Personally, I didn't see any reason to state the obvious when it was there for
everyone to see.

There is no *safe* or *best* way to deploy that architecture as far as I'm
concerned. The sooner everyone just accepts that, the better off everyone will be.

I've found personally that a correctly implemented VPN solution is 1000 times
better than trying to get OWA deployed and *safe*.

Paul Melson wrote:

>PS - How come nobody's come back with, "The most secure option is to not use
>OWA at all and make people check their e-mail from the office like normal
>human beings." ? If you apply that option to the risk valuation I use
>above, you get a sum of 0. Clearly better than the rest.

