URLScan and IIS7 Request Filtering features and Exchange Server


Symptom


Frequently, Microsoft Exchange Server technical support receives requests to harden security using Request Filtering for IIS 7. This is comparable to the URLScan configurations used in Exchange Server 2003 and IIS 6.

The hardening process, if done incorrectly, can cause issues with many components of Exchange, Outlook, OWA and Entourage connectivity.

Cause


This is not a tested scenario for Exchange Server 2007 and 2010. Modifications to IIS 7 for the purposes of Request Filtering are not required on systems that are running Microsoft Exchange Server.

Resolution


We do not recommend changing the IIS 7 Request Filtering.

Customers may make any changes desired. However, if an issue occurs, the first request that Microsoft Commercial Technical Support will make is to remove any customizations and try to reproduce the problem.

More Information


For more reading on IIS 7 Request Filters, see the following document from TechNet online:

Configuring Request Filters (IIS 7)
http://technet.microsoft.com/en-us/library/cc771493(WS.10).aspx