Загрузка
MS Exchange is a core communication platform tightly integrated into the MS Windows infrastructure. Compromising a mail server can lead not only to theft of confidential information, but also to a takeover of the entire domain infrastructure followed by its disruption.
Login and password are easily intercepted by a keylogger.
A user may reuse the same password for the corporate infrastructure and for personal services; a leak from those services may allow attackers to reuse the password to access the corporate environment.
Having compromised a password, an attacker gains access not only to correspondence, but also the ability to send malicious content directly to company employees via Exchange, bypassing mail gateways and sandboxes.
Exchange services may contain vulnerabilities that allow remote code execution. The proxyShell vulnerability is one example: it allowed an unauthenticated user to execute code remotely. Given the rapid development of AI for vulnerability discovery, history may well repeat itself.
The standard certificate-based authentication is usually implemented with ADCS, which is tightly integrated into the Active Directory infrastructure. If a user certificate is compromised, an attacker can gain access not only to mail, but also to other Windows resources, such as file servers, web applications and MSSQL databases.
Modern authentication adds multi-factor authentication, but does not address the possibility of exploiting vulnerabilities in Exchange services exposed to the Internet.
The corporate VPN must be activated to sync emails and calendar events.
Corporate and personal VPNs cannot run simultaneously.
Corporate and personal VPNs cannot run simultaneously.
Some specialized EMM solutions do not support multiple corporate mailboxes on a single mobile device.
EMM solutions typically containerize all content, including the calendar, which may inconvenience users when a calendar widget cannot be placed on the smartphone home screen.
Users may be skeptical about installing EMM/MDM solutions on their personal devices.
ASProxy is an mTLS reverse proxy for Exchange ActiveSync and EWS that performs the following tasks:
To install the certificate, the user must enter a random password shown on screen during certificate generation; once the download limit is reached, the PFX container is deleted from the portal's memory
To enable generation of user Kerberos tickets for Exchange, a technical account must be created and configured for constrained delegation to the Exchange SPN
Kerberos authentication must also be enabled on the IIS endpoint serving ActiveSync
ASProxy supports multiple Exchange servers, both with a shared ASA account using the same SPN and without one