Requires
Robin connects to your Exchange server with Microsoft's proprietary authentication protocol, "NTLM". Most modern Windows Servers have NTLM enabled by default.
Office 365 does not support NTLM authentication. Office 365 admins should use Robin's integrated OAuth app instead.
What NTLM is
NTLM is a proprietary secure authentication protocol from Microsoft. With NTLM, Robin connects to an external Exchange host without sending a user's password. Robin also stores Exchange credentials with one-way encryption (called "hashing"), so a user's Exchange password is never stored in plain text. This is best practice for security.
Windows Servers have many configurations that can stop NTLM from working correctly. Follow these steps to make sure that NTLM is configured correctly for Robin.
Robin uses NTLMv2 by default, and also supports v1.
Log on to the Windows Server that hosts the Exchange server software. Use Administrator Credentials.
-
Select Start, then Administrative Tools, then Local Security Policy. A new window opens.
-
The Local Security Policy window has a left panel with an item titled Local Policies. Expand Local Policies, then select the inner Security Options item. The right side of the window shows a list of policies and their settings.
In the list of security policies, find the policy titled "Network Security: LAN Manager authentication level" and double-click it. A properties window opens.
-
In the "Network Security: LAN Manager authentication level" policy property window, open the drop-down menu and make sure that an option is selected. The most compatible and recommended option is "Send LM & NTLM - use NTLMv2 session security if negotiated". Select "OK" to save the change.
In the list of security policies, find the policy titled "Network Security: Restrict NTLM: Incoming NTLM traffic" and double-click it to open its properties window.
-
In the "Network Security: Restrict NTLM: Incoming NTLM traffic" policy property window, open the drop-down menu, select "Allow all" and then select "OK".
In the list of security policies, find the policy titled "Network Security: Restrict NTLM: NTLM authentication in this domain" and double-click it to open its properties window.
-
In the "Network Security: Restrict NTLM: NTLM authentication in this domain" policy property window, open the drop-down menu, select "Disable" and then select "OK".
In the list of security policies, find the policy titled "Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers" and double-click it to open its properties window.
-
In the "Network Security: Restrict NTLM: Outgoing NTLM traffic to remote servers" policy property window, open the drop-down menu, select "Allow all" and then select "OK".
Close the Local Security Policy window.
With these changes, Robin should be able to access your Exchange server through NTLM authentication on your Windows Server. You may need to reload or reboot the server before the changes take full effect.