Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Microsoft
[Top] [All Lists]

Re: Security and Implications of Hosted Exchange

Subject: Re: Security and Implications of Hosted Exchange
Date: Fri, 16 Nov 2007 10:23:55 -0700
Past companies I have worked with, who have used Hosted Exchange services, the provider used SSL to secure the access.

OWA over SSL
and also RPC over HTTPS (SSL) for direct Outlook client Access. (2003 and Newer Outlook Clients I believe)


As for the user info, the providers I saw in use, did not need nor require any user info. The providers had Web Based administration to add/remove/edit user accounts, and the person doing this filled in as much or little personal info as they want.

I also assume that being it is a hosted solution, they farm out the exchange server to numerous other companies, but if done right, you never noticed, you don't see the other clients in the GAL nor the Public Folders.

The biggest concern I had with this method was Data Recovery... If the provider should go under, what means and legalities are needed to obtain your data back from them?

Hope that helps somewhat.



On 16-Nov-07, at 9:34 AM, Roland Dobbins wrote:


On Nov 15, 2007, at 11:11 AM, Dan Denton wrote:

But, having the features of
Exchange without having to backup/restore the system or worry about patches
and fixes is pretty attractive.

I'm sure at least some of the folks who offer hosted Exchange would also offer a VPN service whereby the Exchange server wouldn't be exposed to the general Internet (or to other servers for other customers), but would be isolated with all appropriate network, host OS, and application BCPs, and accessible only via a VPN of some sort.


-----------------------------------------------------------------------
Roland Dobbins <rdobbins@cisco.com> // 408.527.6376 voice

        Culture eats strategy for breakfast.

          -- Ford Motor Company



<Prev in Thread] Current Thread [Next in Thread>