United States Change | All Microsoft Sites
Microsoft Home | Servers and Tools | Forefront | Edge Security
The following tables provide an overview of the key features of Microsoft's Intelligent Application Gateway (IAG) 2007.
Application Intelligence
Feature
Description
Out-of-the-box application optimizers
Built-in application settings and configurations for most common, enterprise applications such as Exchange, SharePoint, Dynamics CRM and others. Ensures easy deployment, minimal integration overhead (filtering, single sign on, etc.) and low ongoing management costs.
Out-of-the-box settings for common application types (web, network, integrated) to simplify application deployment.
Policies updated periodically to include new functionality and support for new versions.
Granular application policy engine
Ability to filter transactions and modify application functionality based on type of transaction, URL, user authorization data and/or endpoint health assessment.
Interoperability
Toolkit for defining positive-logic rule sets, URL filters to supplement optimizer settings and to develop policies for customized or proprietary applications.
Includes optimizers for commonly used 3rd party enterprise applications such as Citrix, SAP, Lotus Domino, Websphere and more.
Supports templates that provide a framework to build application optimizers for both generic Web applications and complex enterprise applications incorporating components, Web parts and objects.
Application firewall
Helps detect application anomalies and threats at the URL, header and data levels, leveraging built in negative-logic as well as regular expressions/positive-logic to filter traffic and firewall web applications.
Endpoint and Access Security
Out-of-the-box endpoint policies
Built-in endpoint health policies address most commonly used security settings/software detection, allowing for a far simpler deployment and ongoing use of granular endpoint engine.
Highly flexible and granular policy engine
Provides the ability to detect virtually every aspect of a client’s PC such as registry keys, file hashes, processes in memory and more.
Extensible policy engine provides easy creation of new/custom policies using wizards as well as the ability to create and deploy self-made policies using client scripting languages.
Robust authentication and authorization engine
Easily overlays virtually any authentication method including domain, certificate, token and many other methods.
Built-in single-sign-on (SSO) features to ensure credentials are easily passed to internal applications and users are spared secondary logins (including within applications like SharePoint).
Flexible authentication and authorization enables creation of multiple policies and portals per user, group, application or endpoint status.
SSL VPN tunnels
Ability to publish applications of varying complexity while requiring minimal resources on client computer (port/socket forwarding, network level connections, etc.)
Information leakage mitigation
Ensures that documents left behind on unmanaged machines are scrubbed during session termination or timeout.
For highly sensitive applications and environments, policies can be set to ensure that documents and attachments are not shared from environments that can’t be trusted to scrub correctly.
Easy Management and Customization
Wizard-driven deployment and configuration
Deployment wizard to ensure easy implementation and quick access to key applications/users/scenarios.
Easy to follow/use wizards for key ongoing tasks such as adding applications, configurations and policies.
Minimizes errors and total cost of operations.
Easy and flexible user experience
Built-in portal/menu provides simple and straightforward user experience.
Portal and functionality can be easily integrated into enterprise solutions such as SharePoint, SAP and Websphere.
Highly robust and customizable user experience options enable deployment of multiple portals, applications, settings and templates.
Virtualization and scale
Scalable solution allows high-availability arrays (Active/Active or Active/Passive), global deployments and near-linear scaling of users/throughput.
Multiple hardware partners provide wide range of appliance options, utilizing updated and best-of-breed hardware.
Virtual machine option allows complete virtualization of IAG deployment and provides flexibility in management, disaster recovery and highly scalable environments.
Consolidated gateway
IAG consolidates access and gateways into one platform thus allowing ITPros to easily manage policies and resources from a centralized array/location.
Centralized monitoring and access control improve security by reducing the number of access points into the network/resources.
Features