We help IT Professionals succeed at work.

your account does not have permission to sync with current settings for some users only

5,532 Views
Last Modified: 2012-05-06
Hi All,

I have been struggling for the past one month with this strange problem.

I have an exchange server 2003 with about 100+ users.  Out of which, there are about 20-30 users are using mobile phones for push emails.  The phones are HTC S710, Nokia E63 and E71.

Until last month, any user i setup in the mobile device, i was able to do sync with my exchange server from the phones.  Since last month, i can't configure a phone with a new user email whether that user id itself is there for few years or created in the last month.  In the same month, if i setup my mail id, it works.  It means the phone is alright.  In the same way, if i setup the same user email in my phone, the sync does not work and comes up with the above error
' your account does not have permission to sync with current settings'.

I have tried the following already without luck:

1. checked the active directory properties 'Exchange features' and all are enabled.
2. Unticked 'Secure layer only' & ticked 'Secure layer only' under server certificate option in IIS-MS Activesync Directory security property.
3. ticked/unticked 'Anonymous access' using 'IUSR_Computername' userid.
4. ticked/unticked ' Integrated authentication'
5. ticked/unticked ' basic authentication'.

Restarting IIS services after 2,3,4 & 5 above.  No luck.

I did the above for 'OMA' and 'Mobile' as well. no luck.

Only thing i haven't tried is deleting and recreating MS-Activesync virtual directory. This is because there are about 20 users who are using this and it is working for them.  I'm bit scared of trying to delete virtual directory as this may cause problem for them as well.

Please help as i have ran out of ideas.

Thank you in advance.

Regards
RK
Comment
Watch Question

Author

Commented:
Just add to my question,  I have tried the problematic users email ids in more than 2/3 phones where if i setup my email, it works.
Expert of the Quarter 2009
Expert of the Year 2009

Commented:
Anything that connects the users? Email addresses for example? Are you running additional email addresses on the server?

Simon.
Hello,
What kinda Certificate you are having? (internal/ external or public)
In case you are having a public certificate try testing it with site www.testexchangeconnectivity.com

Author

Commented:
I'm using public certificate issued by Geotrust/equifax.  I will check with the link you sent.

ta
RK

Author

Commented:
Hi aletjolly,

I tried the link you gave me.  It doesn't help much.  

I'm still having trouble setting up new users for email connectivity in mobile phones.

Please help.

Thanks & Regards
RK
Expert of the Quarter 2009
Expert of the Year 2009

Commented:
When you ran the test on the Microsoft site, was the test successful, or did it fail?
It provides a lot of troubleshooting information if the test was unsuccessful. If the tests all passed then it is not a setup problem with the server, but has to be related to the user account.

Simon.

Author

Commented:
Hi Mestha,

When i ran the test with my user id and password, the test was successful, whereas if i try with any other new users (not necessarily a new user in AD - the new user means, never set up push email in windows mobile devices), the test failed with the following error:  

An HTTP 403 forbidden response was received. The response appears to have come from Unknown. Body is: <body><h2>HTTP/1.1 403 Forbidden</h2></body>

Is there any limit on no. of users i can configure to use windows active sync to in exchange 2003 server?

RK
Expert of the Quarter 2009
Expert of the Year 2009

Commented:
Forbidden is an annoying error, as there is no single reason for it. There are no limits on the number ActiveSync clients, and if you were hitting some other kid of error I would expect to have a different error message - access denied rather than forbidden.

I would start by looking at the http logs for when you do the test, verify the attempt is being made by the correct account as Exchange sees it. I have seen some odd configurations that means only users with certain permissions can access the directory.

Simon.

Author

Commented:
When i check the event log (application) when the connection fails, i get this event id 3005.

Unexpected Exchange mailbox Server error: Server: [leb-ex001.GBR.lebara] User: [username@domain.com] HTTP status code: [409]. Verify that the Exchange mailbox Server is working correctly.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.    


Expert of the Quarter 2009
Expert of the Year 2009
Commented:
This one is on us!
(Get your first solution completely free - no credit card required)
UNLOCK SOLUTION
Commented:
This one is on us!
(Get your first solution completely free - no credit card required)
UNLOCK SOLUTION
Unlock the solution to this question.
Join our community and discover your potential

Experts Exchange is the only place where you can interact directly with leading experts in the technology field. Become a member today and access the collective knowledge of thousands of technology experts.

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.