EXCHANGE WEB SERVICES PROTECTION FOR SKYPE-FOR-BUSINESS
Secure Exchange access for Skype for Business by allowing only approved registered devices to retrieve mail, meetings, contacts, and other EWS data.
Secure Exchange access used by Skype for Business clients
Skype for Business clients communicate with Exchange to retrieve meeting information, which often requires Exchange Web Services to be published externally.
This exposure can increase account lockout risk and may expose mail, attachments, events, tasks and contacts if valid credentials are abused.
SphereShield blocks requests from unregistered devices and adds a two factor authentication layer for Exchange access.
Block Exchange and Skype for Business access from unregistered devices.
Use the device as a second authentication factor alongside the user password.
Support secure access even when the Save Password option is disabled.
SphereShield validates the registered device before Exchange data is reached
Organizations using Skype for Business can be exposed to threats because the client connects to Exchange for meeting information.
Publishing EWS externally exposes an authentication service, creating account lockout risk during DDoS attempts.
EWS can retrieve Exchange data such as events, mail, attachments, tasks and contacts, meaning exposed EWS can increase the risk of broader Exchange data exposure.
OWA access can also increase risk, because an attacker with valid Active Directory credentials may gain access to a user's full mailbox.
Account lockout exposure
Externally published authentication services can be abused during repeated login attacks.
Exchange data exposure
Mail, attachments, meetings, tasks and contacts can become reachable if credentials are abused.
OWA mailbox risk
Valid Active Directory credentials may allow full mail access through Outlook Web Access.
Two factor protection for Skype for Business and Exchange access
Device as a second factor
Unauthorized credential usage is not enough without access to the registered device.
Unregistered device blocking
Information requests from unregistered devices are blocked before Exchange data is reached.
Save Password disabled support
Users can stay connected to Skype for Business and Exchange until sign-out without saving the password on the device.
Approved device control
Organizations can restrict usage to approved or registered devices only.
The user password and the registered device work together, reducing the risk of stolen credentials being used from unauthorized devices.
Automatic registration
The device is registered when the user connects to Skype for Business for the first time. Future connections are verified against that registered device.
Two step registration
Users register through the Access Portal from the internal network and connect their device within a limited admin-defined time window.
Multiple device support
SphereShield can support multiple approved devices per user and can limit the number of devices allowed.
Admin manual approval
New devices can first be placed in a blocked device list and then manually approved by the SphereShield administrator.
Prevent unauthorized devices from using corporate credentials.
Match each user to an approved registered device.
Add strong two step verification for Skype for Business and Exchange access.
Reduce risk from hackers or unauthorized users with stolen Active Directory credentials.
Protect Exchange Web Services used by Skype for Business clients.
Support secure connectivity without saving passwords on the device.
Keep Exchange access available to approved users while blocking requests from unregistered or unauthorized devices.
Secure Your Collaboration Environment
Protect Microsoft 365, Webex, Teams, OneDrive, SharePoint, and Skype for Business with SphereShield’s policy-driven security, compliance, and governance controls.