Exchange 2016 and Hybrid Modern Auth (HMA)

David Steinhart 1 Reputation point
2022-01-06T04:55:04.493+00:00

Can you direct me to any official documentation from Microsoft regarding Exchange on-premises and securing access through Azure App Proxy? Specifically, I am trying to use Hybrid Modern Authentication (HMA) to secure Exchange on-premises. Much of the documentation out there states how to setup HMA but not how to expose the secure environment to end users. In my lab with Exchange 2016, I use Azure App Proxy exclusively and have port 443 completely blocked. I am able to get Outlook and Outlook Mobile to connect securely, or so it seems. The only auth method on virtual directories is OAUTH, or basic auth methods all set to $false. It is difficult to know what I should be recommending to clients when there seems to be missing pieces in the HMA guidelines/architecture. For example, here is the guide for enabling HMA: https://learn.microsoft.com/en-us/microsoft-365/enterprise/configure-exchange-server-for-hybrid-modern-authentication?view=o365-worldwide. The only reference that traffic should be NAT'ed through a firewall is the listing of 2 IP ranges towards the bottom of the article. If I am using Azure App Proxy for OWA, and allowing port 443 through my firewall, what is to keep a threat actor from typing https://1.2.3.4/owa and bypassing the Azure App Proxy protection for OWA? Is there a way to split up the name spaces or put exchange services on different public IP addresses that would provide protection?

Outlook Management
Outlook Management
Outlook: A family of Microsoft email and calendar products.Management: The act or process of organizing, handling, directing or controlling something.
4,958 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,929 questions
{count} votes