> For the complete documentation index, see [llms.txt](https://enterprise.hideez.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://enterprise.hideez.com/hideez-server-integration/ws-federation-integration/configure-exchange-outlook-web-application-and-exchange-admin-center.md).

# Configure Exchange Outlook Web Application and Exchange Admin Center

{% hint style="info" %}
This integration is designed to enable authentication for the Exchange Outlook Web Application (OWA) and Exchange Admin Center acting as a Service Providers (SP) via the Hideez Server as the Identity Provider (IdP).
{% endhint %}

<figure><img src="/files/hSqwhidr5WlxmVk3QWel" alt=""><figcaption></figcaption></figure>

## **Step 1: Configure integration for Exchange OWA in Hideez Server**

1. **Login to Hideez Server as Administrator.**
2. **Navigate to WS Federation Settings**:
   * Go to **Settings → Parameters → WS Federation section**.
3. **Add Exchange OWA as a Service Provider**:

* Click **Add Service Provider**.
* Fill in the following details:
  * **Name**: OWA
  * **WT-Realm**: `https://{owa-url}` (e.g., `https://mail.example.com/owa/`)
  * **Reply URL**: `https://{owa-url}` (e.g., `https://mail.example.com/owa/`)
    * In our case `https://exch.lab.hideez.com/owa/`
* Click **Add**.

<div><figure><img src="/files/kKnpooGMz954hOb1ijay" alt=""><figcaption></figcaption></figure> <figure><img src="/files/lG6FUp6VH1yz3GLrx046" alt=""><figcaption></figcaption></figure></div>

4. **Obtain IdP Details**:

* Click on **Details** for the newly added service provider.
* Download the **IdP signing certificate**.
* Copy the **IdP WS Federation URL**.

<figure><img src="/files/ggFmHvGAIDIfS2vEoGGg" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="info" %}
Keep the tab **WS Federation** with values IdP WS Federation URL and the certificate ready for the next step.
{% endhint %}

## **Step 2: Configure integration for** Exchange admin center (EAC) in **Hideez Server**&#x20;

1. **Add an Exchange admin center (EAC) as a Service Provider:**&#x20;

* Click **Add Service Provider**.
* Fill in the following details:
  * **Name**: ECP
  * **WT-Realm**: `https://{ecp-url}` (e.g., `https://mail.example.com/ecp/`)
  * **Reply URL**: `https://{ecp-url}` (e.g., `https://mail.example.com/ecp/`)
    * In our case `https://exch.lab.hideez.com/ecp/`
* Click **Add**.

<div><figure><img src="/files/kKnpooGMz954hOb1ijay" alt=""><figcaption></figcaption></figure> <figure><img src="/files/GiiGYTntuGG4v7nKnn9U" alt=""><figcaption></figcaption></figure></div>

2. **Obtain IdP Details**:

* Click on **Details** for the newly added service provider.
* Download the **IdP signing certificate**.
* Copy the **IdP WS Federation URL**.

<figure><img src="/files/8AtfHcMj4LdNwnsIqqEI" alt="" width="563"><figcaption></figcaption></figure>

{% hint style="info" %}
Keep the tab **WS Federation** with values IdP WS Federation URL and the certificate ready for the next step.
{% endhint %}

## **Step 3: Configure Exchange Server** Sign-On via Hideez Server

### **1. Install the Certificate on the Exchange Server for Exchange OWA**:

* **Open the MMC Console on the Exchange Server:**

1. Press **Win + R**, type `mmc`, and press **Enter**.
2. In the MMC console, go to **File** → **Add/Remove Snap-in**.
3. Select **Certificates** from the list, then click **Add**.
4. Choose **Computer account** and click **Next** → Select **Local Computer** → Click **Finish** → **OK**.

<div><figure><img src="/files/6f1VtazghbSmfYyfxgxG" alt=""><figcaption></figcaption></figure> <figure><img src="/files/kwHkCj0DAi5PNNWLCskI" alt=""><figcaption></figcaption></figure> <figure><img src="/files/urGD8asE6b3lA8jMkHYY" alt=""><figcaption></figcaption></figure></div>

* **Import the Certificate**

1. In the MMC console, navigate to:
   * **Certificates (Local Computer)** → **Trusted Root Certification Authorities** → **Certificates**.
2. Right-click on **Certificates** → **All Tasks** → **Import**.
3. Follow the **Certificate Import Wizard**:
   * Click **Next** and browse to the location of the `ws-fed-signing-owa.cer`
   * Select the certificate and click **Next**.
   * Ensure the certificate is placed in the **Trusted Root Certification Authorities** store.
   * Click **Next** → **Finish**.

<div><figure><img src="/files/Ks7Md6WA3suWx1omSCWu" alt=""><figcaption></figcaption></figure> <figure><img src="/files/b2hVl1znhv5DudYDrszQ" alt=""><figcaption></figcaption></figure> <figure><img src="/files/6eN2XWZGS06cPjNCS0lV" alt=""><figcaption></figcaption></figure></div>

<div><figure><img src="/files/ZxcHB2WM9AUQm6uasIcI" alt=""><figcaption></figcaption></figure> <figure><img src="/files/qAZ8lytvZF8sjVVwCfCh" alt=""><figcaption></figcaption></figure> <figure><img src="/files/QXTkGz2x9StsWvy6O3HT" alt=""><figcaption></figcaption></figure> <figure><img src="/files/JXvmSm5r2H9PGifg8DE9" alt=""><figcaption></figcaption></figure></div>

### **2. Execute Commands in Exchange Management Shell for** Exchange OWA:

* Open the **Exchange Management Shell** and execute the following commands:

{% code overflow="wrap" %}

```
Set-OrganizationConfig -AdfsIssuer "{Hideez WS Fed URL}" -AdfsAudienceUris "{OWA Base URL}" -AdfsSignCertificateThumbprint {Hideez Cert Thumbprint}
```

{% endcode %}

**In the above command:**

* `{OWA Base URL}` is the Exchange OWA host,
* `{Hideez WS Fed URL}` is the Idp WS Federation URL.
* `{Hideez Cert Thumbprint}` is the thumbprint of the certificate you downloaded and installed.&#x20;

**Example**:

{% code overflow="wrap" %}

```powershell
Set-OrganizationConfig -AdfsIssuer "https://dev.hideez.com/wsfed" -AdfsAudienceUris "https://exch.lab.hideez.com/owa/" -AdfsSignCertificateThumbprint d80e7aa3d27ac800fb2d5fa7c08748a73d924cd2
```

{% endcode %}

## **Step 4: Configure** Sign-On to Exchange admin center (EAC) via Hideez Server

### **1. Install the Certificate on the Exchange Server for Exchange OWA**:

* **Open the MMC Console on the Exchange Server:**

1. Press **Win + R**, type `mmc`, and press **Enter**.
2. In the MMC console, go to **File** → **Add/Remove Snap-in**.
3. Select **Certificates** from the list, then click **Add**.
4. Choose **Computer account** and click **Next** → Select **Local Computer** → Click **Finish** → **OK**.

<div><figure><img src="/files/6f1VtazghbSmfYyfxgxG" alt=""><figcaption></figcaption></figure> <figure><img src="/files/kwHkCj0DAi5PNNWLCskI" alt=""><figcaption></figcaption></figure> <figure><img src="/files/urGD8asE6b3lA8jMkHYY" alt=""><figcaption></figcaption></figure></div>

* **Import the Certificate**

1. In the MMC console, navigate to:
   * **Certificates (Local Computer)** → **Trusted Root Certification Authorities** → **Certificates**.
2. Right-click on **Certificates** → **All Tasks** → **Import**.
3. Follow the **Certificate Import Wizard**:
   * Click **Next** and browse to the location of the `ws-fed-signing-ecp.cer`
   * Select the certificate and click **Next**.
   * Ensure the certificate is placed in the **Trusted Root Certification Authorities** store.
   * Click **Next** → **Finish**.

<div><figure><img src="/files/xYty955Ik3mY3WmKxLc0" alt=""><figcaption></figcaption></figure> <figure><img src="/files/KCqnOLzuPhjGrT8mMavl" alt=""><figcaption></figcaption></figure> <figure><img src="/files/saXx9OBxs5XLccVWaePm" alt=""><figcaption></figcaption></figure></div>

<div><figure><img src="/files/EBQYtw6K2bLOSaiuQ8mF" alt=""><figcaption></figcaption></figure> <figure><img src="/files/FWsjWhaNAtrL9FVL98gU" alt=""><figcaption></figcaption></figure> <figure><img src="/files/pXlIJ7VmS62hQKw1D3ER" alt=""><figcaption></figcaption></figure> <figure><img src="/files/sokanMg0biHpLEFM8MdQ" alt=""><figcaption></figcaption></figure></div>

### **2. Execute Commands in Exchange Management Shell for** Exchange admin center (EAC):

* Open the **Exchange Management Shell** and execute the following commands:

{% code overflow="wrap" %}

```powershell
Set-OrganizationConfig -AdfsIssuer "{Hideez WS Fed URL}" -AdfsAudienceUris "{ECP Base URL}" -AdfsSignCertificateThumbprint {Hideez Cert Thumbprint}
```

{% endcode %}

**In the above command:**

* `{ECP Base URL}` is the Exchange Admin Center (EAC) host,
* `{Hideez WS Fed URL}` is the Idp WS Federation URL.
* `{Hideez Cert Thumbprint}` is the thumbprint of the certificate you downloaded and installed.

**Example**:

{% code overflow="wrap" %}

```powershell
Set-OrganizationConfig -AdfsIssuer "https://dev.hideez.com/wsfed" -AdfsAudienceUris "https://exch.lab.hideez.com/ecp/" -AdfsSignCertificateThumbprint 3e04c68e71a591de637d0d21dcfd8e6f4b843684
```

{% endcode %}

{% hint style="info" %}
If you need to configure both **Outlook Web Application (OWA)** and **Exchange Admin Center (EAC)** simultaneously, you can use the following command:

{% code overflow="wrap" %}

```powershell
Set-OrganizationConfig -AdfsIssuer "{Hideez WS Fed URL}" -AdfsAudienceUris "{OWA Base URL}","{ECP Base URL}" -AdfsSignCertificateThumbprint {Hideez Cert Thumbprint}
```

{% endcode %}

#### Command Parameters Explained:

* **`{Hideez WS Fed URL}`**: The URL of the Hideez WS Federation endpoint, acting as the Identity Provider (IdP) for authentication.
* **`{OWA Base URL}`**: The base URL of the Outlook Web Application Service Provider (SP), such as `https://mail.example.com/owa/`.
* **`{ECP Base URL}`**: The base URL of the Exchange Admin Center (EAC)  Service Provider (SP), such as `https://mail.example.com/ecp/`.
* **`{Hideez Cert Thumbprint}`**: The thumbprint of the Hideez signing certificate installed on the Exchange server, used to establish a trust relationship.

**Example:**

{% code overflow="wrap" %}

```
Set-OrganizationConfig -AdfsIssuer "https://dev.hideez.com/wsfed" -AdfsAudienceUris "https://exch.lab.hideez.com/owa/","https://exch.lab.hideez.com/ecp/" -AdfsSignCertificateThumbprint d80e7aa3d27ac800fb2d5fa7c08748a73d924cd2, 3e04c68e71a591de637d0d21dcfd8e6f4b843684
```

{% endcode %}
{% endhint %}

## **Step 5: Configure Virtual Directories**:

### 1. Configure virtual directories for AD FS authentication for OWA:

{% code overflow="wrap" %}

```powershell
Get-OwaVirtualDirectory | Set-OwaVirtualDirectory -AdfsAuthentication $true -BasicAuthentication $false -DigestAuthentication $false -FormsAuthentication $false -WindowsAuthentication $false
```

{% endcode %}

### 2. Configure virtual directories for AD FS authentication for Exchange admin center (EAC):

{% code overflow="wrap" %}

```powershell
Get-EcpVirtualDirectory | Set-EcpVirtualDirectory -AdfsAuthentication $true -BasicAuthentication $false -DigestAuthentication $false -FormsAuthentication $false -WindowsAuthentication $false
```

{% endcode %}

## **Step 6: Restart Internet Information Services (IIS)**

Restart IIS to apply the changes:

```powershell
net stop was /y
net start w3svc
```
