<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Inside Entourage by Amir</title><link>http://blogs.technet.com/b/amir/</link><description>A Blog Focussed on Entourage for Mac &amp;amp; Exchange Server</description><dc:language>en</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>Current Status</title><link>http://blogs.technet.com/b/amir/archive/2009/11/09/current-status.aspx</link><pubDate>Mon, 09 Nov 2009 17:51:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3292501</guid><dc:creator>Amir Haque [MSFT]</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/amir/rsscomments.aspx?WeblogPostID=3292501</wfw:commentRss><comments>http://blogs.technet.com/b/amir/archive/2009/11/09/current-status.aspx#comments</comments><description>&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;Hello Everyone,&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;This blog is not being updated&amp;nbsp;anymore as I have moved to another team (Exchange Product Quality) and job (Program Manager for Exchange CAS) at Microsoft. As you can guess from words in paranthesis, I still work for Exchange but my concentration is not on &lt;A href="http://www.microsoft.com/mac/products/entourage2008" target=_blank mce_href="http://www.microsoft.com/mac/products/entourage2008"&gt;Entourage&lt;/A&gt; or &lt;A href="http://www.officeformac.com/blog/A-New-Outlook-for-Mac-Office" target=_blank mce_href="http://www.officeformac.com/blog/A-New-Outlook-for-Mac-Office"&gt;Outlook for Mac&lt;/A&gt;, rather on &lt;A href="http://technet.microsoft.com/en-us/library/bb124915(EXCHG.140).aspx" target=_blank mce_href="http://technet.microsoft.com/en-us/library/bb124915(EXCHG.140).aspx"&gt;Exchange Client Access Server&lt;/A&gt;.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;Now,&amp;nbsp;if you h&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;ave &lt;STRONG&gt;Questions&lt;/STRONG&gt; &amp;amp; want &lt;STRONG&gt;Answers&lt;/STRONG&gt; from &lt;STRONG&gt;Entourage Experts&lt;/STRONG&gt;, go to &lt;A href="http://www.officeformac.com/ProductForums/Entourage" target=_blank mce_href="http://www.officeformac.com/ProductForums/Entourage"&gt;Entourage Forum&lt;/A&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;If you&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;want to learn more about:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;1. 'Entourage for Mac', head over to:&amp;nbsp;&lt;A href="http://www.entourage.mvps.org/" target=_blank mce_href="http://www.entourage.mvps.org/"&gt;Entourage Help Page&lt;/A&gt;&amp;nbsp;-&amp;nbsp;excellent website maintained by&amp;nbsp;&lt;A href="http://mvp.support.microsoft.com/" target=_blank mce_href="http://mvp.support.microsoft.com"&gt;MVPs&lt;/A&gt;, highly recommended!&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;2. 'Entourage News &amp;amp; Issues', check out:&amp;nbsp;&lt;A href="http://blog.entourage.mvps.org/" target=_blank mce_href="http://blog.entourage.mvps.org"&gt;Entourage Help Blog&lt;/A&gt;&amp;nbsp;-&amp;nbsp;the blog from Entourage MVPs, regularly updated,&amp;nbsp;valuable resource!&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;3. 'Office for Mac', try:&amp;nbsp;&lt;A href="http://www.officeformac.com/blog" target=_blank mce_href="http://www.officeformac.com/blog"&gt;Mac Mojo: Office for Mac Team Blog&lt;/A&gt;&amp;nbsp;- name says it all,&amp;nbsp;source of news &amp;amp; technical info as well!&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;4.&amp;nbsp;'All Things Exchange', you should run to:&amp;nbsp;&lt;A href="http://msexchangeteam.com/" target=_blank mce_href="http://msexchangeteam.com/"&gt;EHLO - Exchange Team Blog&lt;/A&gt;&amp;nbsp;-&amp;nbsp;excellent blog with a wealth of info,&amp;nbsp;one of the first &amp;amp; best in 'blog industry'!&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;All The Best,&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;- Amir&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Lucida Sans Unicode'; mso-ansi-language: EN" lang=EN&gt;11/9/2009&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3292501" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage/">Entourage</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Exchange/">Exchange</category></item><item><title>How To Setup Exchange 2007 Account Automatically in Entourage 2008 Thru Autodiscover</title><link>http://blogs.technet.com/b/amir/archive/2009/01/31/how-to-setup-exchange-2007-account-automatically-in-entourage-2008-thru-autodiscover.aspx</link><pubDate>Sat, 31 Jan 2009 15:42:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3195274</guid><dc:creator>Amir Haque [MSFT]</dc:creator><slash:comments>12</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/amir/rsscomments.aspx?WeblogPostID=3195274</wfw:commentRss><comments>http://blogs.technet.com/b/amir/archive/2009/01/31/how-to-setup-exchange-2007-account-automatically-in-entourage-2008-thru-autodiscover.aspx#comments</comments><description>&lt;P&gt;Entourage 2008 with &lt;A href="http://support.microsoft.com/kb/952331" mce_href="http://support.microsoft.com/kb/952331"&gt;SP1&lt;/A&gt; can use Autodiscover Service available on Exchange 2007 Server to configure your Exchange account automatically. In this post I will talk about this new feature from Entourage user perspective. I have also recorded a screencast to actually show you how you can do it in Entourage 2008. Please keep in mind that this feature is not available in earlier versions of Entourage (2004 and earlier) &amp;amp; Exchange (2003 &amp;amp; earlier).&lt;/P&gt;
&lt;P&gt;&lt;B&gt;What’s Autodiscover Service?&lt;/B&gt; &lt;BR&gt;Microsoft Exchange Server 2007 includes a new Microsoft Exchange service named the Autodiscover service. The Autodiscover service configures client computers for Exchange mailbox access that are running Microsoft Office Outlook 2007 or Microsoft Entourage 2008 for Mac. The Autodiscover service can also configure supported mobile devices (Windows Mobile or iPhone). The Autodiscover service provides access to Microsoft Exchange features for Outlook 2007 or Entourage 2008 clients that are connected to your Microsoft Exchange messaging environment. The Autodiscover service must be deployed and configured correctly for Outlook or Entourage clients to automatically connect to Microsoft Exchange features, such as the Availability service (used for Free/Busy info pull-up), OOF Assistant and Delegate management. Additionally, these Exchange features must be configured correctly to provide their respective functionality for Outlook &amp;amp; Entourage clients. You can go &lt;A href="http://technet.microsoft.com/en-us/library/bb124251.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb124251.aspx"&gt;here&lt;/A&gt; for more info.&lt;/P&gt;
&lt;P&gt;Now a couple of important points:&lt;/P&gt;
&lt;P&gt;&lt;B&gt;1. Entourage Version&lt;/B&gt; – Check to see which version of Entourage you are using. You should be using the latest released version (build), currently its 12.1.5 (081119). In order to check for that, launch Entourage, go to ‘Entourage’ menu on top left hand corner and then click on ‘About Entourage’, the top potion of resulting window should look like this:&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG style="DISPLAY: block; FLOAT: none; MARGIN-LEFT: auto; MARGIN-RIGHT: auto" title="How To Setup Exchange Account Automatically in Entourage 2008 Thru Autodiscover-1" alt="How To Setup Exchange Account Automatically in Entourage 2008 Thru Autodiscover-1" src="http://erage.members.winisp.net/images/HowToSetupExchange2007AccountAutomatical_8E68/HowToSetupExchangeAccountAutomaticallyinEntourage2008ThruAutodiscover1.png" width=396 height=169 mce_src="http://erage.members.winisp.net/images/HowToSetupExchange2007AccountAutomatical_8E68/HowToSetupExchangeAccountAutomaticallyinEntourage2008ThruAutodiscover1.png"&gt; &lt;/P&gt;
&lt;P&gt;If your version (build) does not match, you need to install all available updates for Office 2008 for Mac. You can do that by going to ‘Help’ menu and clicking on ‘Check for Updates’. ‘Microsoft AutoUpdate’ application will launch and you can then click on ‘Check for Updates’ button there to have it look for all available updates. It will check for released updates, will come back and report to you about them and you can then install them one by one. You can also download and install all updates from &lt;A href="http://www.microsoft.com/mac/downloads.mspx" mce_href="http://www.microsoft.com/mac/downloads.mspx"&gt;Mactopia&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;B&gt;2. Exchange Version&lt;/B&gt; – Check to see which version of Exchange Server is hosting your mailbox. You can do so by logging into your mailbox thru OWA or ‘Outlook Web Access’ (explained in screencast video). Generally organizations publish a website for this purpose, like Microsoft has published this &lt;A href="https://mail.microsoft.com/" mce_href="https://mail.microsoft.com"&gt;website&lt;/A&gt; for its employees to log into their mailboxes thru OWA. You should have one as well, if you don’t know its address or URL, you should talk to your Exchange Server Administrator or IT Help Desk/Support in your organization.&lt;/P&gt;
&lt;P&gt;The very first mention of Exchange Server version can be found on the main login page for OWA, it looks like this if it’s not published thru Microsoft ISA Firewall Server (see ‘Microsoft Exchange’ &amp;amp; ‘2007’ in the screenshot below):&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3 face=Calibri&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG style="BORDER-RIGHT-WIDTH: 0px; DISPLAY: block; FLOAT: none; BORDER-TOP-WIDTH: 0px; BORDER-BOTTOM-WIDTH: 0px; MARGIN-LEFT: auto; BORDER-LEFT-WIDTH: 0px; MARGIN-RIGHT: auto" title="E2K7 OWA Login Page Mac" border=0 alt="E2K7 OWA Login Page Mac" src="http://erage.members.winisp.net/images/HowToSetupExchange2007AccountAutomatical_8E68/E2K7OWALoginPageMac.png" width=504 height=547 mce_src="http://erage.members.winisp.net/images/HowToSetupExchange2007AccountAutomatical_8E68/E2K7OWALoginPageMac.png"&gt; &lt;/P&gt;
&lt;P&gt;Screencast video also talks about this in the beginning, where OWA has been published thru Microsoft ISA Firewall Server thus the login page looks a bit different. Let’s watch the screencast now.&lt;/P&gt;
&lt;OBJECT width=560 height=340&gt;&lt;PARAM NAME="movie" VALUE="http://www.youtube.com/v/ZPZL_aNekNg&amp;amp;hl=en_US&amp;amp;fs=1&amp;amp;rel=0&amp;amp;hd=1"&gt;&lt;PARAM NAME="allowFullScreen" VALUE="true"&gt;&lt;PARAM NAME="allowscriptaccess" VALUE="always"&gt;
&lt;embed src="http://www.youtube.com/v/ZPZL_aNekNg&amp;hl=en_US&amp;fs=1&amp;rel=0&amp;hd=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="560" height="340"&gt;&lt;/embed&gt;&lt;/OBJECT&gt;
&lt;P&gt;&lt;B&gt;Note&lt;/B&gt;: If you meet the requirements listed above and automatic Exchange account configuration still does not work for you, then it could be because your Exchange Server Administrator has not published Autodiscover Service properly. You should then contact your administrator to verify that. You can provide &lt;A href="http://technet.microsoft.com/en-us/library/bb332063.aspx" mce_href="http://technet.microsoft.com/en-us/library/bb332063.aspx"&gt;this&lt;/A&gt; link to get him started on that.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3195274" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage/">Entourage</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Microsoft/">Microsoft</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Macintosh/">Macintosh</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Exchange/">Exchange</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage+2008/">Entourage 2008</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Feature/">Feature</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Mail/">Mail</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Authentication/">Authentication</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Connectivity/">Connectivity</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Directory+Access/">Directory Access</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Public+Folders/">Public Folders</category><category domain="http://blogs.technet.com/b/amir/archive/tags/WebDAV/">WebDAV</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Exchange+2007/">Exchange 2007</category></item><item><title>Continued Credentials Prompt in Entourage Connecting to Exchange Mailbox</title><link>http://blogs.technet.com/b/amir/archive/2008/08/11/continued-credentials-prompt-in-entourage-connecting-to-exchange-mailbox.aspx</link><pubDate>Tue, 12 Aug 2008 01:18:04 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3103697</guid><dc:creator>Amir Haque [MSFT]</dc:creator><slash:comments>16</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/amir/rsscomments.aspx?WeblogPostID=3103697</wfw:commentRss><comments>http://blogs.technet.com/b/amir/archive/2008/08/11/continued-credentials-prompt-in-entourage-connecting-to-exchange-mailbox.aspx#comments</comments><description>&lt;p&gt;In this blog I wanted to talk about an issue which we have seen enough number of times working with our enterprise customers that it warrants a blog.
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Issue&lt;/strong&gt;&lt;br/&gt;When connecting to an Exchange mailbox Entourage user sees the following error repeatedly. User enters correct credentials (username, password &amp;amp; domain) but same error comes back again thus effectively entering a never ending loop. We have seen this on all currently &lt;a href="http://support.microsoft.com/gp/lifeselectindex" target="_blank"&gt;supported&lt;/a&gt; versions of Exchange &amp;amp; Entourage. This error can also come up when:
&lt;/p&gt;&lt;p&gt;a. User tries to permanently delete or move a large number of messages from his Exchange mailbox
&lt;/p&gt;&lt;p&gt;b. User tries to send/receive new mail after deleting or moving a large number of messages from his Exchange mailbox
&lt;/p&gt;&lt;p style="text-align: center"&gt;&lt;img src="http://erage.members.winisp.net/081108_2217_ContinuedCr1.png" alt=""/&gt;
	&lt;/p&gt;&lt;p style="text-align: center"&gt;&lt;img src="http://erage.members.winisp.net/081108_2217_ContinuedCr2.png" alt=""/&gt;
	&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Cause&lt;/strong&gt;&lt;br/&gt;When Entourage tries to permanently delete messages from a folder in Exchange mailbox, Exchange Server utilizes the TEMP (temporary) folder for that operation. If Entourage user does not have required permissions on that TEMP folder, server issues a '401, Access Denied' error. Moving messages in Entourage involves permanent deletion from source folder, thus it results in the same issue.
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Resolution&lt;/strong&gt;&lt;br/&gt;There are two parts of it.
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;1. Locating TEMP &amp;amp; TMP Folders
&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;a. Non-Clustered Servers&lt;/strong&gt;&lt;br/&gt;First determine which TEMP folder is set as default on Exchange Mailbox Server on the back-end, cos that's where the delete operation actually takes place. The default location of TEMP folder is set under the following registry key:
&lt;/p&gt;&lt;p&gt;&lt;span style="color:blue"&gt;HKEY_LOCAL_MACHINE\System\CurrrentControlSet\Control\Session Manager\Environment&lt;br/&gt;REG_EXPAND_SZ: TEMP&lt;br/&gt;Value: &amp;lt;PATH&amp;gt;\TEMP
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;By default, the TEMP folder is located at: '%SystemRoot%\TEMP' which is usually 'C:\WINDOWS\TEMP'
&lt;/p&gt;&lt;p&gt;Another place to check this is: Bring up 'Control Panel' on Exchange Server, go to System : Advanced : Environment Variables : System Variables (see the screenshot below) 
&lt;/p&gt;&lt;p style="text-align: center"&gt;&lt;img src="http://erage.members.winisp.net/081108_2217_ContinuedCr3.png" alt=""/&gt;
	&lt;/p&gt;&lt;p&gt;Same check applies for TMP folder, if there is one located on your drive. The above registry key should have an entry for TMP folder as well.
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;b. Clustered Servers&lt;br/&gt;&lt;/strong&gt;On clustered servers, the following registry keys are used to specify the locations of TEMP &amp;amp; TMP folders (&lt;a href="http://technet.microsoft.com/en-us/library/aa998044(EXCHG.80).aspx" target="_blank"&gt;Ref.&lt;/a&gt;).
&lt;/p&gt;&lt;p&gt;&lt;span style="color:blue"&gt;HKEY_USERS\&amp;lt;Cluster service account SID&amp;gt;\Environment\TEMP
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color:blue"&gt;HKEY_USERS\&amp;lt;Cluster service account SID&amp;gt;\Environment\TMP
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;2. Verifying Permissions&lt;/strong&gt;&lt;br/&gt;Now let's verify the permissions assigned on TEMP folder. The 'Authenticated Users' group (Entourage user belongs to this group) should have the following special permissions:
&lt;/p&gt;&lt;p&gt;&lt;span style="color:blue"&gt;Traverse Folder / Execute File&lt;br/&gt;Create Files / Write Data&lt;br/&gt;Create Folders / Append Data
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;In order to check these permissions, locate the TEMP folder and then right click on it to take 'Properties', go to 'Security' tab, highlight 'Authenticated Users', under 'Permissions for Authenticated Users' section, click on 'Advanced' button (see the screenshot below)
&lt;/p&gt;&lt;p style="text-align: center"&gt;&lt;img src="http://erage.members.winisp.net/081108_2217_ContinuedCr4.png" alt=""/&gt;
	&lt;/p&gt;&lt;p&gt;You will then see the 'Advanced Security Settings for TEMP' folder window (see the screenshot below)
&lt;/p&gt;&lt;p style="text-align: center"&gt;&lt;img src="http://erage.members.winisp.net/081108_2217_ContinuedCr5.png" alt=""/&gt;
	&lt;/p&gt;&lt;p&gt;Highlight the entry for 'Authenticated Users' in the above window and then click on 'Edit' button to view/edit the permissions. The screenshot below displays the required permission assigned properly.
&lt;/p&gt;&lt;p style="text-align: center"&gt;&lt;img src="http://erage.members.winisp.net/081108_2217_ContinuedCr6.png" alt=""/&gt;
	&lt;/p&gt;&lt;p&gt;Same check applies for TMP folder, if there is one located on your drive.
&lt;/p&gt;&lt;p&gt;&lt;span style="text-decoration:underline"&gt;Redirected TEMP/TMP Folder&lt;/span&gt;&lt;br/&gt;If the TEMP/TMP folder has been redirected to D (or any other) drive on the Exchange Server, it is suggested to specify the above permissions at the following three levels:
&lt;/p&gt;&lt;p&gt;1. Drive level, especially at the root of drive if you notice that 'Authenticated Users' group is simply missing
&lt;/p&gt;&lt;p&gt;2. TEMP/TMP folder
&lt;/p&gt;&lt;p&gt;3. Any sub-folders inside TEMP folder which may have numerical (like 1, 2, etc.) names as such folders have been seen on clustered servers
&lt;/p&gt;&lt;p&gt;&lt;span style="text-decoration:underline"&gt;Important&lt;/span&gt;&lt;br/&gt;You will need to restart IIS (Internet Information Server) on all those servers where you made these changes in permissions, i.e. mailbox servers on the back-end and front-end servers as well to which Entourage users are connecting for mailbox access.
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More Info&lt;/strong&gt;&lt;br/&gt;If your Entourage users are running into this issue then IIS Log on Exchange Server (front-end and/or back-end) &amp;amp; TCPFlow Log on Entourage Client will show the following:
&lt;/p&gt;&lt;p&gt;a. 'BDELETE' request from client 
&lt;/p&gt;&lt;p&gt;b. '401' error response from server
&lt;/p&gt;&lt;p&gt;&lt;span style="text-decoration:underline"&gt;IIS Trace Sample
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New; font-size:10pt"&gt;&lt;span style="color:#7030a0"&gt;2008-08-10 07:05:33 W3SVC1 192.168.137.121 &lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;BDELETE&lt;/strong&gt;&lt;/span&gt;&lt;span style="color:#7030a0"&gt; /exchange/john/Deleted+Items/ - 80 CONTOSO\JOHN 192.168.120.110 Entourage/12.11.0+(PPC+Mac+OS+X+10.4.9) &lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;401&lt;/strong&gt;&lt;/span&gt;&lt;span style="color:#7030a0"&gt; 5 0
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New; font-size:10pt"&gt;&lt;span style="color:#7030a0"&gt;2008-08-10 07:05:35 W3SVC1 192.168.137.121 &lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;BDELETE&lt;/strong&gt;&lt;/span&gt;&lt;span style="color:#7030a0"&gt; /exchange/john/Deleted+Items/ - 80 CONTOSO\JOHN 192.168.120.110 Entourage/12.11.0+(PPC+Mac+OS+X+10.4.9) &lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;401&lt;/strong&gt;&lt;/span&gt;&lt;span style="color:#7030a0"&gt; 1 0
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="text-decoration:underline"&gt;TCPFlow Trace Sample
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New; font-size:10pt"&gt;&lt;span style="color:#7030a0"&gt;192.168.120.110.54103-192.168.137.121.00080:&lt;br/&gt;&lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;BDELETE&lt;/strong&gt;&lt;/span&gt;&lt;span style="color:#7030a0"&gt; /exchange/john/Deleted%20Items/ HTTP/1.1
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New; font-size:10pt"&gt;&lt;span style="color:#7030a0"&gt;192.168.137.121.00080-192.168.120.110.54103:&lt;br/&gt;HTTP/1.1 &lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;401 Unauthorized&lt;/strong&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3103697" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage/">Entourage</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Exchange/">Exchange</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Troubleshooting/">Troubleshooting</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Known+Issues/">Known Issues</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Mail/">Mail</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Authentication/">Authentication</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Connectivity/">Connectivity</category></item><item><title>E-mail Download Issue in Entourage With Exchange 2007 on Windows 2008</title><link>http://blogs.technet.com/b/amir/archive/2008/08/06/e-mail-download-issue-in-entourage-with-exchange-2007-on-windows-2008.aspx</link><pubDate>Wed, 06 Aug 2008 19:00:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3100753</guid><dc:creator>Amir Haque [MSFT]</dc:creator><slash:comments>5</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/amir/rsscomments.aspx?WeblogPostID=3100753</wfw:commentRss><comments>http://blogs.technet.com/b/amir/archive/2008/08/06/e-mail-download-issue-in-entourage-with-exchange-2007-on-windows-2008.aspx#comments</comments><description>&lt;p&gt;In this blog post I wanted to talk about another new issue being experienced by our customers who are working with Exchange 2007 on Windows 2008. Windows Server 2008 is the key here as it relates to IIS 7 (Internet Information Server) and it's default security restrictions.
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Issue&lt;/strong&gt;&lt;br/&gt;Using Entourage for Mac (2004 or 2008) while connecting to an Exchange 2007 mailbox on a Windows 2008 Server, user cannot download any e-mail message which has a plus sign in it's subject line, like 'Test + Mail'.
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Cause&lt;/strong&gt;&lt;br/&gt;Entourage's request to download this e-mail message goes thru IIS 7 on Windows 2008 Server, which is configured (by default) to deny 'double escape sequences' in any HTTP request and thus it rejects the request with a '404.11' error.
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Resolution&lt;/strong&gt;&lt;br/&gt;As Entourage talks to 'Exchange' virtual directory (for mailbox access) under 'Default Website' on IIS, thus you can use the following procedure to allow the use of 'double escape sequence' &lt;span style="text-decoration:underline"&gt;only&lt;/span&gt; at that level to address this issue. This will minimize the risk you will be taking to enable the usage of double escape sequence. Enabling the use of 'double escape sequence' does carry some risk, please go thru the links below under 'More Info' section to get yourself educated on the issue &amp;amp; involved risks before you work on the steps below.
&lt;/p&gt;&lt;p&gt;&lt;span style="text-decoration:underline"&gt;Quick &amp;amp; Easy Way&lt;/span&gt;&lt;br/&gt;You will need to run this command on all of your Exchange 2007 CAS and Mailbox Servers as IIS is installed on them by default.
&lt;/p&gt;&lt;p&gt;Bring up a Windows 'Command Prompt', type the following command and hit 'Enter' on keyboard, that's it, you are done!
&lt;/p&gt;&lt;p&gt;&lt;span style="color:blue"&gt;%windir%\system32\inetsrv\appcmd set config "http://localhost/Exchange" -section:system.webServer/security/requestfiltering -allowDoubleEscaping:true /commit:apphost
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;You will see the following response after running the above command in the same window.
&lt;/p&gt;&lt;p&gt;&lt;span style="color:blue"&gt;Applied configuration changes to section "system.webServer/security/requestFiltering" for "MACHINE/WEBROOT/APPHOST/Default Web Site/Exchange" at configuration commit path "MACHINE/WEBROOT/APPHOST"
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;After running this command, you don't need to restart any services on server, just run the command and ask your Entourage users to see if the issue has been resolved for them, at the most you can ask them to re-launch Entourage.
&lt;/p&gt;&lt;p&gt;OR if you are a guy who is interested in details, then you can follow the manual steps outlined below.
&lt;/p&gt;&lt;p&gt;&lt;span style="text-decoration:underline"&gt;Manual Steps&lt;/span&gt;&lt;br/&gt;1. Bring up Notepad : File : Open, type &lt;span style="color:blue"&gt;%windir%\System32\inetsrv\config\applicationHost.config&lt;/span&gt; in the 'File name' box, and then click 'Open'.
&lt;/p&gt;&lt;p&gt;2. Locate the section titled as: &lt;span style="color:blue"&gt;&amp;lt;location path="Default Web Site/Exchange"&amp;gt;&lt;/span&gt;
	&lt;/p&gt;&lt;p&gt;3. Under that section locate &lt;span style="color:blue"&gt;&amp;lt;/authentication&amp;gt;&lt;/span&gt; tag
&lt;/p&gt;&lt;p&gt;4. Just after that insert the following text on a new line: &lt;span style="color:blue"&gt;&amp;lt;requestFiltering allowDoubleEscaping="true" /&amp;gt;&lt;/span&gt;
	&lt;/p&gt;&lt;p&gt;5. Save the file and 'Exit' Notepad
&lt;/p&gt;&lt;p&gt;Again, no restart of any service is required.
&lt;/p&gt;&lt;p&gt;Note:&lt;br/&gt;As Entourage talks to 'Public' virtual directory (for public folder access) under 'Default Website' on IIS, thus you will need to follow the same procedure for 'Public' virtual directory as well. Same instructions apply, just replace 'Exchange' with 'Public' in all steps mentioned above.
&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Details&lt;/strong&gt;&lt;br/&gt;Let's go into the details of this issue. First of all let's see how this issue would look like to an Entourage user when he looks at his Inbox thru Outlook Web Access &amp;amp; Entourage.
&lt;/p&gt;&lt;p&gt;Outlook Web Access thru Safari (note the presence of messages with '+' in their subject lines, i.e. 'Movie + Dinner' &amp;amp; 'Test + Message')
&lt;/p&gt;&lt;p&gt;&lt;img src="http://erage.members.winisp.net/080608_1600_EmailDownlo1.png" alt=""/&gt;
	&lt;/p&gt;&lt;p&gt;Entourage 2008 (note the absence of messages with '+' in their subject lines, i.e. 'Movie + Dinner' &amp;amp; 'Test + Message')
&lt;/p&gt;&lt;p&gt;&lt;img src="http://erage.members.winisp.net/080608_1600_EmailDownlo2.png" alt=""/&gt;
	&lt;/p&gt;&lt;p&gt;So how did it happen? Let's review the TCPFlow Trace pasted below, which I took on Entourage user's machine. Important parts are highlighted in red.
&lt;/p&gt;&lt;p&gt;&lt;span style="color:blue"&gt;65.53.65.121 = Entourage Client
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color:blue"&gt;172.30.142.217 = Exchange 2007 CAS Server
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;In the trace snippet pasted below Entourage client is requesting (thru SEARCH command) if there are any changes in user's Inbox, i.e. if there are any new items there for Entourage to retrieve and sync down to its local database.
&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New; font-size:10pt"&gt;&lt;span style="color:#7030a0"&gt;065.053.065.121.51253-172.030.142.217.00080:&lt;br/&gt;&lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;SEARCH /exchange/john/Inbox/ HTTP/1.1&lt;/strong&gt;&lt;/span&gt;&lt;span style="color:#7030a0"&gt;&lt;br/&gt;Host: 172.30.142.217&lt;br/&gt;From: 65.53.65.121&lt;br/&gt;User-Agent: Entourage/12.10.0 (PPC Mac OS X 10.4.9)&lt;br/&gt;Accept: */*&lt;br/&gt;Accept-Language: en&lt;br/&gt;Content-Type: text/xml; charset="utf-8"&lt;br/&gt;Brief: t&lt;br/&gt;Translate: F&lt;br/&gt;Range: Rows=0-512&lt;br/&gt;Cookie: sessionid=7f5d08a5-f5ef-4e36-91e1-8c57c1c2a67f;&lt;br/&gt;cadata="4Soepik9ZpG1ev4w+C87pKQrHkOOeTHX4IiYZdRzhFlUtMQICwpFE3&lt;br/&gt;/xSe3jJmd6QpyBoZI08NwuacKT+wAeWBA==";&lt;br/&gt;OwaLbe={7313483B-4B9B-459B-8EB9-8D0BEE690596}&lt;br/&gt;Content-Length: 743&lt;br/&gt;Accept-Encoding: gzip&lt;br/&gt;Connection: Keep-Alive
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color:#7030a0; font-family:Courier New; font-size:10pt"&gt;065.053.065.121.51253-172.030.142.217.00080:&lt;br/&gt;&amp;lt;?xml version="1.0"?&amp;gt;&amp;lt;D:searchrequestxmlns:D="DAV:"&lt;br/&gt;xmlns:R="&amp;lt;http://schemas.microsoft.com/repl/&amp;gt;"&amp;gt;&lt;br/&gt;&amp;lt;R:repl&amp;gt;&amp;lt;R:collblob&amp;gt;toCTAAMAAQIgzWX+UAA=&amp;lt;/R:collblob&amp;gt;&lt;br/&gt;&amp;lt;/R:repl&amp;gt;&amp;lt;D:sql&amp;gt;SELECT &lt;br/&gt;"&amp;lt;http://schemas.microsoft.com/repl/repl-uid&amp;gt;",&lt;br/&gt;"&amp;lt;http://schemas.microsoft.com/repl/resourcetag&amp;gt;",&lt;br/&gt;"&amp;lt;http://schemas.microsoft.com/mapi/proptag/x001A001F&amp;gt;",&lt;br/&gt;"&amp;lt;http://schemas.microsoft.com/mapi/sensitivity&amp;gt;",&lt;br/&gt;"urn:schemas:httpmail:read", "urn:schemas:httpmail:datereceived"&lt;br/&gt;FROM SCOPE ('SHALLOW TRAVERSAL OF "/exchange/john/Inbox/"')&lt;br/&gt;WHERE "&amp;lt;http://schemas.microsoft.com/mapi/proptag/0x67aa000b&amp;gt;"&lt;br/&gt;= false AND "DAV:isfolder" = false&amp;lt;/D:sql&amp;gt;&amp;lt;/D:searchrequest&amp;gt;
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;And here comes the response from server with the URL of the new item, which is an e-mail with the subject 'Test + Mail' (we are working with only one message to keep things simple) …
&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New; font-size:10pt"&gt;&lt;span style="color:#7030a0"&gt;172.030.142.217.00080-065.053.065.121.51253:&lt;br/&gt;&lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;HTTP/1.1 207 Multi-Status&lt;/strong&gt;&lt;/span&gt;&lt;span style="color:#7030a0"&gt;&lt;br/&gt;Transfer-Encoding: chunked&lt;br/&gt;Content-Type: text/xml&lt;br/&gt;Content-Range: rows 0-0; total=*&lt;br/&gt;Accept-Ranges: rows&lt;br/&gt;Server: Microsoft-IIS/7.0&lt;br/&gt;Set-Cookie: OwaLbe={7313483B-4B9B-459B-8EB9-8D0BEE690596}; path=/&lt;br/&gt;MS-WebStorage: 08.01.10240&lt;br/&gt;MS-WebStorage: 08.01.10240&lt;br/&gt;X-Powered-By: ASP.NET&lt;br/&gt;X-Powered-By: ASP.NET&lt;br/&gt;Date: Fri, 20 Jun 2008 21:46:52 GMT
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New; font-size:10pt"&gt;&lt;span style="color:#7030a0"&gt;172.030.142.217.00080-065.053.065.121.51253:&lt;br/&gt;&amp;lt;?xml version="1.0"?&amp;gt;&amp;lt;a:multistatusxmlns:b="urn:&lt;br/&gt;uuid:c2f41010-65b3-11d1-a29f-00aa00c14882/"&lt;br/&gt;xmlns:g="urn:schemas:httpmail:"&lt;br/&gt;xmlns:f="&amp;lt;http://schemas.microsoft.com/mapi/&amp;gt;" &lt;br/&gt;xmlns:c="xml:" &lt;br/&gt;xmlns:e="&amp;lt;http://schemas.microsoft.com/mapi/proptag/&amp;gt;"&lt;br/&gt;xmlns:d="&amp;lt;http://schemas.microsoft.com/repl/&amp;gt;" &lt;br/&gt;xmlns:a="DAV:"&amp;gt;&amp;lt;a:contentrange&amp;gt;&lt;br/&gt;0-0&amp;lt;/a:contentrange&amp;gt;&amp;lt;a:response&amp;gt;&amp;lt;a:href&amp;gt;&lt;br/&gt;&amp;lt;&lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;http://172.30.142.217/exchange/john/Inbox/Test%20%2B%20Mail.EML&lt;br/&gt;&lt;/strong&gt;&lt;/span&gt;&lt;span style="color:#7030a0"&gt;&amp;lt;/a:href&amp;gt;&amp;lt;d:changetype&amp;gt;new&amp;lt;/d:changetype&amp;gt;&amp;lt;a:propstat&amp;gt;&amp;lt;a:status&amp;gt;&lt;br/&gt;HTTP/1.1&amp;gt; 200 OK&amp;lt;/a:status&amp;gt;&amp;lt;a:prop&amp;gt;&amp;lt;d:repl-uid&amp;gt;&lt;br/&gt;rid:d17078df5926b048921786b466da7185000220cd63ff&lt;br/&gt;&amp;lt;/d:repl-uid&amp;gt;&amp;lt;d:resourcetag&amp;gt;rt:d5926b04892185000220cd728e&lt;br/&gt;&amp;lt;/d:resourcetag&amp;gt;&amp;lt;e:x001A001F&amp;gt;IPM.Note&amp;lt;/e:x001A001F&amp;gt;&lt;br/&gt;&amp;lt;f:sensitivity b:dt="int"&amp;gt;0&amp;lt;/f:sensitivity&amp;gt;&amp;lt;g:readb:dt="boolean"&amp;gt;0&lt;br/&gt;&amp;lt;/g:read&amp;gt;&amp;lt;g:datereceived b:dt="dateTime.tz"&amp;gt;&lt;br/&gt;20080620T21:46:46.895Z&amp;lt;/g:datereceived&amp;gt;&amp;lt;/a:prop&amp;gt;&amp;lt;/a:propstat&amp;gt;&lt;br/&gt;&amp;lt;/a:response&amp;gt;&amp;lt;d:repl&amp;gt;&amp;lt;d:collblob&amp;gt;toaUAABAAYAAiDNY/8A&amp;lt;/d:collblob&amp;gt;&lt;br/&gt;&amp;lt;/d:repl&amp;gt;&amp;lt;/a:multistatus&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;In the snippet below Entourage tries to fetch the new mail message using the URL provided by server …
&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New; font-size:10pt"&gt;&lt;span style="color:#7030a0"&gt;065.053.065.121.51253-172.030.142.217.00080:&lt;br/&gt;&lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;PROPFIND /exchange/john/Inbox/Test%20%2B%20Mail.EML HTTP/1.1&lt;/strong&gt;&lt;/span&gt;&lt;span style="color:#7030a0"&gt;&lt;br/&gt;Host: 172.30.142.217&lt;br/&gt;From: 65.53.65.121&lt;br/&gt;User-Agent: Entourage/12.10.0 (PPC Mac OS X 10.4.9)&lt;br/&gt;Accept: */*&lt;br/&gt;Accept-Language: en&lt;br/&gt;Content-Type: text/xml; charset="utf-8"&lt;br/&gt;Depth: 0&lt;br/&gt;Brief: t&lt;br/&gt;Translate: F&lt;br/&gt;Cookie: sessionid=7f5d08a5-f5ef-4e36-91e1-8c57c1c2a67f;&lt;br/&gt;cadata="4Soepik9ZpG1ev4wJmd6QpyBoZI08NwuacKT+wAeWBA==";&lt;br/&gt;OwaLbe={7313483B-4B9B-459B-8EB9-8D0BEE690596}&lt;br/&gt;Content-Length: 646&lt;br/&gt;Accept-Encoding: gzip&lt;br/&gt;Connection: Keep-Alive
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;And Entourage's receives a 404 error from server for it's request, as IIS7 installed on that Windows 2008 Server (with Exchange 2007) does not allow the use of 'double escape sequence' in any incoming HTTP request.
&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New; font-size:10pt"&gt;&lt;span style="color:#7030a0"&gt;172.030.142.217.00080-065.053.065.121.51253:&lt;br/&gt;&lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;HTTP/1.1 404 Not Found&lt;/strong&gt;&lt;/span&gt;&lt;span style="color:#7030a0"&gt;&lt;br/&gt;Content-Type: text/html&lt;br/&gt;Server: Microsoft-IIS/7.0&lt;br/&gt;X-Powered-By: ASP.NET&lt;br/&gt;Date: Fri, 20 Jun 2008 21:46:52 GMT&lt;br/&gt;Content-Length: 1245&lt;br/&gt;&amp;lt;!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"&lt;br/&gt;"&amp;lt;http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd&amp;gt;"&amp;gt;&lt;br/&gt;&amp;lt;htmlxmlns="&amp;lt;http://www.w3.org/1999/xhtml&amp;gt;"&amp;gt;&lt;br/&gt;&amp;lt;head&amp;gt;&lt;br/&gt;&amp;lt;meta http-equiv="Content-Type" content="text/html;&lt;br/&gt;charset=iso-8859-1"/&amp;gt;&lt;br/&gt;&amp;lt;title&amp;gt;404 - File or directory not found.&amp;lt;/title&amp;gt;&lt;br/&gt;&amp;lt;style type="text/css"&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color:#7030a0; font-family:Courier New; font-size:10pt"&gt;&amp;lt;!--
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color:#7030a0; font-family:Courier New; font-size:10pt"&gt;body{margin:0;font-size:.7em;font-family:Verdana, Arial,&lt;br/&gt;Helvetica, sans-serif;background:#EEEEEE;}&lt;br/&gt;fieldset{padding:0 15px 10px 15px;} &lt;br/&gt;h1{font-size:2.4em;margin:0;color:#FFF;}&lt;br/&gt;h2{font-size:1.7em;margin:0;color:#CC0000;} &lt;br/&gt;h3{font-size:1.2em;margin:10px 0 0 0;color:#000000;} &lt;br/&gt;#header{width:96%;margin:0 0 0 0;padding:6px 2% 6px 2%;&lt;br/&gt;font-family:"trebuchet MS", Verdana, sans-serif;color:#FFF;&lt;br/&gt;background-color:#555555;}&lt;br/&gt;#content{margin:0 0 0 2%;position:relative;}&lt;br/&gt;.content-container{background:#FFF;width:96%;margin-top:8px;&lt;br/&gt;padding:10px;position:relative;}
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="color:#7030a0; font-family:Courier New; font-size:10pt"&gt;--&amp;gt;
&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Courier New; font-size:10pt"&gt;&lt;span style="color:#7030a0"&gt;&amp;lt;/style&amp;gt;&lt;br/&gt;&amp;lt;/head&amp;gt;&lt;br/&gt;&amp;lt;body&amp;gt;&lt;br/&gt;&amp;lt;div id="header"&amp;gt;&amp;lt;h1&amp;gt;Server Error&amp;lt;/h1&amp;gt;&amp;lt;/div&amp;gt;&lt;br/&gt;&amp;lt;div id="content"&amp;gt;&lt;br/&gt;&amp;lt;div class="content-container"&amp;gt;&amp;lt;fieldset&amp;gt;&lt;br/&gt;&amp;lt;h2&amp;gt;&lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;404 - File or directory not found.&lt;/strong&gt;&lt;/span&gt;&lt;span style="color:#7030a0"&gt;&amp;lt;/h2&amp;gt;&lt;br/&gt;&amp;lt;h3&amp;gt;&lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;The resource you are looking for might have been removed,&lt;br/&gt;had its name changed, or is temporarily unavailable.&lt;/strong&gt;&lt;/span&gt;&lt;span style="color:#7030a0"&gt;&amp;lt;/h3&amp;gt;&lt;br/&gt;&amp;lt;/fieldset&amp;gt;&amp;lt;/div&amp;gt;&lt;br/&gt;&amp;lt;/div&amp;gt;&lt;br/&gt;&amp;lt;/body&amp;gt;&lt;br/&gt;&amp;lt;/html&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Now if you look in IIS Log on Exchange 2007 CAS or Mailbox Servers, you will find the following entry there:
&lt;/p&gt;&lt;p&gt;CAS&lt;br/&gt;&lt;span style="font-family:Courier New; font-size:10pt"&gt;&lt;span style="color:#7030a0"&gt;2008-06-20 14:38:09 172.30.142.217 PROPFIND /exchange/john/Inbox/Test+++Mail.EML - 80 - 65.53.65.121 Entourage/12.11.0+(PPC+Mac+OS+X+10.4.9) &lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;404&lt;/strong&gt;&lt;/span&gt;&lt;span style="color:#7030a0"&gt; 11 0 0
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Mailbox&lt;span style="font-family:Courier New; font-size:10pt"&gt;&lt;span style="color:#7030a0"&gt;&lt;br/&gt;2008-06-20 14:38:09 172.30.142.218 PROPFIND /exchange/john/Inbox/Test+++Mail.EML - 80 - 172.30.142.217 Exchange-Server-Frontend-Proxy/6.5+Entourage/12.11.0+(PPC+Mac+OS+X+10.4.9) &lt;/span&gt;&lt;span style="color:red"&gt;&lt;strong&gt;404&lt;/strong&gt;&lt;/span&gt;&lt;span style="color:#7030a0"&gt; 11 0 0
&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;More Info&lt;/strong&gt;&lt;br/&gt;For more info, you can go thru the following links:
&lt;/p&gt;&lt;p&gt;&lt;a href="http://blogs.iis.net/thomad/archive/2007/12/17/iis7-rejecting-urls-containing.aspx" target="_blank"&gt;Blog&lt;/a&gt; : IIS7 Rejecting URLs Containing Plus Sign '+'
&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.owasp.org/index.php/Double_Encoding" target="_blank"&gt;Article&lt;/a&gt; : Double Encoding
&lt;/p&gt;&lt;p&gt;KB &lt;a href="http://support.microsoft.com/kb/942076" target="_blank"&gt;942076&lt;/a&gt; : Error message when you visit a Web site that is hosted on IIS 7.0: "HTTP Error 404.11 – URL_DOUBLE_ESCAPED"
&lt;/p&gt;&lt;p&gt;KB &lt;a href="http://support.microsoft.com/kb/943891" target="_blank"&gt;943891&lt;/a&gt; : The HTTP status codes in IIS 7.0&lt;/p&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3100753" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/amir/archive/tags/Troubleshooting/">Troubleshooting</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Top+Issues/">Top Issues</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage+2008/">Entourage 2008</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage+2004/">Entourage 2004</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Known+Issues/">Known Issues</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Mail/">Mail</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Security/">Security</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Exchange+2007/">Exchange 2007</category></item><item><title>Understanding How You Use This Blog</title><link>http://blogs.technet.com/b/amir/archive/2008/08/05/understanding-how-you-use-this-blog.aspx</link><pubDate>Tue, 05 Aug 2008 21:12:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3099059</guid><dc:creator>Amir Haque [MSFT]</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/amir/rsscomments.aspx?WeblogPostID=3099059</wfw:commentRss><comments>http://blogs.technet.com/b/amir/archive/2008/08/05/understanding-how-you-use-this-blog.aspx#comments</comments><description>&lt;P&gt;Hello Readers,&lt;BR&gt;Here is a guest post from our director who needs your input which will help us in making these blogs better. Thanks for your time! &lt;/P&gt;
&lt;P&gt;--------------------------------------------------------------- &lt;/P&gt;
&lt;P&gt;Greetings Blog Readers,&lt;BR&gt;My name is Ed Jolly, and I am a director in the Commercial Technical Support (CTS) organization at Microsoft. I am here to request a few minutes of your time. &lt;/P&gt;
&lt;P&gt;We would like to learn more about blog readership through a brief survey. This is an opportunity for us to better understand what is valuable to you and what you would like to see in the future. &lt;/P&gt;
&lt;P&gt;Below is a link that will take you to another website to complete the survey. Based on what we learn, we may request more feedback in future surveys like this. When you open the survey, you will see a list of blogs that CTS engineers contribute to across many different products. We have not posted a listing of these blogs in the past, and I hope it helps you find other blogs that are helpful to you. &lt;/P&gt;
&lt;P&gt;The blog survey is completely anonymous. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Location&lt;/STRONG&gt;:&amp;nbsp;&amp;lt; Survey Period Expired, Link Removed &amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Availability&lt;/STRONG&gt;: Until August 22. You may receive a request to complete this survey through multiple RSS feeds. You need only to complete it one time. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Length&lt;/STRONG&gt;: The survey can be a maximum of 11 questions. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Time&lt;/STRONG&gt;: Less than 5 minutes (but providing more information in the open text fields may take a minute or two extra, improving our ability to understand your needs in these blogs). &lt;/P&gt;
&lt;P&gt;Thank you in advance for your time, participation and assistance. &lt;/P&gt;
&lt;P&gt;Ed Jolly (edjolly@microsoft.com)&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3099059" width="1" height="1"&gt;</description></item><item><title>Parts of Hyperlink After Ampersand Sign Are Stripped in Entourage 2008</title><link>http://blogs.technet.com/b/amir/archive/2008/07/17/parts-of-hyperlink-after-ampersand-sign-are-stripped-in-entourage-2008.aspx</link><pubDate>Thu, 17 Jul 2008 18:34:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3090205</guid><dc:creator>Amir Haque [MSFT]</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/amir/rsscomments.aspx?WeblogPostID=3090205</wfw:commentRss><comments>http://blogs.technet.com/b/amir/archive/2008/07/17/parts-of-hyperlink-after-ampersand-sign-are-stripped-in-entourage-2008.aspx#comments</comments><description>&lt;P&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: blue; LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;&lt;STRONG&gt;&lt;U&gt;Update&lt;/U&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 11pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;: The fix for this issue has been &lt;A href="http://www.microsoft.com/mac/downloads.mspx" target=_blank&gt;&lt;FONT color=#800080&gt;released&lt;/FONT&gt;&lt;/A&gt; in the 12.1.2 Update for Office 2008 for Mac.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is another known issue we are working to fix these days. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue&lt;/STRONG&gt;&lt;BR&gt;Entourage 2008 users are reporting that it is stripping parts of hyperlinks (URLs) in messages they receive from other users. It always strips parts of those hyperlinks right after '&amp;amp;', including the ampersand sign. This is only being reported by those users who have recently upgraded to Office 2008 for Mac Service Pack 1 (&lt;A href="http://support.microsoft.com/kb/952331" target=_blank mce_href="http://support.microsoft.com/kb/952331"&gt;SP1&lt;/A&gt;). Examples of stripped URLs are: &lt;/P&gt;
&lt;P&gt;Original Link:&lt;BR&gt;https://www.contoso.com/dept/sales/abc.php?ABCD=0987654321&amp;amp;UID=987612345 &lt;/P&gt;
&lt;P&gt;Stripped Link:&lt;BR&gt;https://www.contoso.com/dept/sales/abc.php?ABCD=0987654321=987612345 &lt;/P&gt;
&lt;P&gt;&lt;SPAN style="TEXT-DECORATION: underline"&gt;Note&lt;/SPAN&gt; that '&amp;amp;UID' has been stripped &lt;/P&gt;
&lt;P&gt;Original Link:&lt;BR&gt;https://www.litwareinc.com/EntApp/ViewMsg.asp?MsgID=897&amp;amp;SaveID=7843~2945 &lt;/P&gt;
&lt;P&gt;Stripped Link:&lt;BR&gt;https://www.litwareinc.com/EntApp/ViewMsg.asp?MsgID=897=7843~2945 &lt;/P&gt;
&lt;P&gt;&lt;SPAN style="TEXT-DECORATION: underline"&gt;Note&lt;/SPAN&gt; that '&amp;amp;SaveCaseID' has been stripped &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cause&lt;/STRONG&gt;&lt;BR&gt;This happens as '&amp;amp;' is not properly encoded as '&amp;amp;amp' in the message source &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;BR&gt;Microsoft is working to release a fix for this issue in an update for Entourage 2008 but a final release date is not available yet. I plan to update this post with new information in this regard when it becomes available.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3090205" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage/">Entourage</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Troubleshooting/">Troubleshooting</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage+2008/">Entourage 2008</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Known+Issues/">Known Issues</category></item><item><title>SSL Warning Issue in Entourage 2008</title><link>http://blogs.technet.com/b/amir/archive/2008/07/16/ssl-warning-issue-in-entourage-2008.aspx</link><pubDate>Thu, 17 Jul 2008 00:15:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3089847</guid><dc:creator>Amir Haque [MSFT]</dc:creator><slash:comments>24</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/amir/rsscomments.aspx?WeblogPostID=3089847</wfw:commentRss><comments>http://blogs.technet.com/b/amir/archive/2008/07/16/ssl-warning-issue-in-entourage-2008.aspx#comments</comments><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: blue; LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;&lt;STRONG&gt;&lt;U&gt;Update 1&lt;/U&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 11pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;: The fix for this issue has been &lt;A href="http://www.microsoft.com/mac/downloads.mspx" target=_blank&gt;&lt;FONT color=#800080&gt;released&lt;/FONT&gt;&lt;/A&gt; in the 12.1.2 Update for Office 2008 for Mac. See 'Improvements for Microsoft Entourage 2008 for Mac' section in KB &lt;A class="" href="http://support.microsoft.com/kb/956344" target=_blank mce_href="http://support.microsoft.com/kb/956344"&gt;956344&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="FONT-SIZE: 11pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;&lt;SPAN style="FONT-SIZE: 11pt; COLOR: blue; LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;&lt;STRONG&gt;&lt;U&gt;Update 2&lt;/U&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 11pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: 'Times New Roman'; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;: The fix for a subsequent 'CNAME' entry&amp;nbsp;issue discussed in the comments section of this blog post has been &lt;A href="http://www.microsoft.com/mac/downloads.mspx" target=_blank&gt;&lt;FONT color=#800080&gt;released&lt;/FONT&gt;&lt;/A&gt; in the 12.1.3 Update for Office 2008 for Mac. See 'Improvements for Microsoft Entourage 2008 for Mac' section in KB &lt;A class="" href="http://support.microsoft.com/kb/958267" target=_blank mce_href="http://support.microsoft.com/kb/958267"&gt;958267&lt;/A&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;In this post I wanted to quickly provide an update on an ongoing issue with some specifics to make sure our customers are well informed on its current status. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue&lt;/STRONG&gt;&lt;BR&gt;After installing Office 2008 for Mac Service Pack 1 (&lt;A href="http://support.microsoft.com/kb/952331" target=_blank mce_href="http://support.microsoft.com/kb/952331"&gt;SP1&lt;/A&gt;) when Entourage 2008 users connect to their mailbox on an Exchange 2007 Server, they may see an error like this (you can substitute 'contoso' in the screenshot below with your own root domain): &lt;/P&gt;
&lt;P style="TEXT-ALIGN: center"&gt;&lt;IMG alt="" src="http://erage.members.winisp.net/071608_2114_SSLWarningI1.png" mce_src="http://erage.members.winisp.net/071608_2114_SSLWarningI1.png"&gt; &lt;/P&gt;
&lt;P&gt;If you click on 'OK', Entourage will continue to work and you won't see this error message again until the end of that session when you close Entourage. Clicking on 'Cancel' you may end up in 'Not Connected' state with your Exchange account. This error may also come up when: &lt;/P&gt;
&lt;P&gt;1. You try to configure your Exchange account using 'Account Setup Assistant' which now uses Autodiscover Service on Exchange 2007 to automatically configure your account &lt;SPAN style="TEXT-DECORATION: underline"&gt;or&lt;/SPAN&gt; &lt;/P&gt;
&lt;P&gt;2. You use any 'Exchange Web Services' based feature in Entourage 2008, like OOF Assistant, Free/Busy Info pull-up, etc. as they also utilize Autodiscover feature &lt;SPAN style="TEXT-DECORATION: underline"&gt;or&lt;/SPAN&gt; &lt;/P&gt;
&lt;P&gt;3. Entourage tries to talk to Autodiscover Service while its running connected to your mailbox to see if any updates were made to Autodiscover Service on server side by your Exchange Administrator, this happens automatically in the background based on a pre-set interval which cannot be modified by user &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cause&lt;/STRONG&gt;&lt;BR&gt;This happens as Entourage 2008 tries to establish a secured connection to the first of the 2 default addresses (URLs) in its attempt to contact the Autodiscover Service on your Exchange 2007 Server. This is explained in the Autodiscover &lt;A href="http://technet.microsoft.com/en-us/library/bb332063(EXCHG.80).aspx" target=_blank mce_href="http://technet.microsoft.com/en-us/library/bb332063(EXCHG.80).aspx"&gt;Whitepaper&lt;/A&gt;, see 'How the Autodiscover Service Works with Clients' section. Most organizations using Exchange 2007 do not publish Autodiscover Service thru the first URL mentioned over there, i.e. 'https://contoso.com/autodiscover/autodiscover.xml', rather they use the other URL, i.e. 'https://autodiscover.contoso.com/autodiscover/autodiscover.xml'. When Entourage finds an error (mostly its 'Common Name' mismatch) with the certificate published at the root of your domain (if there is one, many organizations do, but 'Common Name' on that certificate is 'www.contoso.com', not just 'contoso.com' and Autodiscover Service is not published thru that URL), it displays the above error. It does not move silently to try the other possible URL. Clicking 'OK' on above error makes it exactly do that and thus it finds the Autodiscover Service responding on the other URL and everything then works fine from there. &lt;/P&gt;
&lt;P&gt;This issue can also happen in Entourage 2008 if Autodiscover Service is not configured properly as per the guidelines in Autodiscover &lt;A href="http://technet.microsoft.com/en-us/library/bb332063(EXCHG.80).aspx" target=_blank mce_href="http://technet.microsoft.com/en-us/library/bb332063(EXCHG.80).aspx"&gt;Whitepaper&lt;/A&gt;. See 'Note' below on how to quickly check to see if Autodiscover Service is properly configured and published for users. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;BR&gt;Microsoft is working to release a fix for this issue in an update for Entourage 2008 but a final release date is not available yet. I plan to update this post with new information in this regard when it becomes available. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;BR&gt;We need to make sure that when Entourage looks for Autodiscover Service, the related URL as mentioned above in 'Cause' section is configured and published to respond to those requests. A quick way is to look up the A Record (a type of DNS record which is used to map a hostname or URL to the IP Address of the host) which you will have to register with your DNS provider. &lt;/P&gt;
&lt;P&gt;A Working Example:&lt;BR&gt;For Microsoft, the Autodiscover Service is configured and published at 'https://autodiscover.microsoft.com/autodiscover/autodiscover.xml', you can look it up using this URL in your browser: &lt;/P&gt;
&lt;P&gt;&lt;A href="http://codeflux.com/exec/tools/?method=nslookup&amp;amp;query=autodiscover.microsoft.com&amp;amp;type=A" mce_href="http://codeflux.com/exec/tools/?method=nslookup&amp;amp;query=autodiscover.microsoft.com&amp;amp;type=A"&gt;http://codeflux.com/exec/tools/?method=nslookup&amp;amp;query=autodiscover.microsoft.com&amp;amp;type=A&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;You will see an IP Address is mapped to the URL for Autodiscover Service to respond to incoming requests. &lt;/P&gt;
&lt;P&gt;Now, if I go and hit the URL for Autodiscover Service in my browser, i.e. 'https://autodiscover.microsoft.com/autodiscover/autodiscover.xml' &lt;/P&gt;
&lt;P&gt;I will get a window to enter my user credentials (domain\username &amp;amp; password) and after that I will see the following lines in the main browser window: &lt;/P&gt;
&lt;P&gt;&lt;SPAN style="COLOR: #009900"&gt;&amp;lt;?xml version="1.0" encoding="utf-8" ?&amp;gt; &lt;BR&gt;- &amp;lt;Autodiscover xmlns="http://schemas.microsoft.com/exchange/autodiscover/responseschema/2006"&amp;gt;&lt;BR&gt;- &amp;lt;Response&amp;gt;&lt;BR&gt;- &amp;lt;Error Time="10:29:57.7332076" Id="59171512"&amp;gt;&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;ErrorCode&amp;gt;600&amp;lt;/ErrorCode&amp;gt;&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;Message&amp;gt;Invalid Request&amp;lt;/Message&amp;gt;&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;DebugData /&amp;gt;&lt;BR&gt;&amp;lt;/Error&amp;gt;&lt;BR&gt;&amp;lt;/Response&amp;gt;&lt;BR&gt;&amp;lt;/Autodiscover&amp;gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The response above says 'Error 600, Invalid Request' as the Autodiscover Service URL is not supposed to be accessed thru a browser. This is an expected response in this scenario and confirms the proper configuration and publishing of Autodiscover Service. &lt;/P&gt;
&lt;P&gt;A Non-Working Example:&lt;BR&gt;Let's use Contoso as a non-working example, the Autodisover Service should be configured and published at 'https://autodiscover.contoso.com/autodiscover/autodiscover.xml', if you look it up using this URL in your browser: &lt;/P&gt;
&lt;P&gt;&lt;A href="http://codeflux.com/exec/tools/?method=nslookup&amp;amp;query=autodiscover.contoso.com&amp;amp;type=A" mce_href="http://codeflux.com/exec/tools/?method=nslookup&amp;amp;query=autodiscover.contoso.com&amp;amp;type=A"&gt;http://codeflux.com/exec/tools/?method=nslookup&amp;amp;query=autodiscover.contoso.com&amp;amp;type=A&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;You won't find an IP Address mapped to the URL for Autodiscover Service, instead you will see an error there saying 'server can't find autodiscover.contoso.com'.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3089847" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/amir/archive/tags/Troubleshooting/">Troubleshooting</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage+2008/">Entourage 2008</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Known+Issues/">Known Issues</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Exchange+2007/">Exchange 2007</category></item><item><title>Client Certificate-based Authentication in Entourage 2008</title><link>http://blogs.technet.com/b/amir/archive/2008/06/12/client-certificate-based-authentication-in-entourage-2008.aspx</link><pubDate>Fri, 13 Jun 2008 00:46:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3070175</guid><dc:creator>Amir Haque [MSFT]</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/amir/rsscomments.aspx?WeblogPostID=3070175</wfw:commentRss><comments>http://blogs.technet.com/b/amir/archive/2008/06/12/client-certificate-based-authentication-in-entourage-2008.aspx#comments</comments><description>&lt;P&gt;&lt;IMG alt="" src="http://erage.members.winisp.net/061208_2145_ClientCerti1.png" align=left mce_src="http://erage.members.winisp.net/061208_2145_ClientCerti1.png"&gt;Recently Microsoft released Service Pack 1 (&lt;A href="http://support.microsoft.com/kb/952331" target=_blank mce_href="http://support.microsoft.com/kb/952331"&gt;SP1&lt;/A&gt;) for Office 2008 for Mac. There are some new features in SP1 for Entourage 2008 users, one of them is 'Client Certificate-based Authentication'. In this post we will walk thru the setup on server &amp;amp; client sides so that it will be helpful to those who want to use this feature in Entourage. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Introduction&lt;/STRONG&gt;&lt;BR&gt;Entourage connects to an Exchange mailbox thru 'Exchange' virtual directory under 'Default Website' in IIS (Internet Information Server) installed on an Exchange Server. IIS provides several authentication methods and they are all discussed &lt;A href="http://msdn.microsoft.com/en-us/library/aa292114(VS.71).aspx" target=_blank mce_href="http://msdn.microsoft.com/en-us/library/aa292114(VS.71).aspx"&gt;here&lt;/A&gt; &amp;amp; &lt;A href="http://technet2.microsoft.com/windowsserver/en/library/e91631b4-e2f9-4e1d-a4c7-522ad74e7a611033.mspx?mfr=true" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/e91631b4-e2f9-4e1d-a4c7-522ad74e7a611033.mspx?mfr=true"&gt;here&lt;/A&gt;. One of them is 'Client Certificate-based Authentication' (CCA) which works thru 'Client Certificate Mapping' on server side. Most conventional ways of authentication require the provision of username, domain &amp;amp; password (3-tier credentials) but CCA does not require users to provide their domain credentials. It works thru a mapping of user certificates to their accounts in Windows Active Directory. It is used where high level of security is required and domain password policies are very strict or administrators simply do not want their users to remember/enter their domain credentials for any kind of access. In those environments '&lt;A href="http://en.wikipedia.org/wiki/Two-factor_authentication" target=_blank mce_href="http://en.wikipedia.org/wiki/Two-factor_authentication"&gt;Two Factor Authentication&lt;/A&gt;' (RSA, Smart Card) is also used &amp;amp; CCA helps in its implementation. Now with the new support for CCA in Entourage, you can have your Entourage users utilize 'Two Factor Authentication' when they connect to their Exchange mailbox. Let's see how we can set it up. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Setup Details&lt;/STRONG&gt;&lt;BR&gt;To keep things simple, I have a single box server with Windows 2003 SP2 &amp;amp; Exchange 2003 SP2 (most common versions out there). It also has 'Certificate &lt;A href="http://technet2.microsoft.com/windowsserver/en/library/d01a80dd-479a-444b-8893-68c40d61dd9c1033.mspx?mfr=true" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/d01a80dd-479a-444b-8893-68c40d61dd9c1033.mspx?mfr=true"&gt;Services&lt;/A&gt;' (a Windows component) installed on it to act as my 'Private Root Certification Authority' (one can go with Public Root CAs like VeriSign, etc.). You can install an '&lt;A href="http://technet2.microsoft.com/windowsserver/en/library/4ffc15cf-f42f-43db-8eb9-fcd8c3102d621033.mspx?mfr=true" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/4ffc15cf-f42f-43db-8eb9-fcd8c3102d621033.mspx?mfr=true"&gt;Enterprise&lt;/A&gt; Root CA' or a '&lt;A href="http://technet2.microsoft.com/windowsserver/en/library/36d03e33-c9e8-4eca-b948-addab1e22c531033.mspx?mfr=true" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/36d03e33-c9e8-4eca-b948-addab1e22c531033.mspx?mfr=true"&gt;Standalone&lt;/A&gt; Root CA' (&lt;A href="http://www.isaserver.org/img/upl/vpnkitbeta2/installstandaloneca.htm" target=_blank mce_href="http://www.isaserver.org/img/upl/vpnkitbeta2/installstandaloneca.htm"&gt;steps&lt;/A&gt; with screenshots), if you want to read more before installation, go &lt;A href="http://technet2.microsoft.com/windowsserver/en/library/9d4e23f7-f72d-48a1-bd17-236eb5de9a8a1033.mspx" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/9d4e23f7-f72d-48a1-bd17-236eb5de9a8a1033.mspx"&gt;here&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;I installed an 'Enterprise Root CA' on my server. I used it to issue an identity certificate to IIS (Default Website) so that secured connections (SSL) can be established over port 443 by Entourage clients when they connect to 'Exchange' virtual directory to get access to their Exchange mailbox. This is a pre-requisite for CCA, steps are &lt;A href="http://technet2.microsoft.com/windowsserver/en/library/87e27bae-a060-4bf9-a4ff-98fbf227cea71033.mspx" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/87e27bae-a060-4bf9-a4ff-98fbf227cea71033.mspx"&gt;here&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;I also used it to issue client certificates to individual Entourage users so that they can use it for CCA when connecting to their Exchange mailbox (more details later in 'Client Side Setup' section below). &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Server Side Setup&lt;/STRONG&gt;&lt;BR&gt;There are several ways to set 'Client Certificate Mapping' on IIS, they are all discussed &lt;A href="http://technet2.microsoft.com/windowsserver/en/library/7b6b8444-e893-4534-9089-dfe860b644a91033.mspx?mfr=true" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/7b6b8444-e893-4534-9089-dfe860b644a91033.mspx?mfr=true"&gt;here&lt;/A&gt;. I used the 'Windows Directory Service Mapper' for my setup, as its most popular &amp;amp; simple to setup. I followed the steps listed &lt;A href="http://technet2.microsoft.com/windowsserver/en/library/7cce4299-28f2-45fa-8730-4e0cbe3be8561033.mspx?mfr=true" target=_blank mce_href="http://technet2.microsoft.com/windowsserver/en/library/7cce4299-28f2-45fa-8730-4e0cbe3be8561033.mspx?mfr=true"&gt;here&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;&lt;SPAN style="TEXT-DECORATION: underline"&gt;Note&lt;/SPAN&gt;: I tested this feature successfully with '1-to-1 Mapping' as well, no issues, however I didn't test it with 'Many-to-1 Mapping', I assume that scenario will also work without any issues. &lt;/P&gt;
&lt;P&gt;After that I went to 'Exchange' virtual directory and enabled the requirement of client certificates for authentication. To do that: &lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to IIS Manager : Default Website : Exchange : Properties : Directory Security : Secure Communications : Edit : Check the 2 boxes for 'Require secure channel (SSL)' &amp;amp; 'Require 128 bit encryption' &lt;/LI&gt;
&lt;LI&gt;On the same window, under 'Client certificates' section, select 'Require client certificates' &lt;/LI&gt;
&lt;LI&gt;Also check the box for 'Enable client certificate mapping' &lt;/LI&gt;
&lt;LI&gt;The final configuration will look like &lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/1.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/1.png"&gt;this&lt;/A&gt; &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;That's it, click OK twice to get back to IIS Manager. &lt;/P&gt;
&lt;P&gt;Now when we are set to use CCA for authentication on 'Exchange' virtual directory, we can go and turn off all other authentication methods. To do that, go to IIS : Default Website : Exchange : Properties : Directory Security : Authentication &amp;amp; Access Control : Edit : Uncheck all boxes here (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/2.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/2.png"&gt;screenshot&lt;/A&gt;), click OK twice to get back to IIS Manager. &lt;/P&gt;
&lt;P&gt;Repeat the above steps now for 'Public' virtual directory which is used by Entourage to access public folders on Exchange Server. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Client Side Setup&lt;/STRONG&gt;&lt;BR&gt;To begin with Entourage users should follow these steps for obtaining and installing a user certificate on their Mac. I used a Mac with Tiger (Mac OS 10.4.11) and Entourage 2008 SP1 installed on it. &lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Launch Safari browser and go to &lt;A href="http://%3cserver-name%3e/certsrv" mce_href="http://&lt;server-name&gt;/certsrv"&gt;http://&amp;lt;server-name&amp;gt;/certsrv&lt;/A&gt; (where 'server-name' is the name of the server where 'Private Root CA' is installed) (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/3.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/3.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;Enter your username and password when prompted (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/4.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/4.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;On the 'Welcome' page of your Root CA Server, click on 'Request a certificate' link (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/5.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/5.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;On the 'Request a certificate' page, click on 'User Certificate' link (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/6.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/6.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;On the 'User Certificate – Identifying Information' page, keep the 'Key Strength' field set to '2048 (High Grade)', click on 'Submit' button (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/7.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/7.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;On the 'Certificate Issued' page, click on 'Install this certificate' link (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/8.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/8.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;You will see the 'Downloads' window from Safari and a file by the name of 'certnew.cer' will be downloaded to your desktop (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/9.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/9.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;Double click on the 'certnew.cer' file on your desktop (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/10.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/10.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;The 'Keychain Access' application will launch and you will see the 'Add Certificates' window, keep the 'Keychain' field set to 'login' and click 'OK' (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/11.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/11.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;The user certificate will then be imported in the Keychain (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/12.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/12.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;You can double click on it to view the user certificate (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/13.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/13.png"&gt;screenshot&lt;/A&gt;) &lt;/LI&gt;
&lt;LI&gt;You can also launch 'Microsoft Cert Manager' application (from Mac Hard Drive : Applications : Microsoft Office 2008 : Office) to view the certificate in 'Digital Identities' &lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/14.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/14.png"&gt;container&lt;/A&gt;. This is a good indication that the user certificate will work fine with CCA or digital signing and encryption of outgoing mail. &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;SPAN style="TEXT-DECORATION: underline"&gt;Quick Admin Check&lt;/SPAN&gt;: Now in order to make sure that Entourage user account is setup properly in Windows Active Directory, take a look at its properties (thru 'Active Directory Users &amp;amp; Computers' or 'ADUC'), you should see the user certificate there under 'Published Certificates' tab (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/15.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/15.png"&gt;screenshot&lt;/A&gt;). If not then you can also import it (use the 'cer' file from user's Mac, see Step 7 above) using the 'Add from file' button there. Another way to add &amp;amp; map user certificate is to do a right click on user object in ADUC, choose 'Name Mappings', then add the user certificate there under 'X.509 Certificates' tab (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/16.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/16.png"&gt;screenshot&lt;/A&gt;). &lt;/P&gt;
&lt;P&gt;Now let's configure Exchange account settings in Entourage, this &lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/17.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/17.png"&gt;screenshot&lt;/A&gt; depicts how 'Account Settings' tab should look like. Note that you do not need to provide user's domain credentials, i.e. username, domain &amp;amp; password. The '&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/18.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/18.png"&gt;Advanced&lt;/A&gt;' tab is where you need to select user certificate under 'Client Certificate-based Authentication' section. Clicking on 'Select' button there will provide you with the 'Choose an Identity' window which will list the user certificate there. That's it, you are done. &lt;/P&gt;
&lt;P&gt;After that Entourage will try to connect to Exchange mailbox utilizing 'Client Certificate-based Authentication', user will see a &lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/19.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/19.png"&gt;prompt&lt;/A&gt; 'Confirm Access to Keychain', choose 'Always Allow' on that. This allows Entourage to access 'Keychain' in Mac OS where user certificate is stored. Entourage will then go and talk to 'Exchange' virtual directory on server. User certificate will be used for CCA and connection to Exchange mailbox will be &lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/20.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/20.png"&gt;established&lt;/A&gt; in seconds. We are done! &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;But What About GAL Access?&lt;/STRONG&gt;&lt;BR&gt;After some research I found that currently it is not possible in Windows Server 2003 to require CCA for LDAP connections &amp;amp; queries. Thus if you want your Entourage users to access your Windows Global Catalog Server (LDAP Server) for 'GAL Access' (Global Address List) feature, you will need to configure it appropriately (non-SSL over ports 3268 &amp;amp; 389 or SSL over ports 3269 &amp;amp; 636) and also provide domain credentials in Exchange account settings in Entourage. Entourage uses the same set of domain credentials provided on first tab (&lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/21.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/21.png"&gt;screenshot&lt;/A&gt;) for authentication against Exchange &amp;amp; LDAP Server. The authentication processes are separate for IIS (for Exchange mailbox &amp;amp; public folder access) &amp;amp; LDAP Server (for 'GAL Access' feature). If CCA is required for authentication by IIS (at 'Exchange' &amp;amp; 'Public' virtual directories), then Entourage will use client certificate for that and will only use domain credentials for authentication against LDAP Server for 'GAL Access' feature. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Smart Cards&lt;/STRONG&gt;&lt;BR&gt;Some organizations out there use Smart Cards to store user certificate which is generally used by them for digital signing and encryption of outgoing mail. They will continue to work in the same way for CCA feature as well. Just select the same user certificate over &lt;A href="http://erage.members.winisp.net/CCAAuthEntourage2008/22.png" target=_blank mce_href="http://erage.members.winisp.net/CCAAuthEntourage2008/22.png"&gt;here&lt;/A&gt; as well.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3070175" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage/">Entourage</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Microsoft/">Microsoft</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Exchange/">Exchange</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage+2008/">Entourage 2008</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Feature/">Feature</category></item><item><title>DST Workaround for Entourage 2004 &amp; 2008 Users in ANZ   </title><link>http://blogs.technet.com/b/amir/archive/2008/03/31/dst-workaround-for-entourage-2004-2008-users-in-anz.aspx</link><pubDate>Tue, 01 Apr 2008 02:12:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3024890</guid><dc:creator>Amir Haque [MSFT]</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/amir/rsscomments.aspx?WeblogPostID=3024890</wfw:commentRss><comments>http://blogs.technet.com/b/amir/archive/2008/03/31/dst-workaround-for-entourage-2004-2008-users-in-anz.aspx#comments</comments><description>&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Update&lt;/U&gt;&lt;/STRONG&gt;: The fixes for this issue have been released in 11.5 (Entourage 2004) &amp;amp; 12.1 (Entourage 2008) Updates for Office for Mac.&lt;/P&gt;
&lt;P&gt;I wanted to quickly provide this workaround to the users of Entourage 2004 &amp;amp; 2008 in Australia &amp;amp; New Zealand (ANZ) time zones until Microsoft releases fixes thru updates at Mactopia website. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue&lt;/STRONG&gt;&lt;BR&gt;When Entourage 2004 &amp;amp; 2008 users organize meetings by inviting other users who are using Microsoft Outlook or OWA (Outlook Web Access) against their Exchange mailboxes (version of Exchange Server does not matter here), then those meeting attendees may see the incoming meeting invite being an hour off. This issue is not seen if all meeting attendees are Entourage users. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cause&lt;/STRONG&gt;&lt;BR&gt;This happens as Entourage 2004 &amp;amp; 2008 use DST information from related 'Timezones' files for users in ANZ time zones, which are not up to date with current information. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;BR&gt;Microsoft is working to release a fix for this issue in an update for both versions of Entourage but a final release date is not available yet. When that update is available, users can safely install it and it will replace the files which they will put on their systems as a result of applying the workaround provided below. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Workaround&lt;/STRONG&gt;&lt;BR&gt;Below are the steps to follow for both versions of Entourage. Only Entourage users will need to apply this workaround on their machines, no action is required by other users who are using Microsoft Outlook or OWA. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Entourage 2004 &lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Quit Entourage (Entourage should not be running when you apply this workaround) &lt;/LI&gt;
&lt;LI&gt;Back up the current 'Timezones' file in folder: Mac Hard Drive : Applications : Microsoft Office 2004 : Office (just copy it to a backup folder on your hard drive) &lt;/LI&gt;
&lt;LI&gt;Download the updated 'Timezones' file for Entourage 2004 from &lt;A href="http://erage.members.winisp.net/Downloads/Timezones-2004.zip" mce_href="http://erage.members.winisp.net/Downloads/Timezones-2004.zip"&gt;here&lt;/A&gt; (extract its content before proceeding to next step) &lt;/LI&gt;
&lt;LI&gt;Copy the downloaded 'Timezones' file to the same location as above in Step 2, replacing the existing 'Timezones' file &lt;/LI&gt;
&lt;LI&gt;That's it, you are done, launch Entourage and every meeting you create now will not display the issue described above &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Entourage 2008 &lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Quit Entourage (Entourage should not be running when you apply this workaround) &lt;/LI&gt;
&lt;LI&gt;Back up the current 'Timezones.ics' file, go to folder: Mac Hard Drive : Applications : Microsoft Office 2008 : Office, locate a file by the name of 'EntourageCore.framework', now Control-Click on it and choose 'Show Package Contents' in the resulting menu, a new window will appear, in that window go to folder: Versions : 12 : Resources : en.lproj (you will find the 'Timezones.ics' file here, just copy it to a backup folder on your hard drive) &lt;/LI&gt;
&lt;LI&gt;Download the updated 'Timezones.ics' file for Entourage 2008 from &lt;A href="http://erage.members.winisp.net/Downloads/Timezones-2008.zip" mce_href="http://erage.members.winisp.net/Downloads/Timezones-2008.zip"&gt;here&lt;/A&gt; (extract its content before proceeding to next step) &lt;/LI&gt;
&lt;LI&gt;Copy the downloaded 'Timezones.ics' file to the same location as above in Step 2, replacing the existing 'Timezones.ics' file &lt;/LI&gt;
&lt;LI&gt;That's it, you are done, launch Entourage and every meeting you create now will not display the issue described above &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;&lt;SPAN style="TEXT-DECORATION: underline"&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;/SPAN&gt;: Any meetings which were scheduled earlier and display the issue described in this post will not automatically get fixed. If you want to fix them, you will have to open them and make a change in them (like add one character to its subject/title or notes area, etc.), then save them and send update to all attendees. This change will force Entourage to recalculate DST info as per the updated 'Timezones' file. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Workaround Removal&lt;/STRONG&gt;&lt;BR&gt;If at anytime you may need to remove or undo this workaround, just follow the same steps as above and replace the 'Timezones' files with the original ones which you backed up earlier.&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3024890" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage/">Entourage</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Microsoft/">Microsoft</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Troubleshooting/">Troubleshooting</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage+2008/">Entourage 2008</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage+2004/">Entourage 2004</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Known+Issues/">Known Issues</category></item><item><title>How Does Entourage Work?</title><link>http://blogs.technet.com/b/amir/archive/2008/02/08/how-does-entourage-work.aspx</link><pubDate>Sat, 09 Feb 2008 08:17:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2853695</guid><dc:creator>Amir Haque [MSFT]</dc:creator><slash:comments>11</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/amir/rsscomments.aspx?WeblogPostID=2853695</wfw:commentRss><comments>http://blogs.technet.com/b/amir/archive/2008/02/08/how-does-entourage-work.aspx#comments</comments><description>&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;As my blog is focused on Entourage as an 'Exchange Client', let's start with the most obvious topic which will provide details on how Entourage works with a mailbox on an Exchange Server. This blog will encompass the currently supported versions of Entourage &amp;amp; Exchange Server, i.e. Entourage 2004 &amp;amp; 2008, and Exchange 2000, 2003 &amp;amp; 2007. Let's list all the different features in Entourage for which it needs to talk to Exchange Server or any other server in a Windows Active Directory based environment. (Note: All ports mentioned below are server side ports) &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;&lt;STRONG&gt;Entourage Setup Assistant&lt;/STRONG&gt; (&lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/1.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/1.png"&gt;screenshot&lt;/A&gt;)&lt;BR&gt;The very first feature which you use in Entourage is the 'Entourage Setup Assistant' (or 'Account Setup Assistant') after you create a new identity. If you try to configure your Exchange account using the setup assistant, it talks to available DNS server configured in Mac OS X 'Network &lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/2.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/2.png"&gt;Preferences&lt;/A&gt;' to locate a Windows Domain Controller or Global Catalog Server hosting Active Directory and then authenticates &amp;amp; inquires about Exchange mailbox server for user. The whole process is described over &lt;A href="http://www.microsoft.com/mac/itpros/default.mspx?MODE=ct&amp;amp;CTT=PageView&amp;amp;clr=99-15-0&amp;amp;target=a3856960-08e6-4797-b1ac-3b4dcdc749211033&amp;amp;srcid=598f107c-575b-4304-9219-bffc1c32f7ab1033&amp;amp;ep=8&amp;amp;rtype=2&amp;amp;pos=1&amp;amp;quid=5c8b13c1-5ebe-43e8-acf4-f57972caf8ec" target=_blank mce_href="http://www.microsoft.com/mac/itpros/default.mspx?MODE=ct&amp;amp;CTT=PageView&amp;amp;clr=99-15-0&amp;amp;target=a3856960-08e6-4797-b1ac-3b4dcdc749211033&amp;amp;srcid=598f107c-575b-4304-9219-bffc1c32f7ab1033&amp;amp;ep=8&amp;amp;rtype=2&amp;amp;pos=1&amp;amp;quid=5c8b13c1-5ebe-43e8-acf4-f57972caf8ec"&gt;here&lt;/A&gt; in detail. Server side ports used are 53 (for DNS queries) and 3268 (for authentication &amp;amp; LDAP queries to locate mailbox server). &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;&lt;STRONG&gt;Mailbox Synchronization&lt;/STRONG&gt; (&lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/3.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/3.png"&gt;screenshot&lt;/A&gt;)&lt;BR&gt;After you have setup your Exchange account (using setup assistant or manually), Entourage goes and talks to the Exchange &lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/4.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/4.png"&gt;server&lt;/A&gt; (front-end or back-end mailbox server) thru IIS (Internet Information Server) to get connected to your mailbox. This communication is HTTP (WebDAV protocol) in nature, thus can happen over port 80 (without SSL) or 443 (with SSL) as per your server side requirements. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;&lt;STRONG&gt;Public Folders&lt;/STRONG&gt; (&lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/5.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/5.png"&gt;screenshot&lt;/A&gt;)&lt;BR&gt;Another server you have to enter in Exchange account settings is your public folders &lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/6.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/6.png"&gt;server&lt;/A&gt;. Generally in big enterprises public folder servers are maintained separately from mailbox servers on the back-end. Entourage communicates with the public folder server in the same way as with an Exchange mailbox server, i.e. HTTP (WebDAV) over port 80 (without SSL) or 443 (with SSL). &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;&lt;STRONG&gt;Global Address List&lt;/STRONG&gt; (&lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/7.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/7.png"&gt;screenshot&lt;/A&gt;)&lt;BR&gt;In Entourage you also have to provide a Directory or LDAP &lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/6.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/6.png"&gt;server&lt;/A&gt; name, which in a Windows Active Directory based environment is your Global Catalog Server so that you can have access to 'Global Address List' (GAL) of your Exchange organization. Entourage uses ports 389 (without SSL) &amp;amp; 636 (with SSL) for authentication and then to access GAL, it sends LDAP queries over ports 3268 (without SSL) or 3269 (with SSL), so a combination of two ports is used for GAL feature, i.e. 389 &amp;amp; 3268 (without SSL) or 636 &amp;amp; 3269 (with SSL). &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG alt="" src="http://erage.members.winisp.net/020908_0517_HowDoesEnto1.png" mce_src="http://erage.members.winisp.net/020908_0517_HowDoesEnto1.png"&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;&lt;STRONG&gt;Out of Office Assistant&lt;/STRONG&gt;&lt;BR&gt;This is a new feature only in Entourage 2008. When connecting to Exchange 2000/2003 based mailboxes, Entourage sends a WebDAV query to pull up '&lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/8.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/8.png"&gt;Options&lt;/A&gt;' page from OWA (Outlook Web Access) thru which it sets the OOF &lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/9.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/9.png"&gt;Assistant&lt;/A&gt;. The port usage for this feature is same as described above under 'Mailbox Synchronization' section. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;When connecting to an Exchange 2007 CAS, it works thru '&lt;A href="http://msdn2.microsoft.com/en-us/library/bb408417.aspx" target=_blank mce_href="http://msdn2.microsoft.com/en-us/library/bb408417.aspx"&gt;Exchange Web Services&lt;/A&gt;' ('OOFURL' in 'autodiscover.xml') to configure 'OOF &lt;A href="http://erage.members.winisp.net/Entourage2008NewFeaturesII/7.png" target=_blank mce_href="http://erage.members.winisp.net/Entourage2008NewFeaturesII/7.png"&gt;Assistant&lt;/A&gt;' with appropriate settings. Entourage 2008 uses port 80 (without SSL) or 443 (with SSL) for this feature depending on related configuration on Exchange 2007 CAS. Keep in mind that this feature does not work and fails with an &lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/10.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/10.png"&gt;error&lt;/A&gt; if you connect directly to an Exchange 2007 mailbox server on back-end as '&lt;A href="http://technet.microsoft.com/en-us/library/bb124251.aspx" target=_blank mce_href="http://technet.microsoft.com/en-us/library/bb124251.aspx"&gt;autodisover&lt;/A&gt;' and 'Exchange Web Services' are not present on it, they are only present on an Exchange 2007 CAS. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;&lt;STRONG&gt;Free/Busy Info&lt;/STRONG&gt; (&lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/11.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/11.png"&gt;screenshot&lt;/A&gt;)&lt;BR&gt;When Entourage users schedule a meeting with other users in their Exchange organization, they can also view their free/busy information, i.e. whether other users are free or busy on particular day/time slots. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;Entourage 2004 retrieves free/busy information for other users by talking to a public folder server hosting consolidated free/busy info for all users. This communication is also HTTP (WebDAV) in nature thus happens over port 80 (without SSL) or 443 (with SSL). Entourage 2004 pulls free/busy information in this way in all cases. It does not matter where Entourage user's mailbox is located, i.e. on Exchange 2000, 2003 or 2007 Server. Therefore, it is necessary to provide a public server name in Exchange account settings (under '&lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/6.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/6.png"&gt;Advanced&lt;/A&gt;' tab) in Entourage 2004. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;Entourage 2008 utilizes '&lt;A href="http://technet.microsoft.com/en-us/library/bb232134.aspx" target=_blank mce_href="http://technet.microsoft.com/en-us/library/bb232134.aspx"&gt;Availability Service&lt;/A&gt;' (AS, part of 'Exchange Web Services') on Exchange 2007 to retrieve free/busy information for other users (having mailboxes located on any version of Exchange Server) if it is connecting directly to an Exchange 2007 Client Access Server (CAS). For mailboxes located on Exchange 2007 server, AS pulls free/busy info directly from users' mailboxes while for mailboxes located on Exchange 2003 server (or earlier versions), AS sends the WebDAV query (HTTP, this query always goes over port 80 from CAS to an internal Public Folder server) to respective public folder server hosting those users' free/busy information. Entourage 2008 uses port 80 (without SSL) or 443 (with SSL) for this feature depending on related configuration on Exchange 2007 CAS. You also don't need to enter a public folder server name in Exchange account settings (under '&lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/6.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/6.png"&gt;Advanced&lt;/A&gt;' tab) in Entourage for this feature to work, just the name of Exchange 2007 CAS (in 'Exchange server' field under '&lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/4.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/4.png"&gt;Account Settings&lt;/A&gt;' tab) is enough. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;If Entourage 2008 is connecting directly to a backend mailbox server (Exchange 2007 or earlier versions) or a front-end server (Exchange 2003 or earlier versions) then it utilizes the same WebDAV (HTTP) procedure to pull up the free/busy info as Entourage 2004 does (discussed above). It cannot use AS in this scenario as its only available on an Exchange 2007 CAS. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG alt="" src="http://erage.members.winisp.net/020908_0517_HowDoesEnto2.png" mce_src="http://erage.members.winisp.net/020908_0517_HowDoesEnto2.png"&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;&lt;STRONG&gt;Folder Sharing&lt;/STRONG&gt;&lt;BR&gt;When an Entourage user (User1) accesses a shared folder of another user (User2) in his Exchange organization, it uses the same WebDAV (HTTP) based communication which it uses to access the mailbox of Entourage user (User1). The port usage is also the same as described above under 'Mailbox Synchronization' section. Same applies when you use Entourage to assign folder sharing permissions (Folder : &amp;lt;right click&amp;gt; : Sharing : Permissions &lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/12.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/12.png"&gt;tab&lt;/A&gt;). &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;&lt;STRONG&gt;Delegate Management&lt;/STRONG&gt; (&lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/13.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/13.png"&gt;screenshot&lt;/A&gt;)&lt;BR&gt;Using Entourage you can also assign access permissions to your delegates so that they can access your folders such as Inbox, Calendar &amp;amp; Contacts. Entourage 2004 establishes a direct connection to your mailbox server for this purpose, which utilizes &lt;A href="http://en.wikipedia.org/wiki/MAPI" target=_blank mce_href="http://en.wikipedia.org/wiki/MAPI"&gt;MAPI&lt;/A&gt; (RPC over TCP). Why? Please read the 'CAUSE' section in KB &lt;A href="http://support.microsoft.com/kb/909269" target=_blank mce_href="http://support.microsoft.com/kb/909269"&gt;909269&lt;/A&gt;. Entourage 2004 first connects to port 135 ('End-point Mapper' or 'epmap') on Exchange mailbox server, which refers it to 'Exchange System Attendant Service' ('MAD.exe', there is no fixed port for 'MAD', its assigned dynamically). Exchange server then authenticates Entourage client by talking to a 'Domain Controller' or 'Global Catalog Server'. After successful authentication Entourage finally connects to mailbox store on Exchange server (there is no fixed port for 'store' either) and sets two parameters as mentioned in KB &lt;A href="http://support.microsoft.com/kb/909269" target=_blank mce_href="http://support.microsoft.com/kb/909269"&gt;909269&lt;/A&gt;. Entourage 2004 uses this procedure irrespective of the version of Exchange server (2007 or earlier versions) to which its connecting for mailbox access. Entourage 2008 works in the same way except when its connecting to an Exchange 2007 CAS with SP1 installed. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;Entourage 2008 utilizes the new delegate management web &lt;A href="http://technet.microsoft.com/en-us/library/bb684907(EXCHG.80).aspx" target=_blank mce_href="http://technet.microsoft.com/en-us/library/bb684907(EXCHG.80).aspx"&gt;service&lt;/A&gt; if its connecting to an Exchange 2007 CAS with Service Pack 1 installed. This communication happens over port 80 (without SSL) or 443 (with SSL) as per the server side configuration. The major advantage of this feature is that Entourage users can now assign delegation rights to other users independent of their location, i.e. they can do it while connected from internal or external locations. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;&lt;STRONG&gt;Mailbox Quota Management&lt;/STRONG&gt; (&lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/14.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/14.png"&gt;screenshot&lt;/A&gt;)&lt;BR&gt;Entourage users can also find how much space their mailbox is utilizing on server at different levels, like at the top mailbox level, at each folder level, etc. They can do that by going to any folder, right click on it, choose 'Folder Properties' and then go to 'Storage' tab. The port usage for this feature is same as described above under 'Mailbox Synchronization' section. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-SIZE: 9pt; FONT-FAMILY: Lucida Sans Unicode"&gt;&lt;STRONG&gt;Password Expiration Notice&lt;/STRONG&gt; (&lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/15.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/15.png"&gt;screenshot&lt;/A&gt;)&lt;BR&gt;Entourage also checks for Windows domain (where your Exchange server resides) password expiration on every launch or every 24 hours afterwards to see if user's password is going to expire in the next 10 days or not. It does that thru an LDAP query to your Windows 'Domain Controller' or 'Global Catalog Server' configured in Exchange account settings (under '&lt;A href="http://erage.members.winisp.net/HowDoesEntourageWork/6.png" target=_blank mce_href="http://erage.members.winisp.net/HowDoesEntourageWork/6.png"&gt;Advanced&lt;/A&gt;' tab). This communication happens over port 389 (without SSL) or 636 (with SSL).&lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2853695" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage/">Entourage</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Exchange/">Exchange</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage+2008/">Entourage 2008</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Entourage+2004/">Entourage 2004</category><category domain="http://blogs.technet.com/b/amir/archive/tags/Feature/">Feature</category></item></channel></rss>