Question About Network Security

olds

Elite Member
Mar 3, 2000
50,071
744
126
<---Not IT but trying to get my head around this.

I work for a large agency and they are extremely particular (rightly so) about the security of the network.

We need an emergency notification system and a service is provided by a vendor on their server (software as a service).

To keep the contact list updated, it interfaces with our Outlook database. But IT isn't going to let that happen as it introduces a vulnerability.

Is there a way to mirror that Outlook database on another server that wouldn't cause vulnerability to the main network?

For reference, other agencies using this service let the vendor run an API (not sure what an API is) which lets its service talk to our Outlook and keep the database updated. My IT did think there was a way to do it but won't articulate the steps or commit the resources or time to the project. Even though they want to use the service (since I am paying) for their own notifications.

TIA
 

Genx87

Lifer
Apr 8, 2002
41,091
513
126
Is this contact list within your exchange environment? And the people who need to update outside your organization? What generates the notifications?
 

olds

Elite Member
Mar 3, 2000
50,071
744
126
Is this contact list within your exchange environment?
Yes

And the people who need to update outside your organization?
The vendor needs the Exchange info to keep the contact list updated. To do it manually for 20,000 people would be too much.

What generates the notifications?
We log into their portal, type a message or use a template, select who gets the message (groups or individuals) and send it. We can then see who received it and who responded.
In red.
 

olds

Elite Member
Mar 3, 2000
50,071
744
126

Mushkins

Golden Member
Feb 11, 2013
1,631
0
0
Looks like the API may not be secure. Which brings me back to mirroring the Exchange information on a different server with no access to our real servers. Again, I am not IT.

Yes, you could create a Read Only Exchange Server in a DMZ, which will have data copied to it but cannot make changes, and the vendor could interface with this server instead (assuming their software even works with exchange in read-only mode, you'd have to consult them).

However, this opens up another can of worms as you don't ever want an exchange server with live company data on it in a DMZ. Plus you, y'know, have to license and configure a server to do this which costs money.

Honestly, we can't give you a best answer because we don't know anything about your network. Bottom line is your IT department *needs* to be involved in this process, that's kind of what they exist for. If the higher ups deem that this project isnt worth their time, well, that's not on you. Can't have it both ways.
 

Phynaz

Lifer
Mar 13, 2006
10,140
819
126
SFTP the directory. They don't need access to exchange.

But, yeah, leave it to IT, it's their job.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |