......

News

Date : 14 Sep 2016

HOW-TO: How to protect and authenticate your Microsoft applications?

news


Most of our customers use Microsoft applications such as Sharepoint, OWA (Outlook Web Access), Exchange, Lync, etc. Unfortunately, this ecosystem often relies on propriatery protocols like RPC that require special attention. Besides, administrators may wish to enhance authentication requirements, typically with SSO (Single Signo-On) or Kerberos integration. Specially, in the context of Microsoft TMG's EOL, administrators should look for an adequate replacement technology.

Predefined templates for Microsoft applications

Beyond our default security policy, DenyAll ships its WAF with predefined templates for Microsoft applications, with pre-configured exceptions (on known false positives), so that administrators can implement a WAF policy in a matter of a few clicks! We currently provide predefined templates for:

  • Microsoft Sharepoint, see our online documentation for additional information and backup download,
  • Microsoft Exchange, see our online documentation for additional information and backup download,

Microsoft Lync does not rely on standard HTTP protocol for its Web publishing, so you should look at our online documentation for further information on Lync compatibility with our WAF.

Another non-standard (propriatery) protocol used by Microsoft ActiveSync and Outlook Anywhere is RPC over HTTP, which is old RPC transported (encapsulated) in HTTP packets. RPC over HTTP also requires special care and configuration that is described on our online documentation..

Pair Kerberos authentication with a WAF

DenyAll WAF can both use Kerberos on the perimeter authentication (on the WAF itself) and support Kerberos on application side (to support applications that use Kerberos to authenticate users).

Again, on our online documentation, we describe:

  • how to configure Kerberos perimeter authentication in DenyAll WAF
  • how to configure application authentication with Kerberos Constrained Delegation (KCD) in DenyAll WAF

Authentication dedicated to OWA and Sharepoint

DenyAll WAF can be used to provide SSO capabilities to authenticate users once and then authenticate on each application on behalf of the user, so the user does not have to enter any credential.

This feature also performs scheme translations, so users can be authenticated with complex authentication on the perimeter typically, and then support Kerberos (see above), form or NTLM authentication schemes.

As examples, our online documentation provides additional information and configuration guides for:

Conclusion

Through this article we have seen how DenyAll Web Application Firewall Firewall can support the Microsoft ecosystem of applications to both provide security protection as well as advanced authentication and single sign-on capabilities.

Post by: stormshield.eu

Get in touch with us today. Call 02-381-9075

Get started