Don't overlook this feature of Exchange 2007

There's one nice feature in Exchange 2007 that I suspect will get overlooked far more than it deserves, and that's the built in support for the Windows Server 2003 SP1 Security Configuration Wizard. Out of the box, the SCW provided support for an impressive number of current-generation Microsoft applications, but the big question was always what would happen when newer versions of software were released.

Exchange 2007 comes with SCW support. While it doesn't register the SCW extensions during installation (or even give you the option of doing so, which would have been a nice touch), the Post-Install steps in the Exchange Management Console (and the Exchange documentation) give you the complete process for using the SCW to harden your Exchange 2007 servers. While the documentation is impressively complete, I found a couple of typos that might put some small bumps in the road.

In the How to Register Exchange Server Role SCW Extensions topic, they give you a couple of command lines to register the extensions used to tell SCW how to secure Exchange 2007. Here's the command lines I ended up using:

Registering the SCW extensions for one or more of the MB, CAS, HT, or UM roles:

scwcmd register /kbname:"Ex2007KB" /kbfile:"%programfiles%\Microsoft\Exchange Server\scripts\Exchange2007.xml"

Registering the SCW extensions for the ET role:

scwcmd register /kbname:"Ex2007EdgeKB" /kbfile:"%programfiles%\Microsoft\Exchange Server\scripts\Exchange2007Edge.xml"

Let me know how it works for you.

Print | posted on Wednesday, January 10, 2007 1:09 AM

Comments on this post

# One interface or two: an Edge case

Requesting Gravatar...
The release Exchange 2007 docs advocate a curious two-interface configuration for the Edge server. Devin examines this advice and fails to find the sense in it.
Left by (e)Mail Insecurity on Jan 11, 2007 4:21 AM

# Weekend reading

Requesting Gravatar...
After some time off-the-air, "Weekend reading" is back, and this time is really BIG! Exchange Server
Left by subject: exchange on Jan 15, 2007 12:50 AM

# One interface or two: an Edge case

Requesting Gravatar...
The release Exchange 2007 docs advocate a curious two-interface configuration for the Edge server. Devin examines this advice and fails to find the sense in it.
Left by (e)Mail Insecurity on Apr 12, 2007 1:57 PM
Comments have been closed on this topic.