Improve company productivity with a Business Account.Sign Up

x
?
Solved

ActiveSync Permission Issues - 0x85010004

Posted on 2008-06-18
4
Medium Priority
?
3,526 Views
Last Modified: 2012-08-13
Hi
 
Really hitting a brick wall now and would appreciate some ideas on what to try next.
 
Current setup is Exchange 2007 (Separate Mailbox and CAS) using IIS 7 on Server 2008.
Using properly issued Cybertrust certificate.
Link from external goes through ISA 2006.
 
OWA works fine internally and externally no problems at all.
 
ActiveSync gives the following error when I try to sync:
 
"Your account in Microsoft Exchange Server does not have permission to synchronize with your current settings. Contact your Exchange Server administrator. 0x85010004"
 
Tried externally using a Dell x51v and internally using Microsofts emulator. Same error on both.
 
 
 
Things done:
 
 
1. Deleted and recreate the Exchange Activesync mailbox policy. Pointed the mailboxes manually to the policy. As a side not, what are the best settings for the ActiveSync mailbox policy ? I tend to leave it default, but this leaves the "require password" unticked.
 
2. Deleted and recreated the Virtual Directory in IIS. (via powershell commands)
 
3. Pointed all services to the proper certificate (Enable-exchangecertificate) - also making the internal and external URLs of Activesync match our certificate ie. (www.ourdomain.ac.uk/Microsoft-Server-Activesync)
(http://www.shudnow.net/2007/08/10/outlook-2007-certificate-error/)
 
4. Enabled ActiveSync on the test users mailbox, both in the console and via the powershell commands. Some people are indicating that even though it already is enabled, this proved a fix.
 
5. Disabled SSL - This gives the same 0x85010004 error.
 
6. Also tried the  Test-ActiveSyncConnectivity from Powershell. This gives the following error.
 
[System.Net.WebException]: The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel. Inner error [System.Security.Authentication.
AuthenticationException]: The remote certificate is invalid according to the validation procedure.
[System.Security.Authentication.AuthenticationException]: The remote certificate is invalid according to the validation procedure
 
 
 
Really stuggling now. Please help !
0
Comment
Question by:oldhamcol
  • 2
  • 2
4 Comments
 
LVL 10

Expert Comment

by:Casey Herman
ID: 21811745
Are you trying to run ssl or not that is the big question....?
If you are than you have to get a certificate installed in IIS for the phones to work properly.

If not then you have to create the extra virtual directory that acts as a pathway to the ssl side of oma.

First things first check to see if you can log into oma from a workstation.

http://servername/oma

Casey
0
 

Author Comment

by:oldhamcol
ID: 21812190
Yes, we are trying to run SSL, bought a certificate from Cybertrust.

The problem I am having is with Exchange 2007, OMA has been discontinued.

Thank you for taking the time to reply though.
0
 
LVL 10

Expert Comment

by:Casey Herman
ID: 21818504
sorry didn't catch the 2007 mistook it for an '03.  
HAve tried turning on the verbose logging in active sync?

Casey
0
 

Accepted Solution

by:
oldhamcol earned 0 total points
ID: 21820924
FIXED !!

Turned out to be the Authentication delegation rule on ISA, which is set differently on the OWA isa rule.

*phew*
0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

If there is anything erroneous with Exchange Database, it causes a significant effect on email communication till the user remounts the database. Further, database crash directly affects Outlook users due to which they are unable to access their ema…
In a Cross Forest, the steps to migrate users are quite complicated and even in the official articles of Technet there is no clear recommendation on which approach to take .. From an experience, I mention and simplify which way to go and how to use …
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…
This video tutorial shows you the steps to go through to set up what I believe to be the best email app on the android platform to read Exchange mail.  Get the app on your phone: The first step is to make sure you have the Samsung Email app on your …

606 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question