|
|
| |
|
Exchange Messaging Outlook
Volume 10, Number 14
|
|
|
|
Greetings! Welcome to Vol. 10, No. 14, Oct 13, 2005, of Exchange
Messaging Outlook, a biweekly newsletter about Microsoft Exchange
and Microsoft Outlook. Today's highlights:
Regular features:
Outlook 2003 SP2 Anti-Phishing Support
Service pack 2 for Outlook 2003 added two new security features: all
mail is displayed in plain text only and hyperlinks are disabled in
the Junk email folder, additionally all hyperlinks in messages which
are identified as potential phishing attempts are disabled in any
folder. While you can change a junk email option and enable
hyperlinks globally, HTML rendering in the junk email folder was
removed completely and it can't be enabled globally. You either need
to move the messages to another folder or click on the Infobar to
enable HTML for that message only.
The newest junk mail filter does a very good job and has a low false
positive rate so there should be little need to look in the junk
mail folder, once you have your Safe lists configured. While viewing
junk mail as plain text is less important if you keep the download
external content setting on and only download content for individual
messages as needed, many users and administrators requested this
feature because many users allow all external content.
The reaction to this new security feature surprised me. Many users
are upset that they can't turn HTML on in the junk email folder and
ask "how dare Microsoft tell me what to do?" and "I can protect
myself, I don't need big brother telling me what to do". While
Microsoft should have made plain text in the Junk mail folder
optional, there should be few false positives in the Junk email
folder, and if you can't read the plain text portion, move them to
the Inbox. If the message is not junk, mark it Not Junk and add the
sender's address or domain to the Safe senders list. If Outlook's
junk email filter has a high false positive rate for you, then you
need a different anti-spam scanner, one you can train for the types
of messages you receive.
To enable hyperlinks on messages in the junk email folder, as well
as on messages not classified as junk but which exhibits phishing
characteristics, go to Tools, Options, Preferences tab, Junk Email
button. Remove the check from 'Don't turn on links in messages than
might connect to unsafe sites... ' at the bottom of the dialog.
Microsoft recommends you leave this checked, and I agree. It's not
about being smart enough to know it's probably a phishing or spam
email, it's about accidentally clicking on a link. This feature is
added security and it takes just one click in the Infobar to enable
hyperlinks on messages that are legitimate.
To learn more about Service Pack 2 and the anti-phishing features,
view the
Support WebCast: Overview of Outlook 2003 Service Pack 2
http://support.microsoft.com/?kbid=908366 Blocked External Content Revisited
Outlook 2003's release version included a 'web bug' blocking feature
which prevents automatic downloading of external content, usually
images, but other content, such as style sheets are also blocked.
This feature is good for users in several ways: users can avoid
prompts from Windows dialer as they read messages offline, users
with slow connections can reduce the bandwidth they use, and
everyone can prevent companies or spammers from learning if they
viewed their messages.
I purposely choose not to download any external content and enable
it per message, as necessary, because I don't want someone to know
if, where or from what IP, I read their messages. Unfortunately, too
many users do enable external content for all messages because they
don't want to be bothered with enabling external content as needed.. An incident from last week illustrates why blocking external content
is good for users, bad for newsletters and advertisers and why many
people are opposed to 'web bugs'. I received a message which began
with the following sentence. "It appears from our records that you
are not getting our messages." All I can say is "Oh, really?" I'm
most certainly getting their newsletters and I sometimes even read
them, when the titles are interesting, but I value my privacy and
don't want them to know when I read their messages, so I do what I
can to prevent this information from getting back to them, which is
to leave external content blocked in Outlook 2003. Autocomplete Cache and User Logons
An interesting question about Outlook's autocomplete cache and
security came up this week:
"We are experiencing an issue with the autocomplete naming in
Outlook 2003. The AutoComplete name displays with the name followed
by a UniqueID. The issue is the UniqueID is the user logon name
which presents a security issue. After all, we remove the "last
logon name" from the logon dialog box for the same security reason.
Is there a way to remove the <UniqueID> portion of the AutoComplete
name?
While Microsoft allows a way to NOT see a user ID in the logon
dialog box, it allows it in the autocomplete section using an .NK2
file? This is a huge security issue so I guess my next question
would be is there a way to turn Autocomplete off?" I'm not sure this problem qualifies as a security issue. What they
are seeing in the autocomplete cache is the Exchange mailbox alias,
which just happens to be the user logon account at their site. Many
sites use the account name as the default SMTP alias, but even if
you create a different default SMTP alias, it's visible in the GAL,
and anyone with access to the GAL can open the contact record and
view it. It can be removed from the GAL, but then users can't log on
to OWA using an email address. When you send a message internally, the display name and exchange
alias are stored in the autocomplete cache. This is normal - on my
server it's "Diane Poremsky <dianep>". In their case, it looks like
Bill Smith <123456>, displaying the same logon id they don't want
stored in the logon screen for security reasons. Had they configured
the account differently, it could show "Bill Smith <bsmith>" in
autocomplete and the user account name would not be seen, even in
the GAL.
When many sites create a user account in the AD, they enter the user
account logon name and OK their way thru the screens, accepting the
defaults for the exchange alias, which by default, just happens to
be the same as the user account logon.
If you want to keep the logon separate from the exchange alias, you
should create the user account in the AD and enter the user logon
name as usual, but once you get to the Create Exchange mailbox
screen, enter a different name for the Exchange alias. When the user
logs on to Windows using his user account, he'll be logged into the
mailbox as usual, even though the user account and mailbox name are
different, unless Outlook was configured to require the username and
password when accessing the mailbox.
If this is a problem for your company and changing the Exchange
mailbox name is not a workable solution, you can disable
autocomplete in Tools, Options, Preferences, Email options button,
Advanced Email options. Remove the checkmark from Suggest names
while completing TO, CC, and BCC fields near the bottom of the
dialog.
|
 |
|
|
New Utilities
|
FREEBUSY FOR OUTLOOK
http://freebusy.4team.biz/?pcode=508260136ovkjc2
MS Outlook add-on automatically creates and sends e-mail auto
reply from your custom templates based on your Status (Away, Out
of Office, Vacation, custom Status or Calendar Free/Busy time).
Allow response to selected Contacts or Distribution lists.
Version 1.20.0049 LBE FIND & REPLACE FOR MS OUTLOOK
http://www.outlook-find-replace.com
LBE Find & Replace for MS Outlook lets you Search and replace in
Outlook Contacts, Emails, Appointments, Notes and Tasks. Free
trial available.
OUTLOOKPRINTER
http://www.outlookprinter.com/
Use OutlookPrinter to customize your look of your emails easily
and print just the part of the email you need. It also allows
you to list the attachments or print them out directly. PSTSYNC
http://www.pstsync.com
Use PSTSync to perform Outlook synchronizations, helping you
synchronize every Outlook folder, even custom created ones.
PSTSync provides bi-directional folder synchronization as well
as a number of other tools to help you manage your pst files
with ease, PSTSync offers SmartMove and SmartCopy functionality
as well as Encryption, Password Protection, Online Backup as
well as the popular built in PST file viewer. SPAMFIGHTER EXCHANGE MODULE
http://www.spamfighter.com/product_sem.asp
SPAMfighter Exchange module (SEM), is an easy-to-use anti-spam
solution for Microsoft Exchange Servers. SEM delivers instant
spam protection with no configuration or maintenance, to help
small and medium businesses filtering time consuming spam. |
 |
|
Updated Utilitiesties
|
EXCHANGE GROUPCALENDAR
http://www.exchangegroupcalendar.com/
This Active Directory integrated tool for Exchange server 2000/2003
monitors user & resource calendars and collates the appointments in
Public Folders. You can configure what type of content every
individual public calendar will contain based on the properties of
the original item. It can also change the appointment-copy in the
public calendar to obscure, convert or enhance the original
appointment properties. New features include improved
administration, import of existing calendars, additional interface
languages, reporting and a utility to export public folder calendar
data to Excel/html. Version 1.30 works with Exchange 2000/2003.
IMI GAL EXPORTER
http://www.imibo.com/imidev/Exchange/imige.htm
IMI GAL Exporter for Microsoft Exchange Server is small utility for
Exchange Admin to export GAL (Global Access List) to a Microsoft
Access 2000 table. Also available is IMI Distribution List Content
Exporter, a small add-in used to export the contents of Distribution
Lists to an Access 2000 table. Now supports custom attributes and
multi-value entries for phone entries. Version 3.
LUCATEC MASK
http://www.lucatec.net/mask/maskoverview-en.htm
The Lucatec Mask Add-in for Outlook is used with Exchange server
accounts which allows you to reply from a shared mailbox or public
folder, automatically entering the folder or mailbox's email address
in the From field. Lucatec Mask will automatically determine the
correct sender address to use based on the mailbox or public folder
the user is currently using in Outlook. It also offers the option to
move or copy the sent message to the relevant account's Sent Items
folder (or Public Folder) and define sender addresses and target
locations for sent items for individual folders or even globally for
all sent messages. It supports shared Exchange Server mailbox
accounts and Public Folders with email addresses and was tested with
Exchange Server 5.5 and 2000, Microsoft Outlook 2000 and XP. Version
1.2.2
PROFILER
http://www.dirwiz.com/products/index.shtml?profiler.html
Profiler gives the typical end user the ability to update their
directory information (telephone number, office location etc) using
their browser. Because the software is web based, deploying the
solution is as easy as giving your users the correct URL or adding a
link to your intranet. Supports Exchange 5.5/2000/2003 and OpenLDAP,
LDAP v3 (including SSL) for directory updates. Updating membership
of Groups and Distribution lists are now supported. Version 4.5
SHAREO FOR OUTLOOK
http://shareo.4team.biz/?pcode=409220071fmbb2r
Share your Outlook calendar, contacts, journal, mail, tasks and
notes folders with other Outlook users, without a server, with this
utility. Version 2.15.0034 |
 |
|
Other Resources
|
CHANGES TO CUSTOM PROPERTIES IN OUTLOOK 2003 SERVICE PACK 2
http://support.microsoft.com/default.aspx?scid=KB;EN-US;907985
To guarantee consistent use of custom properties, or fields, Microsoft Office
Outlook 2003 Service Pack 2 (SP2) and later versions of Outlook limit some of
the ways that custom properties can be introduced into Outlook data stores. For
example, custom properties can be introduced in specific ways in Outlook
personal folders (.pst) files.OFFICE 2003 SP2
http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=57e27a97-2db6-4654-9db6-ec7d5b4dd867
SP2 contains a number of fixes, including one for SMTP problems, and a new
phishing protection feature that's works with the Outlook Junk Email Filter to
warn you of potential phishing attempts.
OUTLOOK LIVE 2003 SERVICE PACK 2
http://support.microsoft.com/?kbid=902848
Outlook Live subscribers who use the subscription service version of Outlook
need to download and install this service pack. The general Office 2003 SP2 will
not install with the downloaded version of Outlook supplied by Outlook Live.
SUPPORT WEBCAST: NEW FEATURES IN THE BUSINESS CONTACT MANAGER UPDATE FOR OFFICE
2003
http://support.microsoft.com/?kbid=908467
This Support WebCast describes new features in the Business Contact Manager
Update for Microsoft Office 2003. Some of the topics will include: System
requirements, a brief technical overview of BCM and the Microsoft SQL Server
2000 Desktop Engine (MSDE), database sharing, accounting integration, Pocket PC
synchronization support, and a brief introduction to troubleshooting
SUPPORT WEBCAST: OVERVIEW OF OUTLOOK 2003 SERVICE PACK 2
http://support.microsoft.com/?kbid=908366
This WebCast discusses some of the new Microsoft Outlook features that are
included in Microsoft Office 2003 Service Pack 2 (SP2). New features that will
be discussed include updated junk e-mail functionality, changes to Calendar
meeting processing, and support for Microsoft Exchange Server 2003 SP2 Offline
Address Book, version 4. |
 |
|
New Exchange Knowledge Base Articles
|
The IMailBox.BaseFolder, IMailBox.RootFolder, and IMailBox.Inbox CDOEX
properties may return blank values when you use script code to access a
hierarchy of folders that belongs to a person
http://support.microsoft.com/?kbid=899351
The event sink does not fire as expected on a computer that has both Exchange
2000 SP2 and ScanMail for Exchange version 6 installed
http://support.microsoft.com/?kbid=810150 |
 |
|
New Outlook Knowledge Base Articles
|
You receive an "Unable to update Public free/busy data" error message when you
quit Outlook 2002 after you add a new appointment to a delegate's calendar
http://support.microsoft.com/?kbid=905814
Description of the Outlook 2002 post-Service Pack 3 hotfix package: August 30,
2005
http://support.microsoft.com/?kbid=905864
Description of the Outlook 2003 Junk E-Mail Filter update: September 2005
http://support.microsoft.com/?kbid=904631
Issues that are fixed in Outlook 2003 by Office 2003 Service Pack 2
http://support.microsoft.com/?kbid=906451
Description of Outlook Live 2003 Service Pack 2
http://support.microsoft.com/?kbid=902848 |
 |
|
More Information
|
ISSN 1523-7990
Copyright 1996-2006, Slipstick Systems and CDOLive LLC. All rights reserved.
|
|
|
|