On Premise OWA Brute force Protection

Ash73 21 Reputation points
2021-03-20T15:32:22.813+00:00

Hi, please can someone advise if a owa captcha can be setup on exchange 2016, or the best way to lock out the user account after 4 incorrect logon attempts on owa (on prem) - cant see it in active directory? This has been brought more in to focus after the recent Microsoft exchange vulnerability with brute force attacks now more of a concern on owa / mobile active synch.

Thanks

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,349 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,721 questions
{count} votes

Accepted answer
  1. Andy David - MVP 141.6K Reputation points MVP
    2021-03-20T21:18:28.247+00:00

    OWA with VPN access would probably make the most sense financially if you already have a VPN solution. Do that and block 443 externally and you should be pretty secure.

    Any other solution would require Azure / 365 licensing, yes.

    Or 3rd party licensing for any integrated MFA solution with ADFS.

    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Andy David - MVP 141.6K Reputation points MVP
    2021-03-20T17:21:39.537+00:00

    Not possible natively.
    Look at using ADFS with OWA:
    https://learn.microsoft.com/en-us/exchange/clients/outlook-on-the-web/ad-fs-claims-based-auth?view=exchserver-2019

    and then setting the Extranet Smart Lockout to stop these:

    https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/operations/configure-ad-fs-extranet-smart-lockout-protection

    Really though, a Multi-Factor solution integrated with that is the best solution.
    You can leverage 3rd party MFA or use Azure:

    https://learn.microsoft.com/en-us/microsoft-365/enterprise/hybrid-modern-auth-overview?view=o365-worldwide

    0 comments No comments

  2. Ash73 21 Reputation points
    2021-03-20T20:47:28.787+00:00

    Thanks Andy,

    Would we need to purchase the office 365 email / exchange package for this. Licensing is currently for on-prem. so don't want to go for a full online solution just yet.

    Or should we just use owa with vpn access. Owa is currently accessible externally on 443

    cheers
    Ash

    0 comments No comments