Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Deny Access to email if sophos control app is not installed.

Hello There,

My name is Pablo and we have setup SMC 6.0 in our environment, two thing I found some threat about it but no solution, we want to force the use the of sophos control and if a device doesnt have it deny access to email, I thing this is a two side conf, one from smc and one from exchange activesync but I havent found how to do it, and when i deny access to email to some devices even though they still can receive email, what i have to do to complete deny access to email.



This thread was automatically locked due to age.
Parents
  • Hi All,

    to connect the internal EAS Proxy to an Exchange Server, log in as the super administrator of your SMC server.
    Then, go to the "Setup | System setup" section and switch to the "EAS Proxy" tab. Within the "Exchange/groupware server URL" enter the name of your Exchange / ActiveSync server. You can test if the SMC server is able to reach the server by using the "Test connection" button.

    Once that is done, your SMC server will forward all traffic coming in for the page https://smcserver.company.com/Microsoft-Server-ActiveSync to your configured email server.

    Within your email profiles / policies, enter as the email server the SMC server and the proxy functionality of the SMC server can be used.

    Hope that helps

    Best regards
    Stefan

  • Stefan,

    That's ok I already done that, but the problem is if the user know the exchange server path he's still able to bypass the SMC and just download email directly without have smc installed, my question is if I have to redirect the activesync to the smc server to deny access to email server and if that's all i have to do and how to do it.

  • Hi koolkuiet,

    if there is an externally accessible URL for the mail server, either deny access for that on the firewall or you can restrict access based on the IP to the ActiveSync website directly on the Exchange server..

    How to do this is described in this article.

    Hope this helps

    Best regards
    Stefan

Reply
  • Hi koolkuiet,

    if there is an externally accessible URL for the mail server, either deny access for that on the firewall or you can restrict access based on the IP to the ActiveSync website directly on the Exchange server..

    How to do this is described in this article.

    Hope this helps

    Best regards
    Stefan

Children