This topic describes how to change the default endpoint policy for privileged endpoints that is applied by Forefront Unified Access Gateway (UAG) when publishing Outlook Web App. The default privileged endpoint policy is called OWA Private Computer and is defined such that Forefront UAG automatically identifies all clients as public endpoints and sets the security settings on the Outlook Web App logon page to This is a public or shared endpoint. To allow users to select This is a private endpoint, you must change the policy.

To modify the OWA Private Computer endpoint policy

  1. In the Forefront UAG Management console, click the trunk through which you published Outlook Web App. In the Trunk Configuration area, click Configure.

  2. On the Advanced Trunk Configuration dialog box, click the Endpoint Access Settings tab.

  3. In the Privileged Endpoint Policy area, make a note of the endpoint policy in use (by default it is OWA Private Computer) and click Edit Endpoint Policies.

  4. On the Manage Policies and Expressions dialog box, select the policy used for the privileged endpoint policy, and click Edit Policy.

  5. On the Policy Editor dialog box, click Manage Windows Policies.

  6. On the Manage Windows Policies and Expressions dialog box, select the policy used for the privileged endpoint policy with (Windows) appended, for example OWA Private Computer (Windows), and click Edit Policy.

    The Advanced Policy Editor for Windows dialog box appears.



    Advanced Policy Editor for Windows
  7. Delete the existing variable Privileged_Endpoint.

  8. Make changes to the policy as required. For example, to create a policy that defines privileged endpoints as those with an up to date Microsoft Forefront anti virus product and a Windows 7 personal firewall installed and running, do the following:

    1. Under Components/Windows Variables, expand Anti-Virus, expand Microsoft/Forefront, and then click Up To Date.

    2. On the Advanced Policy Editor for Windows dialog box, click AND.

    3. Under Components/Windows Variables, expand Personal Firewall, expand Microsoft/Windows 7 PFW, and then click Running.

    4. Click OK.

  9. On the Manage Windows Policies and Expressions click Close.

  10. On the Policy Editor dialog box, click OK.

  11. On the Manage Policies and Expressions dialog box, click Close.

  12. On the Advanced Trunk Configuration dialog box, click OK.

  13. Activate the configuration.