&gt;After that I went to 'Exchange' virtual directory and enabled the requirement of client certificates for authentication. To do that: &lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to IIS Manager : Default Website : Exchange : Properties : Directory Security : Secure Communications : Edit : Check the 2 boxes for 'Require secure channel (SSL)' &amp;amp; 'Require 128 bit encryption' &lt;/LI&gt;
&lt;LI&gt;On the same window, under 'Client certificates' section, select 'Require client certificates' &lt;/LI&gt;
&lt;LI&gt;Also check the box for 'Enable client certificate mapping' &lt;/LI&gt;
&lt;LI&gt;The final configuration will look like &lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/1.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/1.png"&gt;this&lt;/A&gt; &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;That's it, click OK twice to get back to IIS Manager. &lt;/P&gt;
&lt;P&gt;Now when we are set to use CCA for authentication on 'Exchange' virtual directory, we can go and turn off all other authentication methods. To do that, go to IIS : Default Website : Exchange : Properties : Directory Security : Authentication &amp;amp; Access Control : Edit : Uncheck all boxes here (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/2.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/2.png"&gt;screenshot&lt;/A&gt;), click OK twice to get back to IIS Manager. &lt;/P&gt;
&lt;P&gt;Repeat the above steps now for 'Public' virtual directory which is used by Entourage to access public folders on Exchange Server. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Client Side Setup&lt;/STRONG&gt;&lt;BR&gt;To begin with Entourage users should follow these steps for obtaining and installing a user certificate on their Mac. I used a Mac with Tiger (Mac OS 10.4.11) and Entourage 2008 SP1 installed on it. &lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Launch Safari browser and go to &lt;A href="http://%3cserver-name%3e/certsrv" mce_href="http://&lt;server-name&gt;/certsrv"&gt;http://&amp;lt;server-name&amp;gt;/certsrv&lt;/A&gt; (where 'server-name' is the name of the server where 'Private Root CA' is installed) (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/3.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/3.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;Enter your username and password when prompted (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/4.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/4.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;On the 'Welcome' page of your Root CA Server, click on 'Request a certificate' link (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/5.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/5.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;On the 'Request a certificate' page, click on 'User Certificate' link (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/6.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/6.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;On the 'User Certificate – Identifying Information' page, keep the 'Key Strength' field set to '2048 (High Grade)', click on 'Submit' button (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/7.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/7.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;On the 'Certificate Issued' page, click on 'Install this certificate' link (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/8.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/8.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;You will see the 'Downloads' window from Safari and a file by the name of 'certnew.cer' will be downloaded to your desktop (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/9.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/9.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;Double click on the 'certnew.cer' file on your desktop (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/10.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/10.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;The 'Keychain Access' application will launch and you will see the 'Add Certificates' window, keep the 'Keychain' field set to 'login' and click 'OK' (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/11.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/11.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;The user certificate will then be imported in the Keychain (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/12.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/12.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;You can double click on it to view the user certificate (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/13.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/13.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;You can also launch 'Microsoft Cert Manager' application (from Mac Hard Drive : Applications : Microsoft Office 2008 : Office) to view the certificate in 'Digital Identities' &lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/14.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/14.png"&gt;container&lt;/A&gt;. This is a good indication that the user certificate will work fine with CCA or digital signing and encryption of outgoing mail. &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;SPAN style="TEXT-DECORATION: underline"&gt;Quick Admin Check&lt;/SPAN&gt;: Now in order to make sure that Entourage user account is setup properly in Windows Active Directory, take a look at its properties (thru 'Active Directory Users &amp;amp; Computers' or 'ADUC'), you should see the user certificate there under 'Published Certificates' tab (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/15.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/15.png"&gt;screenshot&lt;/A&gt;). If not then you can also import it (use the 'cer' file from user's Mac, see Step 7 above) using the 'Add from file' button there. Another way to add &amp;amp; map user certificate is to do a right click on user object in ADUC, choose 'Name Mappings', then add the user certificate there under 'X.509 Certificates' tab (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/16.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/16.png"&gt;screenshot&lt;/A&gt;). &lt;/P&gt;
&lt;P&gt;Now let's configure Exchange account settings in Entourage, this &lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/17.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/17.png"&gt;screenshot&lt;/A&gt; depicts how 'Account Settings' tab should look like. Note that you do not need to provide user's domain credentials, i.e. username, domain &amp;amp; password. The '&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/18.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/18.png"&gt;Advanced&lt;/A&gt;' tab is where you need to select user certificate under 'Client Certificate-based Authentication' section. Clicking on 'Select' button there will provide you with the 'Choose an Identity' window which will list the user certificate there. That's it, you are done. &lt;/P&gt;
&lt;P&gt;After that Entourage will try to connect to Exchange mailbox utilizing 'Client Certificate-based Authentication', user will see a &lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/19.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/19.png"&gt;prompt&lt;/A&gt; 'Confirm Access to Keychain', choose 'Always Allow' on that. This allows Entourage to access 'Keychain' in Mac OS where user certificate is stored. Entourage will then go and talk to 'Exchange' virtual directory on server. User certificate will be used for CCA and connection to Exchange mailbox will be &lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/20.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/20.png"&gt;established&lt;/A&gt; in seconds. We are done! &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;But What About GAL Access?&lt;/STRONG&gt;&lt;BR&gt;After some research I found that currently it is not possible in Windows Server 2003 to require CCA for LDAP connections &amp;amp; queries. Thus if you want your Entourage users to access your Windows Global Catalog Server (LDAP Server) for 'GAL Access' (Global Address List) feature, you will need to configure it appropriately (non-SSL over ports 3268 &amp;amp; 389 or SSL over ports 3269 &amp;amp; 636) and also provide domain credentials in Exchange account settings in Entourage. Entourage uses the same set of domain credentials provided on first tab (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/21.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/21.png"&gt;screenshot&lt;/A&gt;) for authentication against Exchange &amp;amp; LDAP Server. The authentication processes are separate for IIS (for Exchange mailbox &amp;amp; public folder access) &amp;amp; LDAP Server (for 'GAL Access' feature). If CCA is required for authentication by IIS (at 'Exchange' &amp;amp; 'Public' virtual directories), then Entourage will use client certificate for that and will only use domain credentials for authentication against LDAP Server for 'GAL Access' feature. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Smart Cards&lt;/STRONG&gt;&lt;BR&gt;Some organizations out there use Smart Cards to store user certificate which is generally used by them for digital signing and encryption of outgoing mail. They will continue to work in the same way for CCA feature as well. Just select the same user certificate over &lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/22.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/22.png"&gt;here&lt;/A&gt; as well.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3070175" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/amir/archive/tags/Entourage/default.aspx">Entourage</category><category domain="http://blogs.technet.com/amir/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/amir/archive/tags/Exchange/default.aspx">Exchange</category><category domain="http://blogs.technet.com/amir/archive/tags/Entourage+2008/default.aspx">Entourage 2008</category><category domain="http://blogs.technet.com/amir/archive/tags/Feature/default.aspx">Feature</category></item><item><title>DST Workaround for Entourage 2004 &amp; 2008 Users in ANZ   </title><link>http://blogs.technet.com/amir/archive/2008/03/31/dst-workaround-for-entourage-2004-2008-users-in-anz.aspx</link><pubDate>Tue, 01 Apr 2008 02:12:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3024890</guid><dc:creator>amir</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/amir/comments/3024890.aspx</comments><wfw:commentRss>http://blogs.technet.com/amir/commentrss.aspx?PostID=3024890</wfw:commentRss><wfw:comment>http://blogs.technet.com/amir/rsscomments.aspx?PostID=3024890</wfw:comment><description>&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Update&lt;/U&gt;&lt;/STRONG&gt;: The fixes for this issue have been released in 11.5 (Entourage 2004) &amp;amp; 12.1 (Entourage 2008) Updates for Office for Mac.&lt;/P&gt;
&lt;P&gt;I wanted to quickly provide this workaround to the users of Entourage 2004 &amp;amp; 2008 in Australia &amp;amp; New Zealand (ANZ) time zones until Microsoft releases fixes thru updates at Mactopia website. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue&lt;/STRONG&gt;&lt;BR&gt;When Entourage 2004 &amp;amp; 2008 users organize meetings by inviting other users who are using Microsoft Outlook or OWA (Outlook Web Access) against their Exchange mailboxes (version of Exchange Server does not matter here), then those meeting attendees may see the incoming meeting invite being an hour off. This issue is not seen if all meeting attendees are Entourage users. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cause&lt;/STRONG&gt;&lt;BR&gt;This happens as Entourage 2004 &amp;amp; 2008 use DST information from related 'Timezones' files for users in ANZ time zones, which are not up to date with current information. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;BR&gt;Microsoft is working to release a fix for this issue in an update for both versions of Entourage but a final release date is not available yet. When that update is available, users can safely install it and it will replace the files which they will put on their systems as a result of applying the workaround provided below. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Workaround&lt;/STRONG&gt;&lt;BR&gt;Below are the steps to follow for both versions of Entourage. Only Entourage users will need to apply this workaround on their machines, no action is required by other users who are using Microsoft Outlook or OWA. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Entourage 2004 &lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Quit Entourage (Entourage should not be running when you apply this workaround) &lt;/LI&gt;
&lt;LI&gt;Back up the current 'Timezones' file in folder: Mac Hard Drive : Applications : Microsoft Office 2004 : Office (just copy it to a backup folder on your hard drive) &lt;/LI&gt;
&lt;LI&gt;Download the updated 'Timezones' file for Entourage 2004 from &lt;A href="http://erage.members.winisp.net/Downloads/Timezones-2004.zip" mce_href="http://erage.members.winisp.net/Downloads/Timezones-2004.zip"&gt;here&lt;/A&gt; (extract its content before proceeding to next step) &lt;/LI&gt;
&lt;LI&gt;Copy the downloaded 'Timezones' file to the same location as above in Step 2, replacing the existing 'Timezones' file &lt;/LI&gt;
&lt;LI&gt;That's it, you are done, launch Entourage and every meeting you create now will not display the issue described above &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Entourage 2008 &lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Quit Entourage (Entourage should not be running when you apply this workaround) &lt;/LI&gt;
&lt;LI&gt;Back up the current 'Timezones.ics' file, go to folder: Mac Hard Drive : Applications : Microsoft Office 2008 : Office, locate a file by the name of 'EntourageCore.framework', now Control-Click on it and choose 'Show Package Contents' in the resulting menu, a new window will appear, in that window go to folder: Versions : 12 : Resources : en.lproj (you will find the 'Timezones.ics' file here, just copy it to a backup folder on your hard drive) &lt;/LI&gt;
&lt;LI&gt;Download the updated 'Timezones.ics' file for Entourage 2008 from &lt;A href="http://erage.members.winisp.net/Downloads/Timezones-2008.zip" mce_href="http://erage.members.winisp.net/Downloads/Timezones-2008.zip"&gt;here&lt;/A&gt; (extract its content before proceeding to next step) &lt;/LI&gt;
&lt;LI&gt;Copy the downloaded 'Timezones.ics' file to the same location as above in Step 2, replacing the existing 'Timezones.ics' file &lt;/LI&gt;
&lt;LI&gt;That's it, you are done, launch Entourage and every meeting you create now will not display the issue described above &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;SPAN style="TEXT-DECORATION: underline"&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;/SPAN&gt;: Any meetings which were scheduled earlier and display the issue described in this post will not automatically get fixed. If you want to fix them, you will have to open them and make a change in them (like add one character to its subject/title or notes area, etc.), then save them and send update to all attendees. This change will force Entourage to recalculate DST info as per the updated 'Timezones' file. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Workaround Removal&lt;/STRONG&gt;&lt;BR&gt;If at anytime you may need to remove or undo this workaround, just follow the same steps as above and replace the 'Timezones' files with the original ones which you backed up earlier.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3024890" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/amir/archive/tags/Entourage/default.aspx">Entourage</category><category domain="http://blogs.technet.com/amir/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/amir/archive/tags/Troubleshooting/default.aspx">Troubleshooting</category><category domain="http://blogs.technet.com/amir/archive/tags/Entourage+2008/default.aspx">Entourage 2008</category><category domain="http://blogs.technet.com/amir/archive/tags/Entourage+2004/default.aspx">Entourage 2004</category><category domain="http://blogs.technet.com/amir/archive/tags/Known+Issues/default.aspx">Known Issues</category></item><item><title>DST 2007 Changes &amp; Entourage 2004 for Mac</title><link>http://blogs.technet.com/amir/archive/2007/01/31/dst-2007-changes-entourage-2004-for-mac.aspx</link><pubDate>Wed, 31 Jan 2007 23:05:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:617814</guid><dc:creator>amir</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/amir/comments/617814.aspx</comments><wfw:commentRss>http://blogs.technet.com/amir/commentrss.aspx?PostID=617814</wfw:commentRss><wfw:comment>http://blogs.technet.com/amir/rsscomments.aspx?PostID=617814</wfw:comment><description>&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;I know a lot of users out there use Entourage 2004 as an Exchange Client and are thus concerned about upcoming DST Changes in March 2007. They want to know how Entourage will handle that change and what do they or their Exchange Server Administrators need to do. Here are some important points I wanted to share in this regard.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;1. Earlier in 2006 Apple made changes in its Mac OS X (in 10.4.6 &lt;A href="http://docs.info.apple.com/article.html?artnum=303411" target=_blank mce_href="http://docs.info.apple.com/article.html?artnum=303411"&gt;Update&lt;/A&gt;, look under 'Other' section) so that Mac OS X is aware of new DST 2007 changes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;2. Entourage 2004 at that time wasn't updated/aware of those changes, thus users were seeing the issue as described in KB: &lt;A href="http://support.microsoft.com/kb/924606" target=_blank mce_href="http://support.microsoft.com/kb/924606"&gt;924606&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;3. Microsoft released Office 2004 for Mac 11.3.3 &lt;A href="http://www.microsoft.com/mac/downloads.aspx" target=_blank mce_href="http://www.microsoft.com/mac/downloads.aspx"&gt;Update&lt;/A&gt; (see KB: &lt;A href="http://support.microsoft.com/kb/930402" target=_blank mce_href="http://support.microsoft.com/kb/930402"&gt;930402&lt;/A&gt;) recently to resolve that issue, so now Entourage 2004 is aware of DST 2007 changes, and thus you don't see the issue in KB: 924606.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;4. If you are a consumer level user, who uses Entourage with POP/IMAP/SMTP type of accounts, you are good, issue is taken care of for you, BUT if you will exchange meetings with another user who uses an application to handle meetings which is not up to date or aware of DST 2007 changes then you or that user may still see 'meeting times not correct or off by an hour' issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;5. This same issue will also be experienced by Entourage users who connect to mailboxes on an Exchange server, IF the Exchange server and other users (Entourage and Outlook for Windows) are not updated to be aware of DST 2007 Changes. They can test this right now to confirm this behavior with an Entourage user who has installed 11.3.3 Update and working with other Outlook users who are not updated.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;6. Thus we advise customers to follow the same strategy which is outlined &lt;A href="http://www.microsoft.com/windows/timezone/dst2007.mspx" target=_blank mce_href="http://www.microsoft.com/windows/timezone/dst2007.mspx"&gt;here&lt;/A&gt;, i.e. when they upgrade their other clients using Outlook for Windows (which happens after server upgrade), they can then upgrade Entourage clients as well, i.e. install 11.3.3 Update.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;7. Another important point to keep in mind is that Entourage clients updated with 11.3.3 Update will work fine today but issues will come up only when they interact with clients which are not updated with DST 2007 changes. Thus in order to make sure that everyone works fine, the updates need to happen in suggested manner, i.e. severs first and then clients.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;8. The 11.3.3 Update will make sure that Entourage handles all new meetings which span during the new DST time period properly. For meeting invites sent out prior to the 11.3.3 Update and in the new DST window, Entourage will not send meeting updates to announce the adjusted times. As long as the Outlook attendees apply the upcoming patch and Entourage users are up to date, this should not be an issue. They will all have their events adjusted consistently. For attendees using an application unaware of the new DST rules, the meeting times will be off for these events. Entourage product group will not be releasing any client side Update Tool either like you will have for Outlook for Windows. If you are concerned about this specific issue as this may impact your Entourage users working with other internal and external users, we advise to test and use the Time Zone Update Tools (when they become available). The Exchange server side version specifically would be better in my view. Using that Exchange Server Administrators can then take care of the issue with existing meetings in Entourage users' calendars.&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=617814" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/amir/archive/tags/Entourage/default.aspx">Entourage</category><category domain="http://blogs.technet.com/amir/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/amir/archive/tags/Apple/default.aspx">Apple</category><category domain="http://blogs.technet.com/amir/archive/tags/Macintosh/default.aspx">Macintosh</category><category domain="http://blogs.technet.com/amir/archive/tags/Exchange/default.aspx">Exchange</category><category domain="http://blogs.technet.com/amir/archive/tags/Top+Issues/default.aspx">Top Issues</category></item></channel></rss>