
Also, because Basic Authentication credentials can be cached in web browsers it is recommended to use an additional authentication factor (eg a one-time password from a token) to prevent unauthorized access from public kiosk computers using the cached credentials. Because the credentials are sent “in the clear” the use of SSL is highly recommended for securing them. However Integrated Authentication is not suitable for remote access by people using non-domain member computers, or people who are connecting via proxy servers.īasic Authentication – this uses the HTTP protocol to send the logon credentials to the server. This is useful for internal Outlook Web App access as it simplifies the logon process for domain users (they don’t need to logon once to the computer and then a second time for OWA). Integrated Authentication – this allows domain users who are logged on to domain computers to automatically logon to Outlook Web App.

There are four authentication methods available for Exchange Server 2010 OWA. Other Steps When Changing Outlook Web App Authentication SettingsĮxchange Server 2010 Outlook Web App Authentication Types.Configuring Outlook Web App for Forms-Based Authentication.Configuring Outlook Web App for Integrated Authentication.

Exchange Server 2010 Outlook Web App Authentication Types.
