Exchange Messaging Outlook
Volume 12, Number 10

Issue Date: August 23 2007

   

 

Today's highlights:

Regular features:



Configuring Outlook Anywhere Overview

by William Lefkovics

Exchange 2003 and Outlook 2003 introduced a unique method for accessing Exchange server from both sides of the firewall securely without a VPN. RPC over HTTPS in Exchange 2007 and Outlook 2007 is now called simply Outlook Anywhere. Rather than opening up several RPC ports, RPC is tunneled through HTTP. With SSL, only port 443 needs to be available for Outlook Anywhere to work outside of the firewall. Outlook Anywhere requires Outlook 2007 or Outlook 2003 installed on Windows XP SP2 or Windows Server 2003. Outlook 2003 clients can use Outlook Anywhere as they did RPC over HTTPS, but they cannot take advantage of the Autodiscover Service and will need to be configured manually.

Outlook needs to trust the Certificate Authority (CA) issuing a valid SSL certificate. The SSL certificates used by Exchange for OWA and ActiveSync do not apply to Outlook Anywhere. You can either serve as your own CA or use a third party provider. After the SSL certificate is correctly installed, then the RPC over HTTP proxy component needs to be installed. On the Exchange Server, this is found under Add/Remove Programs in the Add/Remove Windows Components under the Networking Services heading. After that Windows component is installed, we still have to enable Outlook Anywhere on the Exchange Server.

Outlook Anywhere in Exchange 2007 is not enabled by default. The Outlook Anywhere wizard is run from an Exchange Server running the Client Access Server (CAS) role. From the Exchange Management Console (EMC), navigate to the Client Access node in the Server Configuration container. The right pane should have the option to ‘Enable Outlook Anywhere’. If it is already enabled, then the option will be to disable it. That opens the window shown in Figure 1.

Figure 1


We can configure basic or NTLM authentication here, and also allow SSL offloading. In addition, we need to assign an external name for the server. We can also use the Exchange Management Shell (EMS) to enable or disable Outlook Anywhere:

>Enable-OutlookAnywhere -SSLOffloading <$True|$False> -ExternalHostname <fqdn> -ExternalAuthenticationMethod: <Basic|NTLM>

Microsoft recommends using NTLM authentication over SSL provided by a third party certificate authority. The switch options are required. If the required options are not included, EMS will prompt for them. Figure 2 shows sample output of this cmdlet. In this output, SSLOffloading is set to True. This means that SSL encryption processes are being managed by a separate server or device and should be set to False if that is not the case.

Figure 2


The other cmdlets pertaining to Outlook Anywhere are:

Disable-OutlookAnywhere
Set-OutlookAnywhere
Get-OutlookAnywhere

Finally, the clients need to be able to find and access Outlook Anywhere. For Outlook 2007, the AutoDiscover service can assist when the services are configured to provide external URLs. When the external URLs are different from the internal ones, Microsoft recommends a certificate that allows for multiple hosts on the same certificate called a Subject Alternative Name Certificate. For the first Outlook Anywhere client, a manual configuration may ease troubleshooting, including SSL certificate issues. Outlook Anywhere is configured within the Account Settings for the Exchange account. Select the Exchange account in Tools -> Account Settings -> More Settings button. The bottom of the Connections tab presents the box to check for Outlook to use HTTP. The Exchange Proxy Settings button opens the window shown in Figure 3. Outlook 2003 will have to be configured manually as before, because it does not know about the Autodiscover service.


Figure


Summary

So to deploy Outlook Anywhere there are a few steps to walk through:
  • Install a valid SSL certificate from a CA Outlook can trust
  • Install the Windows RPC over HTTP proxy component from Network Components in Add/Remove Windows Components under Add/Remove Programs
  • Enable Outlook Anywhere using EMS or EMC on an Exchange 2007 server running the CAS role
  • Configuring Outlook clients to access Outlook Anywhere
In the 2007 versions, Outlook Anywhere, formerly RPC/HTTPS, is much simpler to deploy and configure.

OWA 2007's Missing Month View

The calendar in Outlook Web Access 2007 does not include a month view. Microsoft hopes to bring a month view back in a later version, but for now, its day, work week, and week views only. Additionally, these views are available only in the premium OWA client which is available in Internet Explorer. The OWA "light" client, which displays in all other browsers, offers a day view only.

The good news is that Exchange 2007 SP1 is the "future version" and contains a month view in the premium version while the light version continues to have a day view only.

IE6+ on Windows is the only supported version for OWA Premium because of the cost, time constraints, and customer needs. A small percentage of users use something other than IE6 or greater on Windows and an even smaller percentage of this group need to access an Exchange server. At this time the cost to tweak the advanced AJAX behaviors used by OWA for this small group with is better spent on improving other aspects of OWA (including adding new features).

Exchange 2007 SP1 Beta 2

Exchange Server 2007 Service Pack 1 Beta 2 was released to MSDN and TechNet Plus subscribers last week. I can honestly say I'm impressed with the features in this SP.

I've always felt that upgrading to Exchange 2007 RTM was not an option for smaller sites because the Exchange Management Console lacked a GUI to configure many frequently used settings. That's not going to be an excuse much longer. SP1 adds a GUI for configuration many common options, including public folders, POP and IMAP access. A wizard guides you through setting SendAs permissions.

OWA gets back a lot of features left out of Exchange 2007 RTM due to time constraints. This includes personal distribution lists, S/MIME, rules, the monthly calendar view, deleted items recovery, and public folder access.

Among the other improvements in SP1, you can install the management tools on Windows Vista and Windows Server 2008 and the Move Mailbox administrator tool can import and export to a .pst

Standby Continuous Replication (SCR) is new feature providing high-availability to organizations, allowing them to quickly recover from failures. Mailbox data is continuously replicated to a standby server using the built-in log file shipping technology so that if the primary server goes down, the standby server is ready to be activated.

Release notes
http://download.microsoft.com/download/5/e/6/5e672458-592a-44a2-b489-11cec19d3c82/RelNotes.htm 
Back to Top  

New Utilities

Active Directory UserMod Assistant
http://sourceforge.net/projects/adumass
This tool allows individual users the ability to update their information in Active Directory and thus, the GAL. Version 0.8.1.

ArchiveOne
http://www.c2c.com/site/products/archiveone/default.asp
Exchange Archiving. Cost effective solution for managing email retention policies, reducing mailbox size, storage costs and maintaining compliance.

IMI ADODB ExMAPI Address Book Provider
http://www.imibo.com/imidev/delphi/DownToTheMetal/IMIMADO/Default.htm
Knowing both ADO and Extended MAPI very well one may develop one's own design of MAPI Service Provider that would unify them. We started off with the easiest to implement but also most commonly used Service Provider - Address Book. The current version included in the project consists of two parts - an Administrative part and the Address Book Provider itself. In the administrative part one can create new entries (contacts) in the database that will be accessible afterwards in Outlook through our Address Book.

Mimosa NearPoint
http://www.mimosasystems.com/html/prod_nearpoint.htm
Reduce the size of your Exchange storage by up to 90%. Extend mailboxes using parameters such as message size, age, and mailbox size. Extended messages appear as normal but with a new stub file icon. Auditors can quickly search, review, and export results for compliance purposes.

OWA themes for Exchange 2007 SP1
http://msexchangeteam.com/archive/2007/08/14/446663.aspx
Xbox and Zune themes for OWA 2007.

Public Folder Watcher
http://www.artfulbits.com/Products/PublicFolderWatcher.aspx
Public Folder Watcher (PFW) is an add-on for Microsoft Outlook enabling support of notifications about changes in Exchange Public Folders and providing a status of unread email messages. It works similar to standard Outlook email notifications, but also has several additional features that may be useful for those who use Public Folders. The add-on is integrating into Microsoft Outlook and providing access to its settings through menu in Outlook.

SPAMfighter
http://www.spamfighter.com/product_sem.asp
Anti-spam tool based on peer reporting, blacklist, and whitelist techniques. Can handle any type of Outlook account -- POP, IMAP, Exchange, Hotmail.

Back to Top  

Updated Utilities

eMailSignature
http://www.officeaddon.com/products_overview.shtml
The original signature solution for Outlook and OWA. Use the built-in editor to create, design and manage email signatures centrally. Ensure company logos and merge employee information from Active Directory or any other data source. All signatures are visible for users before sending. Automatic RTF and TEXT version creation and no installations on either clients or Exchange Server required. Simple deployment through logon script or GPO. Extra modules for deploying vCards, campaigns, disclaimers and much more. Central administration through an administrative interface with built-in security and previewing. Free trial available.

Outlook Connector
http://www.microsoft.com/downloads/details.aspx?FamilyID=7aad7e6a-931e-438a-950c-5e9ea66322d4&displa
Use the Outlook Connector with Outlook 2003 or Outlook 2007 to access and manage Windows Live Hotmail or Office Live Mail accounts. Works with free accounts for E-mail messages and contacts. Paid subscriptions also support syncing the Calendar, Tasks, and Notes. Version 3.
Back to Top  

Other Resources

PDF spam – a step ahead of image spam
http://www.gfi.com/whitepapers/attachment-spam.pdf
This white paper, written by GFI, explains what makes spam such an unbearable problem and how spamming tactics are evolving daily to beat anti-spam software. The latest tactic is to use the common PDF file format to send image spam. By using PDF attachments to send images instead of embedding them in the body of the email message, spammers have taken the cat-and-mouse game with anti-spam software developers to a new level. The white paper also explains how the latest forms of spam, Excel spam and ZIP spam, are raiding mailboxes worldwide.
Back to Top  

New Exchange Knowledge Base Articles

A URL that includes a "notes:" prefix does not work in Outlook Web Access for Exchange 2003
http://support.microsoft.com/?kbid=939999

Appointments may be incorrect by one hour when appointments are sent between a Lotus Notes organization and an Exchange Server organization
http://support.microsoft.com/?kbid=928655

Appointments that are sent between different Exchange Server organizations may be incorrect by one hour when one of the organizations is in the Western Australia time zone
http://support.microsoft.com/?kbid=929895

Clients cannot log on to Exchange Server 2007 mailboxes by using Outlook or Outlook Web Access in a mixed Exchange Server 2003 and Exchange Server 2007 environment
http://support.microsoft.com/?kbid=938444

Error message when an account tries to open a mailbox by using Outlook Web Access or Exchange Web Services in Exchange Server 2007: "You do not have permissions to open this mailbox"
http://support.microsoft.com/?kbid=940846

Error message when you try to log on to Exchange 2007 by using Outlook Web Access: "440 Login Timeout"
http://support.microsoft.com/?kbid=941201

Error message when you try to use the spelling checker in Outlook Web Access: "Your Exchange server is busy and can't check spelling at this time. Try again later"
http://support.microsoft.com/?kbid=940011

Event ID 1036 is logged on an Exchange 2007 server that is running the CAS role when mobile devices connect to the Exchange 2007 server to access mailboxes on an Exchange 2003 back-end server
http://support.microsoft.com/?kbid=937031

Event ID 31092 is logged when the Microsoft Exchange Server 2003 Connector for Lotus Notes delivers an Internet e-mail that contains recipients in only the Bcc box
http://support.microsoft.com/?kbid=939954

Non-English characters in the meeting description field are replaced by question marks when an Exchange Server 2007 user opens a meeting invitation that was sent by a Lotus Notes user
http://support.microsoft.com/?kbid=940058
 
Public folder replication issues that occur after you install Exchange 2007 in an existing Exchange 2003 organization
http://support.microsoft.com/?kbid=939764
 
The Setup program stops responding, and event ID 1031 is logged when you try to install or to reinstall Exchange Server 2003 in Disaster Recovery mode
http://support.microsoft.com/?kbid=940725
 
Users cannot download offline address books in Exchange 2007 when you use Microsoft Solution for Hosted Messaging and Collaboration version 4.0
http://support.microsoft.com/?kbid=939560
 
Warning message when you start Outlook 2007 and then connect to a mailbox that is hosted on an Exchange 2007-based server: "The name of the security certificate is invalid or does not match the name of the site"
http://support.microsoft.com/?kbid=940726
 
You cannot use a 3DES-based Secure Sockets Layer (SSL) connection to connect to Exchange 2003
http://support.microsoft.com/?kbid=938857
 
You experience problems in an Exchange 2003 and Lotus Note mixed environment after daylight saving time (DST) starts in New Zealand in 2007
http://support.microsoft.com/?kbid=937655
 
You may receive duplicate e-mail messages after a CCR cluster fails over unexpectedly in Exchange Server 2007
http://support.microsoft.com/?kbid=940031
Back to Top  

New Outlook Knowledge Base Articles

A hotfix is available to adjust the daylight saving time (DST) dates for New Zealand in Outlook 2007
http://support.microsoft.com/?kbid=940557
 
A new feature is available that enables Outlook 2007 to use DNS Service Location (SRV) records to locate the Exchange Autodiscover service
http://support.microsoft.com/?kbid=940881
 
An e-mail item is unexpectedly saved to a user's local .pst file when you use Group Policy to prevent the user from adding a .pst file to his or her profile in Outlook 2007
http://support.microsoft.com/?kbid=940555
 
CDOs are not updated to support a newly created Group Policy object in Outlook 2007
http://support.microsoft.com/?kbid=926195
 
Description of the 2007 Office hotfix package: July 7, 2007
http://support.microsoft.com/?kbid=939870
 
Description of the Outlook 2003 Junk E-mail Filter update: August 14, 2007
http://support.microsoft.com/?kbid=936643
 
Description of the Outlook 2007 hotfix package: June 29, 2007
http://support.microsoft.com/?kbid=939596
 
Description of the Outlook 2007 Junk E-mail Filter update: August 14, 2007
http://support.microsoft.com/?kbid=936644
 
Error message when you perform an action that opens a custom form in another user's mailbox in Outlook 2007: "The form you selected cannot be displayed"
http://support.microsoft.com/?kbid=940556
 
Error message when you press F9 to send and receive e-mail messages in Outlook 2007: "TASK 'Microsoft Exchange Server' reported error (0x8004010F)"
http://support.microsoft.com/?kbid=940559
 
Error message when you try to synchronize Outlook to a Windows Live Hotmail account: "Error with Send/Receive"
http://support.microsoft.com/?kbid=941198
 
How to deploy the "Always prompt for user name and password" setting for all users in Outlook 2003
http://support.microsoft.com/?kbid=940171
 
How to troubleshoot performance issues in Outlook 2007
http://support.microsoft.com/?kbid=940226
 
Outlook 2007 does not use the Windows "Selected Items" color to select an item
http://support.microsoft.com/?kbid=940553
 
Reminders for flagged e-mail messages are not displayed in Outlook 2002
http://support.microsoft.com/?kbid=940168
 
The owner of the e-mail message thread changes when an Outlook 2003 user responds to an Information Rights Management (IRM)-protected message that was sent from an Outlook 2007 user
http://support.microsoft.com/?kbid=931217
 
The public free/busy information for a resource is missing when you schedule a meeting in Outlook 2007
http://support.microsoft.com/?kbid=940558
 
Warning message when you start Outlook 2007 and then connect to a mailbox that is hosted on an Exchange 2007-based server: "The name of the security certificate is invalid or does not match the name of the site"
http://support.microsoft.com/?kbid=940726
 
You cannot rename an attachment in an e-mail message in Outlook before you send the e-mail message
http://support.microsoft.com/?kbid=940792
Back to Top   

More Information

ISSN 1523-7990
Copyright 1996-2006, Slipstick Systems and CDOLive LLC. All rights reserved.