Outlook Anywhere vs Activesync and Enterprise Security

Status
Not open for further replies.

byteguy

Member
Outlook version
Outlook 2013 64 bit
Email Account
Exchange Server
I would like to deploy new MS Surface Pro 2s (SP2s) installed with Windows 8.1 and MS Office 2013. I will keep these outside the corporate firewall so that users can install non company standard apps (as they currently do on iPads). However, unlike with iPads, they can enjoy a fully featured MS Office experience for work related activities. However, the key ‘connection’ they will have to the corporate systems will be email.

I am responsible for my local office’s IT infrastructure which is limited to LAN connected desktops and a local domain for file and print services. Our Exchange environment recently was migrated to our HQ.

I have encountered a roadblock with corporate IT. I would like to use Outlook 2013 on the SP2s connecting via Outlook Anywhere when working remotely (as we do with existing company issued laptops). Corporate IT will only permit an Activesync connection, as is used with company issued iPads. I believe that Outlook 2013 will not work with Activesync which would require us to use the (sadly disappointing) Windows8.1 email client – it won’t be a great experience for our users.

I have countered various arguments regarding ActiveSync benefits (remote wipe, forced encryption, forced passwords) but have encountered one argument that I can’t readily answer. Corporate IT insist that their Exchange environment is more vulnerable if a user’s SP2 is connected to Exchange via Outlook Anywhere rather than Activesync and it becomes compromised by a virus, Trojan or other hack (by using personal apps such as Skype, iTunes, games, etc.).

I can’t find a definitive answer, in my searching, that compares the vulnerability of the enterprise Exchange server when connecting to compromised clients via Outlook Anywhere rather than ActiveSync.

Can anyone help as well as direct me to a MS issued paper that answers this in a manner that corporate IT, or I, can’t refute?
 

Diane Poremsky

Senior Member
Outlook version
Outlook 2016 32 bit
Email Account
Office 365 Exchange
I'm not sure why they are treating the surface any differently than the laptops? Both should be treated the same.

And yes, you are correct, outlook can't use ActiveSync - they'd have to use the builtin mail app or OWa.

IT is incorrect - outlook is secure against viruses. I don't have any documentation for security EAS vrs Outlookanywhere, but I believe they are both equally secure.
 

byteguy

Member
Outlook version
Outlook 2013 64 bit
Email Account
Exchange Server
I'm not sure why they are treating the surface any differently than the laptops? Both should be treated the same.

And yes, you are correct, outlook can't use ActiveSync - they'd have to use the builtin mail app or OWa.

IT is incorrect - outlook is secure against viruses. I don't have any documentation for security EAS vrs Outlookanywhere, but I believe they are both equally secure.

Thanks for your confirmation, Diane. In order for me to convince my IT HQ of this, I doubt that they would accept anything but an MS tech document or a paper from another credible third party analyst. Do you have any guidance as to where I will find such? I have already spent half a day in Google but drawing blanks. Another possible option is for a persuasive document that compares how a client connecting to Exchange via EAS is any different from one connecting via Outlook Anywhere, in particular, whether a compromised client can more easily gain access to the corporate Exchange environment. Please note that these SP2s will have Symantec Endpoint Protection (stand-alone) just as any domain connected laptop - except they will never join the domain.
 

Diane Poremsky

Senior Member
Outlook version
Outlook 2016 32 bit
Email Account
Office 365 Exchange
I'll see what i can find.

They'll only have access to the Exchange server either way.
 

byteguy

Member
Outlook version
Outlook 2013 64 bit
Email Account
Exchange Server
I'll see what i can find.

They'll only have access to the Exchange server either way.

Another related thought: while never having used it, doesn't MS offer its Office 365 suite, to enterprises and individuals, in a configuration that permits the client end to be a full blown Outlook client that connects via Outlook Anywhere to MS's Office 365 Exchange infrastructure? If so, could it be argued that MS has no way of knowing whether the client PCs connecting are compromised by some kind of malware? If this is the case, would they have any better protection from untrusted connecting clients than a enterprise would have with their own Exchange farm? I guess I am asking "if Outlook Anywhere is deemed safe by MS, with untrusted clients, why would an enterprise feel differently?" Any idea the approximate number of clients that Office 365 sees connecting via Outlook Anywhere?
 

Diane Poremsky

Senior Member
Outlook version
Outlook 2016 32 bit
Email Account
Office 365 Exchange
100% of the outlook clients connecting to office 365 use outlook anywhere - it's the only way. I have no idea of the number, but it's in the millions.

Did they give any specifics about why they think outlook anywhere is unsafe?
 

Diane Poremsky

Senior Member
Outlook version
Outlook 2016 32 bit
Email Account
Office 365 Exchange
i don't think these articles will help any - they cover it more from the angle of SSL and someone sniffing email or credentials, which would apply to ActiveSync too, rather than security from the standpoint of viruses and such. From the security/virus angle, the rpc connection is secure - a virus could only get in via email and outlook is secure against viruses.

http://social.technet.microsoft.com...0/thread/140eca3f-bea0-4e40-a74f-9ed7ede6cd3a

Understanding Security for Outlook Anywhere

http://technet.microsoft.com/en-us/library/bb430792.aspx

Securing Client Access Servers

http://technet.microsoft.com/en-us/library/bb400932.aspx
 

Diane Poremsky

Senior Member
Outlook version
Outlook 2016 32 bit
Email Account
Office 365 Exchange
I wonder if they read this article - http://www.computerworld.com/s/arti...nager_s_Journal_Closing_off_a_hole_in_Outlook

If so

1) ActiveSync is a problem too - users can add an account to any win8 computer. Once mail is downloaded to a surface, the user can do anything they want with it, just like they can with outlook.

2) "A few weeks ago, the manager of a local hotel called to tell us that the hotel staff had discovered over 1GB of our company email on the computer in the hotel lobby. " WTF? The problem isn't Outlook Anywhere, it's the idiot user who created an outlook profile on someone else's computer... i can't believe a computer in the hotel lobby has outlook or that they don't reimage nightly. Or that the user was dumb enough to set up a profile on it - they should be using OWA on public computers. But making users use active sync isn't going to prevent this, they can still create accounts in Mail apps on other computers - only educating users will prevent this.
 

byteguy

Member
Outlook version
Outlook 2013 64 bit
Email Account
Exchange Server
I wonder if they read this article - http://www.computerworld.com/s/arti...nager_s_Journal_Closing_off_a_hole_in_Outlook

If so

1) ActiveSync is a problem too - users can add an account to any win8 computer. Once mail is downloaded to a surface, the user can do anything they want with it, just like they can with outlook.

2) "A few weeks ago, the manager of a local hotel called to tell us that the hotel staff had discovered over 1GB of our company email on the computer in the hotel lobby. " WTF? The problem isn't Outlook Anywhere, it's the idiot user who created an outlook profile on someone else's computer... i can't believe a computer in the hotel lobby has outlook or that they don't reimage nightly. Or that the user was dumb enough to set up a profile on it - they should be using OWA on public computers. But making users use active sync isn't going to prevent this, they can still create accounts in Mail apps on other computers - only educating users will prevent this.

Thanks for all the links. I have already reviewed most of them. I also have sent across a 'request' to HQ to consider that seeks to draw comparisons to EAS but also relevance to our company owned SP2s (unlike the hotel faux-pas our data 'should' only be on the SP2). I can't answer your question on why they think OA is not secure as my initial feedback has been vague. The iniital position is that OA would connect an untrusted SP2 directly to their Exchange. I am trying to work through their concerns in a constructive way -- which I thought would benefit from a definitive MS document that would dispell their fears or, at least, categorically, clarify that OA expsoures are not greater that EAS exposures. I might find that their concerns are well placed but my research to date doesn't support this.
 
Status
Not open for further replies.
Similar threads
Thread starter Title Forum Replies Date
C outlook 2016 and outlook anywhere Using Outlook 1
R Outlook anywhere Using Outlook 1
M Autodiscover not configuring Outlook Anywhere Using Outlook 10
e_a_g_l_e_p_i Need clarification on 2-Step Verification for Gmail using Outlook 2021 Using Outlook 0
L Opening People Outlook 2021 Using Outlook 0
e_a_g_l_e_p_i Outlook 2021 not letting me setup my Gmail using pop Using Outlook 1
Geldner Problem submitting SPAM using Outlook VBA Form Outlook VBA and Custom Forms 2
P VBA to add email address to Outlook 365 rule Outlook VBA and Custom Forms 0
M Outlook 2016 outlook vba to look into shared mailbox Outlook VBA and Custom Forms 0
P Can no longer sync Outlook with iPhone calendar after iPhone update to 17.1.1 Using Outlook 2
O Outlook - Switch from Exchange to IMAP Using Outlook 0
e_a_g_l_e_p_i Is it possible to have a reminder in Outlook 2021 for every 90 days Using Outlook 3
farrissf Outlook 2016 Optimizing Email Searches in Outlook 2016: Seeking Insights on Quick Search vs Advanced Search Features Using Outlook 0
C Advanced search terms for "Outlook Data File" Using Outlook 1
N Reply to Outlook messages by moving messages to a specific Outlook folder Outlook VBA and Custom Forms 1
O How to find out the domain and server settings that my Outlook is using? Using Outlook 2
A Outlook 365 (OutLook For Mac)Move "On My Computer" Folder Items From Old To New Mac Computer Using Outlook 3
H Integrating Alexa & Outlook Pro 2021 Using Outlook 2
Z Automatically adjust Outlook Reading Pane from bottom to right depending on portrait or landscape window Using Outlook 1
Rupert Dragwater Background colors not saving in Outlook 365 Using Outlook 15
petunia Outlook tasks module sunsetting? Exchange Server Administration 3
G Save emails as msg file from Outlook Web AddIn (Office JS) Outlook VBA and Custom Forms 0
D Outlook VBA forward the selected email to the original sender’s email ID (including the email used in TO, CC Field) from the email chain Outlook VBA and Custom Forms 3
U Outlook 2021 not showing contact cards in Searches Using Outlook 1
C Outlook - Macro to block senders domain - Macro Fix Outlook VBA and Custom Forms 2
H Outlook 365 O365 outlook calendar item editing Using Outlook 1
J Outlook 365 html inline images Using Outlook 0
Rupert Dragwater How to get Outlook 365 to open from websites Using Outlook 5
S Why do I have to close and reopen Outlook for macros to work? Outlook VBA and Custom Forms 2
J Outlook 2021 ScanPST errors (yet again ... sorry): repair button missing Outlook 2021 Using Outlook 0
HarvMan Outlook 365 - Rule to Move an Incoming Message to Another Folder Using Outlook 4
K Moved pst to new computer, now Gmail not coming into Outlook Using Outlook 7
S Email Macros to go to a SHARED Outlook mailbox Draft folder...NOT my personal Outlook Draft folder Using Outlook 2
F Running Scripts in Outlook 2021 Using Outlook 0
Nufc1980 Outlook "Please treat this as private label" auto added to some emails - Help. Using Outlook 3
S Outlook 2019 Custom outlook Add-in using Visual Studio Outlook VBA and Custom Forms 0
V Outlook macros no longer run until VB editor is opened Outlook VBA and Custom Forms 0
R Outlook 365 How to integrate a third-party app with Outlook to track email and sms? Using Outlook 2
e_a_g_l_e_p_i I can't believe what I am seeing when trying to install Outlook 2021 Using Outlook 9
Kika Melo Outlook Calendar deleted appointments not in Deleted Items folder Using Outlook 3
P How to get a QR code for automatic signin with Outlook for iOS Using Outlook 5
J Migrating Outlook Using Outlook 1
Retired Geek Outlook for the MAC with Yahoo accounts now very broken Using Outlook 9
S Outlook 2002- "Send" button has disappeared. Help please. Using Outlook 1
L How Stop Outlook Nag Messages Using Outlook 1
TomHuckstep Remove Send/Receive All Folders (IMAP/POP) button from Outlook 365 Ribbon Using Outlook 2
L I Cannot Sign Into My Outlook Account? Outlook VBA and Custom Forms 0
icacream Outlook 2021 - Google calendar in the peek Using Outlook 0
e_a_g_l_e_p_i Question about installing my Gmail account on my iPhone but still getting messages downloaded to my desktop Outlook. Using Outlook 3
F Want to add second email to Outlook for business use Using Outlook 4

Similar threads

Top