Protectimus for OWA & EAC
We've created an installer that helps to set up OWA two-factor authentication (Exchange 2013, 2016, 2019) and Exchange Admin Center (EAC) in just a few minutes
Two-factor authentication for OWA and Exchange Admin Center in 15 minutes
Protectimus provides a dedicated multi-factor authentication (MFA) solution for Outlook Web App and Exchange Admin Center on Microsoft Exchange Server. The Protectimus OWA component adds a second authentication factor to OWA and EAC logins on Exchange 2013, 2016, and 2019, and works with either Protectimus Cloud MFA or the Protectimus On-Premise MFA Platform. Installation takes about 15 minutes and needs no agents on individual mailboxes or client devices.
Exchange Server 2013, 2016, 2019
Easy integration
Direct protection for Exchange
You can also use the Protectimus DSPA component for protecting access to Outlook Exchange Server. It integrates directly into Active Directory. It changes users’ passwords every few minutes: one part of the password remains unchanged, while the other is a TOTP password. In this case, you don’t need to install the Protectimus OWA component.
2FA for Exchange Admin Center
Group Policies Configuration
Supports OCRA Algorithm
Why OWA and EAC Need a Dedicated MFA Layer
Outlook Web App is reachable from any browser, on any network, by design. That is what makes it convenient for remote and hybrid staff — and what makes it a favorite entry point for credential-based attacks. A username and a static password are enough to reach a mailbox from anywhere. And a mailbox holds more than message threads — password-reset emails, financial correspondence, internal approval chains: exactly the context a well-crafted business email compromise attempt needs.
The Exchange Admin Center carries even more risk per compromised account. An admin session in EAC can create mail-flow rules, add mailbox delegates, or export data — actions that are hard to spot in real time and easy to abuse once inside.
The scale here is not hypothetical. According to the 2025 Verizon Data Breach Investigations Report, stolen or abused credentials remained the single most common way attackers got into networks, present in roughly a fifth of breaches, with the human element playing a role in about 60% of breaches analyzed. FBI IC3 data cited in that same report puts reported Business Email Compromise losses at $2.77 billion for 2024. OWA, as the public-facing login for corporate mail, is a direct BEC (Business Email Compromise) entry point.
Native Exchange authentication does not stop a phished or leaked password from working. Multi-factor authentication closes that gap without redesigning how OWA or EAC are accessed — and per Microsoft’s 2025 Digital Defense Report, modern MFA reduces the risk of identity compromise by more than 99%, even when the attacker already holds a valid username and password. That is why OWA and EAC are treated as their own MFA target, distinct from a general “add MFA everywhere” project.
OWA 2-Factor Authentication: Two Options
We offer two solutions for protecting access to Microsoft Exchange Outlook Web Access and Exchange Admin Center with multi-factor authentication
Set up two-factor authentication for Outlook Web App (OWA) or Exchange Admin Center (EAC) using the Protectimus OWA 2FA component. For hassle-free integration, download the installer and setup instructions below.
Set up two-factor authentication directly in Active Directory using the Protectimus DSPA (Dynamic Strong Password Authentication) component.
The Protectimus OWA 2FA solution allows you to:
- configure two-factor authenticationfor Outlook Web App and Exchange Admin Center exclusevely, multi-factor authentication will not be activated for any other services connected to Active Directory;
- use either Protectimus Cloud Multi-Factor Authentication Service or Protectimus Local MFA Platform;
- configure group policies during installation;
- activate two-factor authentication only for the selected Active Directory group;
- set the frequency with which users will enter one-time passwords to continue working with OWA, for example, every 12 hours;
- use any 2FA tokens for OWA and EAC two-factor authentication – HOTP, TOTP, or OCRA OTP tokens.
After deploying the Protectimus DSPA component, user passwords in Active Directory are continuously updated with time-based one-time passwords (TOTP). The password rotation interval is configured by the administrator and must be a multiple of 30 seconds.
Because Protectimus DSPA integrates directly with Active Directory, OTP-based authentication is automatically enforced across all services connected to the directory, including Outlook Web App (OWA), Winlogon, RDP, ADFS, and others.
Protectimus DSPA is available exclusively as part of the Protectimus On-Premise Platform and is not supported by the Protectimus Cloud Service. For DSPA authentication, users can generate OTPs using the Protectimus SMART authenticator app or the Protectimus BOT chatbots for Telegram, Viber, and Facebook Messenger.
The OWA component works with both the Protectimus Cloud Service and the Protectimus On-Premise Platform, allowing organizations to choose the deployment model that best fits their infrastructure and compliance requirements. Protectimus OWA supports multiple authentication methods, including authenticator apps, push notifications, email, SMS, chatbots, and hardware tokens.
Two Ways to Protect OWA:
Component-Level vs. Directory-Level
If you're weighing which of the two fits your environment, the OWA two-factor authentication guide on the Protectimus blog walks through both approaches and the trade-offs of each in more depth. This page assumes you already know you want to protect OWA and EAC specifically.
Advanced features
Not only do we deliver and verify one-time passwords, but we also want to make the process of protecting Outlook OWA and Microsoft Outlook Exchange login with two-factor authentication as convenient for administrators as it is for users
User self-service
Time-based filters
Time-based filters allow you to configure OWA multi-factor authentication so that users can only log in to their accounts at certain times of day, such as during business hours. This precludes the possibility of accounts being compromised outside business hours, increasing the security level of your infrastructure.
Analytics and notifications
We provide detailed reports about the operation of the Protectimus Outlook Web App two-factor authentication service: the number of successful and failed authentications, financial information, and much more. Administrators can also receive notifications for each important system event by email or phone.
Cloud Service or On-premise Platform
Protectimus is one of the few OWA two-factor authentication providers offering a choice of two cooperation models: SAAS or on-premise platform. But as our cloud service is already set up, ready to use, and available 24/7, we recommend you to start testing our OWA multi-factor auth service by registering at service.protectimus.com
Cloud Service
The SaaS model is convenient, especially when the number of OWA users to protect is small — say, fewer than 99. There is no equipment to purchase, no authentication server to install, no failover cluster to deploy, and no extra infrastructure to secure — that side is handled for you. A server cluster with a load balancer keeps the service stable and distributes traffic evenly, while the infrastructure is monitored continuously and all sensitive data is encrypted using a hardware security module. All you need to do is register at service.protectimus.com and install the OWA multi-factor authentication component to start protecting Outlook Web App logins the same day.
Local server
Corporate policy or legal regulation often requires the authentication server to stay on the client’s premises. The Protectimus On-Premise Platform is built for exactly those cases: running the server inside your own network gives full control over data and processes, along with the responsibility for fault tolerance and protecting it from external threats. Feature parity with the cloud service is maintained — user self-service, geographic and time-based filters, and event monitoring all work the same. And because the server sits inside the network, Outlook Web App can keep authenticating even as an offline service, with no dependency on the internet.
Supported Two-Factor Authentication Methods
Protectimus OWA does not lock you into a single method. Hardware OTP tokens, an authenticator app, chatbot-delivered OTP, SMS, email, and push notifications are all supported — so each user group can be matched to the delivery method that fits its devices and security policy.
How to set up OWA two-factor authentication with Protectimus
Set up two-factor for OWA in just a few minutes
Registering with the Service
Register with the cloud-based Protectimus multi-factor authentication service, or install the On-Premise Platform to keep the server in your network.
Choose a payment plan
Navigate to the Service plans and activate the plan that meets your needs. To start testing the two-factor authentication solution for OWA, you can just activate the Free plan for now.
Create a resource
Resources are used to logically group users and tokens. Navigate to the Resources section. Then, click Add Resource and create a resource.
Install Protectimus OWA
Use the buttons above to download the installer and open the setup guide. Then run the Protectimus OWA installer and follow the on-screen instructions.
FAQ
Does Protectimus support MFA for Outlook Web App?
Yes. The Protectimus OWA component adds a one-time password step to the OWA login on Exchange Server 2013, 2016, and 2019, working with either Protectimus Cloud MFA or the On-Premise MFA Platform.
Does Protectimus support MFA for the Exchange Admin Center as well as OWA?
Yes. The same installer lets you enable MFA for OWA, EAC, or both, selected as separate modules during setup.
Can OWA MFA be deployed on-premise instead of using a cloud service?
Yes. The Protectimus On-Premise MFA Platform runs the authentication server inside your network or private cloud, with the same OWA component and the same feature set as the cloud service.
Can MFA be enabled for only one Active Directory group instead of everyone?
Yes. During installation you can restrict MFA to a specific AD group; leaving this unset applies it to all users.
Does Protectimus RADIUS support high availability and failover?
Yes. You can deploy multiple Protectimus RADIUS Server instances and configure your NAS devices with primary and secondary RADIUS targets. If the primary server doesn’t respond within the RADIUS timeout, the NAS retries against the secondary automatically. In On-Premise deployments, high availability can also be extended to the Protectimus Platform by deploying it as a cluster. Network devices automatically switch to the secondary server when the primary becomes unavailable, helping maintain authentication availability.
What authentication methods are supported for OWA logins?
Hardware OTP tokens, the Protectimus SMART app, Protectimus BOT chatbots (Telegram, Viber, Facebook Messenger), SMS, email, and push authentication. OTP-based methods support HOTP, TOTP, and OCRA algorithms.
What is the difference between Protectimus OWA and Protectimus DSPA?
Protectimus OWA protects OWA and EAC logins specifically. Protectimus DSPA integrates at the Active Directory level and extends MFA to every AD-connected service automatically, including OWA. See the comparison table above.
How long does it take to set up MFA for OWA?
Deployment, from registering with the service to a working MFA-protected login, is typically completed in around 15 minutes once prerequisites (a trusted SSL certificate, .NET Framework 4.7.x) are in place.