Exchange ActiveSync with Azure AD Application Proxy

Nelson Ma 21 Reputation points
2020-12-18T19:54:55.187+00:00

Hello Microsoft,

We are looking to publish our ActiveSync from on-premises Exchange using the Azure AD Application Proxy. Our goal is to enable MFA and use conditional access policies onto ActiveSync.

Is this type of setup supported now? I've seen some older posts indicating that it was not supported by the Exchange team, I was wondering what is the consensus now.

Thanks

Exchange | Exchange Server | Management
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2020-12-18T20:08:52.237+00:00

    From what I understand, you can use Pass through auth to do this:
    https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-faq

    I would also look at HMA:

    https://learn.microsoft.com/en-us/microsoft-365/enterprise/hybrid-modern-auth-overview?view=o365-worldwide

    Exchange ActiveSync clients (e.g., iOS11 Mail)
    Exchange ActiveSync
    For Exchange ActiveSync clients that support modern authentication, you must recreate the profile in order to switch from basic authentication to modern authentication.


2 additional answers

Sort by: Most helpful
  1. Roy Esteves 41 Reputation points
    2021-05-17T14:16:03.397+00:00

    @Nelson Ma Did you manage to achieve your goal with Pass Through or HMA?

    I have exactly this challenge, however the end user device is iOS and the mailbox is to be accessed through the native mail app (Basic Auth). How do I present EAS auto discovery url externally through App Proxy?

    Thanks.

    0 comments No comments

  2. Cochran, Adam 21 Reputation points
    2021-12-27T21:51:36.39+00:00

    Anyone ever figure this out? I have an onprem exchange server working fine for OWA through azure app proxy. However, I want to fully remove access from the outside to my exchange server except through the app proxy but activesync and outlook anywhere break.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.