A nice tip, to ensure added security if a laptop is lost/stolen on non BitLocker enabled laptop
In AD Create two new security group “Outlook over HTTP” & “Blocked Outlook over Http”;
add all users except for the allowed users to the restricted group, add the allowed users to the “Outlook over Http” group
2 items will now be set on TMG & on Messaging
Watch the power of EBS, using one centralized location.
From Administration console; Computers and Devices.
Right click on the Messaging server
connect to computer
Browse to C:\Windows\System32\RpcProxy
Right click on RpcProxy.dll; properties; security
Add the “Blocked Outlook over Http” group and set this to deny all.
Restart exchange services.
From Administration console; Computers and Devices.
In the Security tab
Right click “Network firewall” “Start Forefront Threat console”
Modify the “Allow Internet Access to All User” to ensure both groups are added
Should be all set.