<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Recommendation: Enabling Kerberos Authentication for MAPI Clients</title><link>http://blogs.technet.com/b/exchange/archive/2011/04/15/recommendation-enabling-kerberos-authentication-for-mapi-clients.aspx</link><description>Update 4/26/11: This post has been updated to include additional steps to ensure Kerberos authentication can be used for OAB downloads by domain-connected Outlook clients. With Exchange 2010, a major change was instituted in the way clients connect and</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Recommendation: Enabling Kerberos Authentication for MAPI Clients</title><link>http://blogs.technet.com/b/exchange/archive/2011/04/15/recommendation-enabling-kerberos-authentication-for-mapi-clients.aspx#3436512</link><pubDate>Tue, 21 Jun 2011 00:09:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3436512</guid><dc:creator>JLundfelt</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;I set the spn&amp;#39;s for my new exchange 2010 environment, and its now prompting users for authentication within OCS, and possibly Outlook. I checked to make sure I didn&amp;#39;t have any duplicate spn&amp;#39;s, but something has obviously gone wrong. I apparently need to delete, or re-add a SPN to fix this, but am not sure if I am supposed to run &amp;#39;setspn -A exchangeAB/&amp;#39; with my GC server, CAS, or Mailbox servers?&lt;/p&gt;
&lt;p&gt;All I ran was these commands-&lt;/p&gt;
&lt;p&gt;Setspn -S http/mail.mycompany.com mycompany\casarray$&lt;/p&gt;
&lt;p&gt;Setspn -S http/autodiscover.mycompany.com mycompany\casarray$&lt;/p&gt;
&lt;p&gt;Setspn -S http/autodiscover.myothercompany.com mycompany\casarray$&lt;/p&gt;
&lt;p&gt;Setspn -S exchangeMDB/cas.mycompany.com mycompany\casarray$&lt;/p&gt;
&lt;p&gt;Setspn -S exchangeRFR/cas.mycompany.com mycompany\casarray$&lt;/p&gt;
&lt;p&gt;Setspn -S exchangeAB/cas.mycompany.com mycompany\casarray$&lt;/p&gt;
&lt;p&gt;Please help!!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3436512" width="1" height="1"&gt;</description></item><item><title>re: Recommendation: Enabling Kerberos Authentication for MAPI Clients</title><link>http://blogs.technet.com/b/exchange/archive/2011/04/15/recommendation-enabling-kerberos-authentication-for-mapi-clients.aspx#3434453</link><pubDate>Wed, 08 Jun 2011 22:04:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3434453</guid><dc:creator>Nick Smith</dc:creator><description>&lt;p&gt;Ross,&lt;/p&gt;
&lt;p&gt;What is the entire exit strategy for this process? &amp;nbsp;Is it just:&lt;/p&gt;
&lt;p&gt;1) &amp;nbsp;Removing and recreating the OAB directory.&lt;/p&gt;
&lt;p&gt;2) &amp;nbsp;Deleting the ASA Credential account.&lt;/p&gt;
&lt;p&gt;Or are there more steps involved to completely reverse the changes made?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3434453" width="1" height="1"&gt;</description></item><item><title>re: Recommendation: Enabling Kerberos Authentication for MAPI Clients</title><link>http://blogs.technet.com/b/exchange/archive/2011/04/15/recommendation-enabling-kerberos-authentication-for-mapi-clients.aspx#3434154</link><pubDate>Tue, 07 Jun 2011 18:57:51 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3434154</guid><dc:creator>Lee</dc:creator><description>&lt;p&gt;You mention &amp;quot;External or Internet-based clients that use Outlook Anywhere won’t use Kerberos authentication as they cannot directly contact a KDC.&amp;quot; &amp;nbsp;Why is this true for Internal OA clients? &amp;nbsp;Is this true both the HTTP level auth as well as the RPC level auth when doing RPC Encryption?&lt;/p&gt;
&lt;p&gt;I&amp;#39;m trying to figure out if Outlook Anywhere can do Kerberos for the RPC auth, regardless of the HTTP auth. &amp;nbsp;I posted this question to the forums, but haven&amp;#39;t found a diffinitive answer:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://social.technet.microsoft.com/Forums/en-US/exchangesvrdeploy/thread/7e5005e7-323d-48aa-b2a9-7a81dbfe84c6?prof=required"&gt;social.technet.microsoft.com/.../7e5005e7-323d-48aa-b2a9-7a81dbfe84c6&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Most everything seems concerned with the HTTP auth (I see only Basic, NTLM supported), but nothing is really addressing the RPC level auth with OA. &amp;nbsp;In practice, even with Outlook set to &amp;quot;Kerberos Only&amp;quot; RPC auth, I still see NTLM being used.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;-Lee&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3434154" width="1" height="1"&gt;</description></item><item><title>re: Recommendation: Enabling Kerberos Authentication for MAPI Clients</title><link>http://blogs.technet.com/b/exchange/archive/2011/04/15/recommendation-enabling-kerberos-authentication-for-mapi-clients.aspx#3431056</link><pubDate>Mon, 23 May 2011 13:33:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3431056</guid><dc:creator>PJ</dc:creator><description>&lt;p&gt;Ross: how do you reverse the work done by the RollAlternateserviceAccountPassword.ps1 script?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3431056" width="1" height="1"&gt;</description></item><item><title>re: Recommendation: Enabling Kerberos Authentication for MAPI Clients</title><link>http://blogs.technet.com/b/exchange/archive/2011/04/15/recommendation-enabling-kerberos-authentication-for-mapi-clients.aspx#3427832</link><pubDate>Tue, 10 May 2011 14:44:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3427832</guid><dc:creator>Ross Smith IV [MSFT]</dc:creator><description>&lt;p&gt;@Joe - You simply delete the OAB vdir (Remove-OABVirtualDirectory) and recreate it (New-OABVirtualDirectory).&lt;/p&gt;
&lt;p&gt;Ross&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3427832" width="1" height="1"&gt;</description></item><item><title>re: Recommendation: Enabling Kerberos Authentication for MAPI Clients</title><link>http://blogs.technet.com/b/exchange/archive/2011/04/15/recommendation-enabling-kerberos-authentication-for-mapi-clients.aspx#3426151</link><pubDate>Tue, 03 May 2011 22:33:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3426151</guid><dc:creator>Joe</dc:creator><description>&lt;p&gt;If we need to fall back the changes, How do you convert back the OAB application back to a virtual folder&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3426151" width="1" height="1"&gt;</description></item><item><title>re: Recommendation: Enabling Kerberos Authentication for MAPI Clients</title><link>http://blogs.technet.com/b/exchange/archive/2011/04/15/recommendation-enabling-kerberos-authentication-for-mapi-clients.aspx#3424698</link><pubDate>Wed, 27 Apr 2011 16:22:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3424698</guid><dc:creator>Ross Smith IV [MSFT]</dc:creator><description>&lt;p&gt;@CY - When you use external trust, only NTLM authentication is available.&lt;/p&gt;
&lt;p&gt;@Gabriel - Other MAPI applications will leverage an authentication mechanism that is defined in the MAPI profile. &amp;nbsp;Kerberos could be leveraged if they are leveraging an FQDN that maps to a deployed SPN on the ASA credential.&lt;/p&gt;
&lt;p&gt;@David - Outlook (and MAPI apps) do not use the /exchweb, /exchange, /public vdirs (some of which don&amp;#39;t exist in E2010). &amp;nbsp;I have added the guidance for OAB vdir.&lt;/p&gt;
&lt;p&gt;Ross&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3424698" width="1" height="1"&gt;</description></item><item><title>re: Recommendation: Enabling Kerberos Authentication for MAPI Clients</title><link>http://blogs.technet.com/b/exchange/archive/2011/04/15/recommendation-enabling-kerberos-authentication-for-mapi-clients.aspx#3424474</link><pubDate>Wed, 27 Apr 2011 04:14:27 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3424474</guid><dc:creator>cy</dc:creator><description>&lt;p&gt;Hi Ross.&lt;/p&gt;
&lt;p&gt;We have a situation where a Exchange 2010 sp1 was setup in a resource forest mode and it uses linked-mailbox to another user domain. Due to some reasons, we can only create an external trust to the user domain, not forest trust.&lt;/p&gt;
&lt;p&gt;Will Kerberos work in this senario?&lt;/p&gt;
&lt;p&gt;TIA&lt;/p&gt;
&lt;p&gt;Cheers&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3424474" width="1" height="1"&gt;</description></item><item><title>re: Recommendation: Enabling Kerberos Authentication for MAPI Clients</title><link>http://blogs.technet.com/b/exchange/archive/2011/04/15/recommendation-enabling-kerberos-authentication-for-mapi-clients.aspx#3424364</link><pubDate>Tue, 26 Apr 2011 16:58:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3424364</guid><dc:creator>Gabriel</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;Just wondering if making this change to an existing environment will have any impact to non-microsoft MAPI applications such as my backup and BES servers. What type of impact, if any?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3424364" width="1" height="1"&gt;</description></item><item><title>re: Recommendation: Enabling Kerberos Authentication for MAPI Clients</title><link>http://blogs.technet.com/b/exchange/archive/2011/04/15/recommendation-enabling-kerberos-authentication-for-mapi-clients.aspx#3422437</link><pubDate>Mon, 18 Apr 2011 13:18:39 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3422437</guid><dc:creator>David</dc:creator><description>&lt;p&gt;Hi.&lt;/p&gt;
&lt;p&gt;There is one caveat with http/ SPNs. Documentation says &amp;quot;For Exchange Web Services and the Autodiscover service&amp;quot;, but there are more things with integrated auth, which are usualy accesed with same hostname - OAB, Exchange, Exchweb and Public virtual directories. &lt;/p&gt;
&lt;p&gt;Since those virtual directories runs in ApplicationPoolIdentity context (in DefaultAppPool), kerberos authentication will fail if http/ SPN is set for service account. So typicaly Outlook 2007 and higher will throw authentication window during OAB download unless your OAB url uses different hostname than EWS/Autodiscover url. Solution could be to change DefaultAppPool context to the service account, but then password generation feature of the ASA script cannot be used.&lt;/p&gt;
&lt;p&gt;d.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3422437" width="1" height="1"&gt;</description></item></channel></rss>