Applies to: Exchange Server 2007 SP3, Exchange Server
2007 SP2, Exchange Server 2007 SP1, Exchange Server 2007
Topic Last Modified: 2007-03-20
This topic explains how to configure the cookie time-out values for private computers by using forms-based authentication on a Microsoft Outlook Web Access virtual directory in Microsoft Exchange Server 2007. Private computers are also known as trusted computers.
Caution: |
---|
It is important that you warn users of the risks that are associated with selecting the This is a private computer option. A user should select This is a private computer only if the user is the sole operator of the computer, and the computer complies with your organization's security policies. |
Before You Begin
To perform the following procedures, the account you use must be delegated the Exchange Server Administrator role and membership in the local Administrators group for the target server.
For more information about permissions, delegating roles, and the rights that are required to administer Exchange Server 2007, see Permission Considerations.
Also, make sure that the Outlook Web Access virtual directory is configured to use forms-based authentication.
Caution: |
---|
Incorrectly editing the registry can cause serious problems that may require you to reinstall your operating system. Problems resulting from editing the registry incorrectly may not be able to be resolved. Before editing the registry, back up any valuable data. |
Procedure
To use Registry Editor to set the cookie time-out values for private computers by using forms-based authentication
-
On the Exchange Client Access server, log on by using your Exchange administrator account, and then start Registry Editor (regedit).
-
In Registry Editor, locate the following registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSExchange OWA
-
On the Edit menu, point to New, and then click DWORD Value. In the details pane, name the new value PrivateTimeout.
-
Right-click the PrivateTimeout DWORD value, and then click Modify.
-
In Edit DWORD Value, under Base, click Decimal.
-
In the Value Data box, type a value in minutes between 1 and 43,200 for a maximum of 30 days. Click OK.
Note: You must restart Internet Information Services (IIS) by using the command iisreset/noforce
for these changes to take effect.
To use the Microsoft Command Shell to set the cookie time-out values for private computers using forms-based authentication
-
Open the Microsoft Command Shell and run the following command to set the private computer cookie time-out value:
Copy Code set-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Services\MSExchange OWA' -name PrivateTimeout -value <amount of time> -type dword
Note: You must restart IIS is by using the command iisreset/noforce
for these changes to take effect. -
Run the following command to view the private computer cookie time-out value:
Copy Code get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Services\MSExchange OWA' -name PrivateTimeout
For More Information
- For more information about the authentication methods that you
can use to help secure Outlook Web Access,
see Managing Outlook Web
Access Security.
- For more information about how to configure
Outlook Web Access to use forms-based
authentication, see How to Configure
Forms-Based Authentication for Outlook Web Access.
- For more information about how to configure the cookie time-out
value for a public computer, see How to Set the
Forms-Based Authentication Public Computer Cookie Time-Out
Value.