Quantcast
Channel: Exchange Server 2013 - Mobility and ActiveSync forum
Viewing all 1206 articles
Browse latest View live

iPhone Users Email Account Settings Change Somehow and Reply to All CC's themselves

$
0
0

I have an odd one here for sure.  

I am an exchange administrator for a organization and we believe that since getting iPhone 6's two of my execs have had an issue where their iphone AND their ipad have issues.  It is reported that a reply to all will cc themselves on every email and we found that when looking at the mail account settings the username actually changes from username@primarysmtp.com to username@internaldomain.com.  

 

We see this on both of the devices (iphone and ipad) and we feel that it began when they two execs got their iPhone 6's.  

 

I will also add that we do not have any way for these devices to communicate with our internal network other than just ActiveSync.  There is no internal wifi network or anything like that.   We have updated the device to the latest version of iOS and we just migrated their mailboxes to Exchange 2013.  I will add that this happened on 2010 as well and the migration just happened to be occurring during the time that we were trying to resolve it.  It has been going on for quite a while, but is starting to make a scene internally.   

We have since found that some of our regular users have this issue as well, but no one in our IT staff has seen this.  I am an Android user, but the rest of my staff are iOS users.  

Anyone seen this before?  Any ideas?  How could this just flip the account settings like this?


Event 1053 ActiveSync doesn't have sufficient permissions to create

$
0
0

Hello all and thanks in advance.

Exchange 2007 to 2013 co-existence.  All email now routed (proxies) through 2013 server.  For everyone, Outlook functional, OWA functional and for everyone else on the old server, EAS is functional.  I only have three clients on the new server.  Outlook and OWA are functional, EAS is not.  Two of those accounts get the following message on the 2013 server:

Exchange ActiveSync doesn't have sufficient permissions to create the "CN=Name\, User,OU=Users-IT,DC=HALFF,DC=AD" container under Active Directory user "Active Directory operation failed on SRV05.HALFF.AD. This error is not retriable. Additional information: Access is denied.

Active directory response: 00000005: SecErr: DSID-031521D0, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0".

Make sure the user has inherited permission granted to domain\Exchange Servers to allow List, Create child, Delete child of object type "msExchangeActiveSyncDevices" and doesn't have any deny permissions that block such operations.

These two accounts are also part of several 'protected' security groups such as domain admins and or enterprise admins.  I've seen this KB: http://support.microsoft.com/en-us/kb/2579075 One of these accounts is mine.  Security for my user object is NOT inherited.  I went to make the change in the article and it said 77 items were going to be changed.  "Warning.  The change you are about to make will result in 77 permissions being added to the access control list"

Is this normal for AD objects that are part of protected groups?  What is the best way to get through this?

Thanks,

Willis

Security Logo Failed Exchange 2007 / IIS

$
0
0

Hi,

I am getting hundreds of security failed logs from windows event viewer.

An account failed to log on.

Subject:

      Security ID:            SYSTEM

      Account Name:            SRV03$

      Account Domain:            xxx

      Logon ID:            0x3e7

Logon Type:                  3

Account For Which Logon Failed:

      Security ID:            NULL SID

      Account Name:            

      Account Domain:            

Failure Information:

      Failure Reason:            Account currently disabled.

      Status:                  0xc000006e

      Sub Status:            0xc0000072

Process Information:

      Caller Process ID:      0xba8

      Caller Process Name:      C:\Windows\System32\inetsrv\w3wp.exe

Network Information:

      Workstation Name:      SRV03

      Source Network Address:      -

      Source Port:            -

Detailed Authentication Information:

      Logon Process:            Authz   

      Authentication Package:      Kerberos

      Transited Services:      -

      Package Name (NTLM only):      -

      Key Length:            0

After I did some research about this event log, I found that it is related to IIS. And I had a look at the log files of IIS and found these errors. There are hundreds of these error in the log file same as the logon failed logs in event viewer.

2015-04-07 02:03:03 192.168.0.3 POST /Microsoft-Server-ActiveSync/default.eas User=user1&DeviceId=ApplDYTHQSUZDVGK&DeviceType=iPad&Cmd=ItemOperations&Log=V121_LdapC2_LdapL0_RpcC28_RpcL34_Pk2503518541_ 443 user1192.168.10.x Apple-iPad3C3/1202.466 200 0 0 254

2015-04-07 02:03:03 192.168.0.3 POST /Microsoft-Server-ActiveSync/default.eas User=user1&DeviceId=ApplDYTHQSUZDVGK&DeviceType=iPad&Cmd=ItemOperations&Log=V121_LdapC2_LdapL0_RpcC34_RpcL40_Pk2503518541_ 443 user1192.168.10.x Apple-iPad3C3/1202.466 200 0 0 332

2015-04-07 02:03:04 192.168.0.3 POST /Microsoft-Server-ActiveSync/default.eas User=user1&DeviceId=ApplDYTHQSUZDVGK&DeviceType=iPad&Cmd=ItemOperations&Log=V121_LdapC1_LdapL15_RpcC17_RpcL16_Pk2503518541_ 443 user1192.168.10.x Apple-iPad3C3/1202.466 200 0 0 162

2015-04-07 02:03:04 192.168.0.3 POST /Microsoft-Server-ActiveSync/default.eas User=user1&DeviceId=ApplDYTHQSUZDVGK&DeviceType=iPad&Cmd=ItemOperations&Log=V121_LdapC1_LdapL0_RpcC13_RpcL18_Pk2503518541_ 443 user1192.168.10.x Apple-iPad3C3/1202.466 200 0 0 102

2015-04-07 02:03:04 192.168.0.3 POST /Microsoft-Server-ActiveSync/default.eas User=user1&DeviceId=ApplDYTHQSUZDVGK&DeviceType=iPad&Cmd=ItemOperations&Log=V121_LdapC1_LdapL0_RpcC13_RpcL14_Pk2503518541_ 443 user1192.168.10.x Apple-iPad3C3/1202.466 200 0 0 92

2015-04-07 02:03:04 192.168.0.3 POST /Microsoft-Server-ActiveSync/default.eas User=user1&DeviceId=ApplDYTHQSUZDVGK&DeviceType=iPad&Cmd=ItemOperations&Log=V121_LdapC2_LdapL0_RpcC28_RpcL31_Pk2503518541_ 443 user1192.168.10.x Apple-iPad3C3/1202.466 200 0 0 318

2015-04-07 02:03:05 192.168.0.3 POST /Microsoft-Server-ActiveSync/default.eas User=user1&DeviceId=ApplDYTHQSUZDVGK&DeviceType=iPad&Cmd=ItemOperations&Log=V121_LdapC2_LdapL15_RpcC28_RpcL24_Pk2503518541_ 443 user1192.168.10.x Apple-iPad3C3/1202.466 200 0 0 248

What would be the cause of this issue here and how can I resolve the failure logs?


Touch screen stops after wake up (possibly) caused by EAS

$
0
0

Hi All,

First of all, I'm not a techie, I'm a user with a little bit more tech-interest than average. I've posted this question on the user-forum (http://answers.microsoft.com/en-us/windows/forum/windows8_1-tms/touch-screen-stops-after-wake-up-possibly-caused/c2beecb9-5b61-4017-8016-0bccba81f153) but the support engineer suggested to post the question here. So here is my question:

I have an Acer R7-371T convertible touch screen laptop and have been having issues with touch screen malfunction from the start. The problem is that if the PC is enforced into sleep mode the touch screen is not functioning after a wake-up. A reset is the only option.

I discovered that the EAS (Exchange Active Sync) policy enforced by my employer may be the cause of this. Looking at the Exchange policy rules I could not find any reason for this but let me explain what happens:

1. After a clean install of my Laptop there is no issue whatsoever. Personally defined power rules about screen-off and sleep are not causing the no-touchscreen issue and in fact, the laptop is working as it is supposed to work;

2. After installing the EAS mail in the Windows Mail app ("metro", not outlook) the policy of my employer is pushed (and accepted) on my laptop. One of the policy rules is that after five minutes of inactivity the lock-screen is pushed enforcing me to re-enter my password. And within a minute after the lock screen is shown the PC-screen is switched off or at least, seems to be in a resting mdoe. From that moment on, after awaking the laptop, the touch screen is malfunctioning.

Is this a known issue? How can I resolve this? What can I ask my employer to change in the policy to stop this malfunction?

Thanks and best regards,

Ben

Can send but not reply or forward on all mobile devices

$
0
0

Hi all,

I have a 2013 environment with MDM also in place. Just recently all mobile devices (iOS, Android, Windows OS) have stopped being able to reply or forward to emails on their mobile device. Nothing has changed in the environment that I'm aware of. The main factors are listed below.

- OWA and Outlook access is functioning as normal.

- Users can send and receive on their mobile device

- When they try to reply or forward it fails with 'Cannot Send Mail. The message was rejected by the server'.

- The user can then go into their Outbox and successfully send the email from there.

- The issue is affecting SmartForward and SmartReply commands but not the SendMail command.

Within OWA I have recorded some logs using Settings -> Options -> Phone -> Start Logging 

Within the logs the error/exception is as below.

Command_WorkerThread_Exception : 
--- Exception start ---
Exception type: System.ArgumentNullException
Exception message: Value cannot be null.
Parameter name: SubjectPrefix
Exception level: 0
Exception stack trace:    at Microsoft.Exchange.Data.Storage.StorePropertyDefinition.Set(ExchangeOperationContext operationContext, BasicPropertyStore propertyBag, Object value)
   at Microsoft.Exchange.Data.Storage.PropertyBag.SetProperty(StorePropertyDefinition propertyDefinition, Object value)
   at Microsoft.Exchange.Data.Storage.PropertyBag.SetProperty(PropertyDefinition propertyDefinition, Object value)
   at Microsoft.Exchange.Data.Storage.ReplyCreation.BuildSubject()
   at Microsoft.Exchange.Data.Storage.Item.InternalCreateReply(MailboxSession session, StoreId parentFolderId, ReplyForwardConfiguration configuration)
   at Microsoft.Exchange.Data.Storage.MessageItem.CreateReply(MailboxSession session, StoreId parentFolderId, ReplyForwardConfiguration configuration)
   at Microsoft.Exchange.AirSync.SmartReplyCommand.ExecuteCommand()
   at Microsoft.Exchange.AirSync.Command.WorkerThread()
--- Exception end ---

This appears to indicate there's an issue with the subject prefix being Null. However the issue occurs when emails have a subject and using transport rules I've set some test emails to prepend a subject to each email but that has not helped. 

I've done quite a bit of searching online but can't find anything really that matches what I'm seeing.

Has anyone experienced  something similar before? Any help would be greatly appreciated :) 

bitzi_f


EAS maxDevicePasswordFailedAttempts. Monitor failed password attempts?

$
0
0

Hi,

I'm struggling with this one. We're using Exchange 2010 SP3 and have several EAS Policies defined, which are all working fine. What I'm keen to understand is where the  maxDevicePasswordFailedAttempts is set, say to 10, is there a way of monitoring failed attempts to unlock the device. So for instance, if I can see a user who is currently at 7 failed attempts, I can intervene before they get to 10 and the device is wiped?

ActiveSync autodiscover not working for iPhone but for Android and Windows Phone

$
0
0

Hi

We have setup an Exchange 2013 hosted environment, where different mail domains are running on it.

The main domain is mydomain.com. One of the client domains is customer.com.

Autodiscover for customer.com has a cname which points to autodiscover.mydomain.com, on our firewall this url is redirected to autodiscover-s.mydomain.com, where our public certificate for mydomain.com is applied. Autodiscover for all our customers finally ends at autodiscover-s.mydomain.com.

Outlook WebApp, Outlook Anywhere and ActiveSync for all customers is reachable through mail.mydomain.com.

Everything works fine, except of autodiscover for iPhones. I always have to enter the server name mail.mydomain.com manually. After that ActiveSync works on iPhones as well.

The Problem doesn’t exist on Androids and Windows Phones.

Any suggestion?

Regards
Peter

Outlook 2013 - Lost Ability to Send Text Messages - Exchange 2010

$
0
0

Hi Folks,

I have an exchange 2010 server that has been up and running for 3+ years. I use MS exchange and Outlook 2010/2013 for receiving and replying to text messages on an Android based phone. 

Without upgrading or changing anything, this past week one of my Outlook 2013 clients lost the ability to send or reply to text messages. In Outlook under "Home:New Items" the "New Text Message" option was gone. The exchange account was still receiving text messages that were sent to the phone. But when I hit reply it said account not setup. 

I checked on another computer with an Outlook 2013 client, and it still had the option for "New Text Message". I contacted Outlook support, and they just wasted 45 minutes of my times and said they can't help because exchange was involved. 

Now several days later, all my clients have lost the option of "New Text Message". It's not greyed out from the list, it's gone. 

Thanks for the help!


Dave B


Test-ActiveSyncConnectivity Not Using CAS Server

$
0
0

Hi everyone,

I'm having an issue with ActiveSync in my new Exchange 2013 environment. I have two mailbox servers and two CAS servers. When I run the ActiveSync test on the Remote Connectivity Analyzer, all of the autodiscover pieces work, but the actual ActiveSync FolderSync command fails with the below error: 

Exception details:
Message: The request was aborted: The request was canceled.
Type: System.Net.WebException
Stack trace:
at System.Net.HttpWebRequest.GetResponse()
at Microsoft.Exchange.Tools.ExRca.Extensions.RcaHttpRequest.GetResponse()
Elapsed Time: 156 ms.

I then attempted to run the Test-ActiveSyncConnectivity cmdlet, but that also fails with the below error:

RunspaceId                  : 616f4a97-8771-4198-bf15-46b97f510748
LocalSite                   : Default-First-Site-Name
SecureAccess                : True
VirtualDirectoryName        :
Url                         :
UrlType                     : Unknown
Port                        : 0
ConnectionType              : Plaintext
ClientAccessServerShortName : <Mailbox server>
LocalSiteShortName          : Default-First-Site-Name
ClientAccessServer          : <Mailbox server FQDN>
Scenario                    : Options
ScenarioDescription         : Issue an HTTP OPTIONS command to retrieve the Exchange ActiveSync protocol version.
PerformanceCounterName      : DirectPush Latency
Result                      : Failure
Error                       : The OPTIONS command returned HTTP 200, but the Exchange ActiveSync header
                              (MS-Server-ActiveSync) wasn't returned. The request likely did not reach a Client Access
                              server, either because

                               - A proxy server intervened (check the headers below for any that may have been
                              returned by a proxy)

                               -The virtual directory could not be reached:
                              https://<Mailbox server FQDN>/Microsoft-Server-ActiveSync

                               - The virtual directory does not point to a Client Access server:
                              https://<Mailbox server FQDN>/Microsoft-Server-ActiveSync

                              HTTP response headers:

                              Allow: OPTIONS, TRACE, GET, HEAD, POST
                              Public: OPTIONS, TRACE, GET, HEAD, POST
                              Content-Length: 0
                              Date: Sat, 11 Apr 2015 18:24:56 GMT
                              Server: Microsoft-IIS/8.5
                              X-Powered-By: ASP.NET


UserName                    : extest_3ee46948de9e4
StartTime                   : 4/11/2015 2:24:57 PM
Latency                     : -00:00:01
EventType                   : Error
LatencyInMillisecondsString :
Identity                    :
IsValid                     : True
ObjectState                 : New

I believe the issue is with the test looking at the mailbox server where the test account is located, and not a CAS server. I'm not sure why the test thinks the mailbox server is a CAS server, but this seems like it would certainly cause what I'm seeing. The ActiveSync directory doesn't exist on the mailbox servers since the CAS servers are in place. 

Any ideas on this? I'm a bit stumped why ActiveSync seems to not understand there are dedicated CAS servers. Autodiscover works fine as well as Outlook connectivity using MAPI/HTTP. Only ActiveSync seems to be nonfunctional. 

Thanks!

-MRCUR

Exception details:
Message: The request was aborted: The request was canceled.
Type: System.Net.WebException
Stack trace:
at System.Net.HttpWebRequest.GetResponse()
at Microsoft.Exchange.Tools.ExRca.Extensions.RcaHttpRequest.GetResponse()
Elapsed Time: 156 ms.
Exception details:
Message: The request was aborted: The request was canceled.
Type: System.Net.WebException
Stack trace:
at System.Net.HttpWebRequest.GetResponse()
at Microsoft.Exchange.Tools.ExRca.Extensions.RcaHttpRequest.GetResponse()
Elapsed Time: 156 ms.
Exception details:
Message: The request was aborted: The request was canceled.
Type: System.Net.WebException
Stack trace:
at System.Net.HttpWebRequest.GetResponse()
at Microsoft.Exchange.Tools.ExRca.Extensions.RcaHttpRequest.GetResponse()
Elapsed Time: 156 ms.

Blocking Unauthorized SmartPhone Apps accessing Corporate e-mails using Exchange Web Services

$
0
0
Hi All,

Can anyone please guide me in restricting unauthorized apps available with various smartphones accessing the Corporate Emails using Exchange Web Services? 

The specific Exchange Web Service traffic is not passing through TMG. Hence the restriction cannot be applied on TMG.

We are looking for using EWSBlockList and it works perfectly with a single app (user agent). No luck with multiple apps or user agents. Checked the forum as well as support knowledge base and could not find anything specific powershell command to block multiple apps using EWS blocklist.

Set-CASMailbox -identity "Test App1" -EWSApplicationAccessPolicy:EnforceBlockList -EWSBlockList:"*CloudMagic*","*Aqua*" -EWSAllowOutlook:$True -EWSAllowMacOutlook:$true -EWSAllowEntourage:$true -EWSEnabled:$true

The above command blocks the app - "CloudMagic". However the other app  - "AquaMail" works perfectly.

Appreciate your thoughts and guidance.


Event ID 4203

$
0
0

We keep receiving below error, this is happening for all the users. We are in exchange 2013 sp1.

Log Name:      Application
Source:        MSExchange ADAccess
Date:          4/13/2015 8:35:09 AM
Event ID:      4023
Task Category: General
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      hioexcmbx02-prd.hq.netapp.com
Description:
Process w3wp.exe (AirSync) (PID=21152). The budget for user 'Domain\User_androidc_MotoDROIDRAZRHD' is locked out until 4/13/2015 3:10:09 AM.  Max Burst: 450000, Recharge Rate: 675000, CutoffBalance: -1125000


Thanks, Mallikarjun

Outlook still showing deleted .ics calendars in Windows Phone

$
0
0
Last year I subscribed to a couple of sports fixtures calendars on the internet (.ics). For the Six Nations rugby actually. I deleted them months ago from Outlook (my company Exchange 2010 account) and they don't show up in Outlook 2013 either on my work or home PC. However, I recently got a Windows Phone and added my company Exchange account, and for some reason they still show in the list of calendars and there's no way to remove them, only hide them. 

They must be still hidden away somewhere in my Exchange account, does anyone know how I can purge them? Thanks in advance!

Outlook doesn't connect when I'm outside my network

$
0
0

Dear all,

I have Exchange 2013 installed in the system

When I connect client PC to different network, I'm not able to use Outlook anymore(everything is okay when I'm in my network) Outlook anywhere is enabled. 

Can it be issues with an Exchange certificate, because sometimes I receive an error message asking to accept the certificate

Thank you in advance

Exchange Active Sync issue - Xiaomi Redmi 4G Note or MIUI android 4.4.4

$
0
0
Dear All, 

We are in technical support for exchange active sync. We are getting number of calls from Redmi 4g note device users, as they are unable to configure or change their password in particular device model(Redmi 4g note, android version 4.4.4 Kitkat).

The same password is working well and good in Outlook, Webmail and other android/IOS devices. 

Steps taken as of now: 
User formatted the handset, flash the device and Hard/Factory reset,
Disabled the active sync service & enable again for users from exchange server, 
Removed accounts from webmail. 
We download some apps from play store and tried but no luck. 

While configure exchange active sync in Particular model users are getting error as "User name and password incorrect". 
There is no issue from exchange server and user account. as same is working fine in other devices. This issue happening for more that 10 users and receiving more calls day by day.

I request anybody to take it forward and provide the solution/suggestion, if it is a known bug for particular device model. Please confirm back. 

We are waiting for someone valuable reply. Many thanks in advance. 

- Senthilkumar.

Event ID 4023

$
0
0

We keep receiving below error, this is happening for all the users. We are in exchange 2013 sp1.

Log Name:      Application
Source:        MSExchange ADAccess
Date:          4/13/2015 8:35:09 AM
Event ID:      4023
Task Category: General
Level:         Error
Keywords:      Classic
User:          N/A
Computer:     abcd.nt.contoso.com
Description:
Process w3wp.exe (AirSync) (PID=21152). The budget for user 'Domain\User_androidc_MotoDROIDRAZRHD' is locked out until 4/13/2015 3:10:09 AM.  Max Burst: 450000, Recharge Rate: 675000, CutoffBalance: -1125000


Thanks, Mallikarjun




ActiveSync on Exchange 2013 suddenly decided to stop working

$
0
0

Hi all,

Until yesterday, I had fully functional Exchange server. Overnight some bundle of updates came and server had restart, in the morning ActiveSync for mobile deviced stopped working. After restart of Ex server, there suddenly appeared a lot of associated problems - OWA and ECP on both external and internal domains stopped working - diplaying notorious "Sorry! Access Denied" and a  lot of critical erros in Event Viewer. 

Sorting all these isues, I managed to make everything working, except ActiveSync.

ExRCA  throwing this HTTP OPTIONS realted errors with following message.

Attempting to send the OPTIONS command to the server.
 Testing of the OPTIONS command failed. For more information, see Additional Details.
 
Additional Details
 
An HTTP 500 response was returned from Unknown.
HTTP Response Headers:
request-id: 5dbb5e4d-e7fd-442d-abd9-370204c0af20
X-TargetBEServer: server.contoso.local
X-DiagInfo: SERVER
X-FEServer: SERVER
Content-Length: 8441
Cache-Control: private
Content-Type: text/html; charset=utf-8
Date: Thu, 16 Apr 2015 19:54:17 GMT
Set-Cookie: X-BackEndCookie=S-1-5-21-2895690208-1618913748-335857996-1239=u56Lnp2ejJqBzs7JyczMz8zSnc/KzdLLysfO0sfGnZvSnJ7LzcyanZzGmczJgYHOydDPy9DNz87K383Pxc/Lxc7H; expires=Thu, 16-Apr-2015 20:04:18 GMT; path=/Microsoft-Server-ActiveSync; secure; HttpOnly
Server: Microsoft-IIS/7.5
X-AspNet-Version: 4.0.30319
X-Powered-By: ASP.NET
Elapsed Time: 296 ms

Same time, ActiveSync Autodiscover test passes.

Everything works fine, OWA, etc, but not a single mobile device with allowed ActiveSync can connect to server.

Would appreciate any ideas helping to solve that, thanks!




Exchange ActiveSync Administrator Emails : Exchange Server 2010 SP3 RU 8v2

$
0
0

Hi there,

We are using Exchange Server 2010 SP3 and I recently installed RU 8v2. We always had an ActiveSync Access Policy in place where the devices are quarantined until an Administrator goes in and approves or rejects this.

Prior to installing RU 8v2, there used to be a link in the email sent to Administrators to click on to login to the ECP and approve this device. However, since the install of this update, there is no link in the emails now. It just informs you that you need to login to ECP and view the quarantined devices. Has this been removed in the RU?

Thanks

Settings for ActiveSync Policy reverts

$
0
0

I´m unable to allow the settings Allow unsigned applications and Allow unsigned installation packages
in ActiveSync Policy.

I can mark the checkboxes in the GUI or change the value to True in the CLI but after some minutes the settings have reverted back again.

Have tried to create a new policy but the same thing happens.

We are running Exchange 2010 version 14.03.0210.002.

How to know if mobile device has password

$
0
0

I have mobile devices connected to Exchange using Active Sync , I want to make sure if the these active sync device has passcode enabled on them .

is there any PowerShell command and/or UI that can tell me if the connected mobile device has passcode or not

Change acccount password through mobile devices (activesync)

$
0
0
Is there any way to let domain users be able to change their password through mobile devices. a third party application or anything to do the job
Viewing all 1206 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>