You must configure the Exchange Client App server to use Basic, NTLM, or KCD authentication, because Forefront UAG does not support forms-based authentication to perform single sign-on (SSO) to Outlook Web App.
To configure Exchange to use basic authentication
To publish Outlook Web App on a Forefront UAG portal
Note: In Outlook 2010, if you want to allow access to the Exchange Control Panel only (without other Outlook Web App functionality), run the Add Application Wizard as described, and then after finishing the wizard, edit the application properties and remove the /owa path.
(Note: When publishing OWA, Forefront UAG communicates with the Exchange Client Access server over HTTP or HTTPS.)
If you are publishing Exchange 2010 and OWA is not the initial portal application, make sure that the Open in a new window check box is selected.
10. On the Authorization page of the wizard, select which users are authorized to access this application.
11. On the Completing the Add Application Wizard page of the wizard, click Finish.
The Add Application Wizard closes, and the application that you defined appears in the Forefront UAG Management console, in the Applications list.
12. If you want to define the Outlook Web App application as the portal home page, in the Forefront UAG Management console, in the Initial application list, click the application that you added in this procedure.
13. To apply the Outlook Web App look and feel to the Forefront UAG user interaction pages, in the Forefront UAG Management console, next to Configure trunk settings, click Configure, click the Authentication tab, and then select the Apply an Outlook Web App look and feel check box. Confirm the changes to the logon settings, and then click OK.
14. On the toolbar of the Forefront UAG Management console, click the Activate configuration icon, and then on the Activate Configuration dialog box, click Activate.
When the configuration is activated, the message "Forefront UAG configuration activated successfully" appears.