<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>ActiveSync clients are unable to authenticate with ISA Server/Forefront TMG using SecurID</title><link>http://blogs.technet.com/b/isablog/archive/2010/04/19/activesync-clients-are-unable-authenticate-with-isa-server-forefront-tmg-using-securid.aspx</link><description>Consider the following scenario: You are currently using ISA Server 2006 or Forefront TMG to publish your internal OWA server. You require SecurID authentication for external OWA clients. You have only one IP address bound to the external interface of</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: ActiveSync clients are unable to authenticate with ISA Server/Forefront TMG using SecurID</title><link>http://blogs.technet.com/b/isablog/archive/2010/04/19/activesync-clients-are-unable-authenticate-with-isa-server-forefront-tmg-using-securid.aspx#3446719</link><pubDate>Fri, 12 Aug 2011 11:40:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3446719</guid><dc:creator>acolada</dc:creator><description>&lt;p&gt;Greetings everyone.&lt;/p&gt;
&lt;p&gt;Had a similar problem and &amp;nbsp;got it working. In my case it&amp;#39;s not about RSA SecurID, but FBA with normal Windows Authentication.&lt;/p&gt;
&lt;p&gt;It&amp;#39;s about the User-Agent property on the firewall, which actually has a *SonyEricsson* string in it mapped to xhtml, not basic(requiered for activesync). So instead of 401 code, the phone gets a 302 redirect to a form. So it nevers falls to baisc, because it interprets the phone as a browser with form processing capabilities.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://forums.isaserver.org/Exchange_Active_Sync_and_Road_Sync_with_FBA_enabled/m_2002031196/tm.htm"&gt;forums.isaserver.org/.../tm.htm&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://msdn.microsoft.com/en-us/library/ff826787(v=vs.85).aspx"&gt;msdn.microsoft.com/.../ff826787(v=vs.85).aspx&lt;/a&gt; the property explained in detail&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://msdn.microsoft.com/en-us/library/ff826786(v=vs.85).aspx"&gt;msdn.microsoft.com/.../ff826786(v=vs.85).aspx&lt;/a&gt; here you find the actual script to insert a new mapping, let&amp;#39;s say a SonyEricssonJ108*.&lt;/p&gt;
&lt;p&gt;like this: &amp;quot;cscript ericsson.vbs SonyEricssonJ108* Basic&amp;quot;&lt;/p&gt;
&lt;p&gt;It&amp;#39;s necessary to modify the order of the string with moveup property:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://msdn.microsoft.com/en-us/library/ff826798(v=vs.85).aspx"&gt;msdn.microsoft.com/.../ff826798(v=vs.85).aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;something like this: &amp;quot;cscript order.vbs 12&amp;quot; This moves up mapping number 12, to position 11. You have to move it to position 5 though, to take precedence over the existing generic SonyEricsson mapping.&lt;/p&gt;
&lt;p&gt;To list the existing mappings:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://msdn.microsoft.com/en-us/library/ff826793(v=vs.85).aspx"&gt;msdn.microsoft.com/.../ff826793(v=vs.85).aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;So it&amp;#39;s a Microsoft problem, at least when ISA and TMG are involved and you want to use FBA with fallback to basic(which is a common configuration nowadays for exchange publishing rule)&lt;/p&gt;
&lt;p&gt;Good luck.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3446719" width="1" height="1"&gt;</description></item><item><title>re: ActiveSync clients are unable to authenticate with ISA Server/Forefront TMG using SecurID</title><link>http://blogs.technet.com/b/isablog/archive/2010/04/19/activesync-clients-are-unable-authenticate-with-isa-server-forefront-tmg-using-securid.aspx#3330410</link><pubDate>Wed, 05 May 2010 13:22:05 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3330410</guid><dc:creator>NKJaiswal</dc:creator><description>&lt;p&gt;Yes You Can use RSA SecurID With Array that are in Workgroup.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3330410" width="1" height="1"&gt;</description></item><item><title>re: ActiveSync clients are unable to authenticate with ISA Server/Forefront TMG using SecurID</title><link>http://blogs.technet.com/b/isablog/archive/2010/04/19/activesync-clients-are-unable-authenticate-with-isa-server-forefront-tmg-using-securid.aspx#3329373</link><pubDate>Thu, 29 Apr 2010 22:52:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3329373</guid><dc:creator>Itworkedinthelab</dc:creator><description>&lt;p&gt;Hi&lt;/p&gt;
&lt;p&gt;i have asmall question&lt;/p&gt;
&lt;p&gt;can i use secureid with a 2 member array that are in a workgroup?&lt;/p&gt;
&lt;p&gt;icurrently have ent array of isa 2006 with the users being prompt twice once for the secureid and then again at the front end ex 2003 servers(dont ask me why thats what the customer has)&lt;/p&gt;
&lt;p&gt;and im not sure if workgroup array's will work with the rsa authetication form(single sign on) when they are not domain joined?&lt;/p&gt;
&lt;p&gt;thanks&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3329373" width="1" height="1"&gt;</description></item><item><title>re: ActiveSync clients are unable to authenticate with ISA Server/Forefront TMG using SecurID</title><link>http://blogs.technet.com/b/isablog/archive/2010/04/19/activesync-clients-are-unable-authenticate-with-isa-server-forefront-tmg-using-securid.aspx#3326688</link><pubDate>Tue, 20 Apr 2010 10:59:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3326688</guid><dc:creator>Kremersp</dc:creator><description>&lt;p&gt;I was looking for this information. Thanks for the clarification.&lt;/p&gt;
&lt;p&gt;Are there any plans to get ISA/TMG to support RSA and basic authentication on the same listener/IP/DNS name?&lt;/p&gt;
&lt;p&gt;Most companies prefer to use a single name for OWA, ActiveSync and Outlook Anywhere, although authentication requirements/methods may vary per service.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3326688" width="1" height="1"&gt;</description></item></channel></rss>