none
Exchange 2007 Web Services Security RRS feed

  • Question

  • I am working with a developer that would like to use Exchange Web Services with SOAP to access a mailbox on our Exchange 2007 server.  What needs to be done, if anything, to allow the developer secure access to the e-mail account and only that one e-mail account?
    Thursday, July 28, 2011 7:34 PM

All replies

  • Hi,

    the webservices are secure by default by means of TLS Security (HTTPS). But the developer needs access permissions to the mailbox in question. You can grant them via Outlook, for example.

    Can you tell us more about your scenario? It seems a little bit vague on what the developer tries to accomplish (and in what environment).

    Kind regards,
    Henning

    "ReinkeIT" wrote in message news:34900799-869b-4e9f-89c6-3e8ef8fd58b6@communitybridge.codeplex.com...

    I am working with a developer that would like to use Exchange Web Services with SOAP to access a mailbox on our Exchange 2007 server.  What needs to be done, if anything, to allow the developer secure access to the e-mail account and only that one e-mail account?

    Thursday, July 28, 2011 7:41 PM
  • Please find below and excerpt from his e-mail to me.  What, if anything, do I need to do to get this to work if he already has access to the e-mail account?  Am I opening myself up to something by doing this?

    By utilizing SOAP (simple object access protocol) XML interface my software could perform a “Subscribe” and listen for the server to tell it about new messages. It could then “GetItem” and “GetAttachment” from the new message, parse, then “DeleteItem” to clear out the message from the server.

    Thursday, July 28, 2011 7:56 PM
  • Will you ultimately run the software or someone else?

    If you run the program, it can use your current Windows access token to log in to your mailbox. Or it could ask you for a username/passwort combination. It would then have the same access to the mailbox as you have with Outlook. Not more, not less.

    Kind regards,
    Henning

    "ReinkeIT" wrote in message news:c7ad0bd1-b27e-4a3f-8d7c-22c149635cfd@communitybridge.codeplex.com...

    Please find below and excerpt from his e-mail to me.  What, if anything, do I need to do to get this to work if he already has access to the e-mail account?  Am I opening myself up to something by doing this?

    By utilizing SOAP (simple object access protocol) XML interface my software could perform a “Subscribe” and listen for the server to tell it about new messages. It could then “GetItem” and “GetAttachment” from the new message, parse, then “DeleteItem” to clear out the message from the server.

    Thursday, July 28, 2011 8:19 PM
  • That is what I thought but I needed to make sure.  Thanks!
    Thursday, July 28, 2011 8:30 PM