Link to home
Start Free TrialLog in
Avatar of iain_stephen
iain_stephenFlag for Canada

asked on

Exchange 2007 remote wiped phone - cannot connect to exchangeserver with new user

We had a user that was recently 'let go' while still in possession of his Palm Treo Pro.  We remote wiped it on the exchange server - which worked very well.   This user returned the phone and the partnerships etc. were deleted from his account, and his account closed.
The phone is now assigned to another individual - we cannot get it to connect to the Exchange Server to sync at all.  We have verified the username/password/domain using OWA - and the phone can surf the web, but it will not connect to the exchange server.
Avatar of Alan Hardisty
Alan Hardisty
Flag of United Kingdom of Great Britain and Northern Ireland image

Your remote wipe may have removed the relevant certificate on the phone.  Do you use a self-signed certificate or a purchased one?
If purchased, then you should be okay.
If a self-signed one - you will need to install the certificate on the phone.
The ID stays inside Exchange somewhere on a kind of blacklist. I have seen a posting on this but I cannot find it right now.
Have you hard reset the device?

Simon.
Whats the error you are getting on the phone while synchronizing
Avatar of iain_stephen

ASKER

We used a purchased SSL Cert from DigiCert...  never have to install the cert separately on phones.

There is no specific error - when attempting to sync, it just defaults back to the activesync setup as if the credentials were incorrect, but they're not.. we verified them through OWA.  We have tried re-typing them, have changed the password on the account - still get the same thing.  I think the comment on the blacklist is the issue as it seems like exchange is simply not willing to talk to this particular smartphone.
What happens if you use the IP address rather than the FQDN?
Changed to IP of the server instead....  Of course, the ssl cert if tied to the FQDN so I am getting a certificate error now...

The device is not showing up in the 'manage mobile device' area of the user account at all.

I really think Exchange has 'blacklisted' the device.
I was expecting that - but thought it would be worth a try.
Yes - that sounds sadly quite viable.
 
I should also state that we have done a hard-reset on the phone, so the problem is not the phone.

I just tried to set it up for another user as a test - same problem.
There must be a way to review the list of 'blocked' devices on the server and remove them?
I have seen this posted somewhere, but I read so much on Exchange that I cannot remember where it was. The ID is blocked and has to be removed.
You have to undo something I think.

Has the user account of the original user been deleted from the domain?

Simon.
The user account of the original user is disabled but not deleted as there is still a need to access some of his information (policy is delete after 90 days).
I wonder if the wipe command is still in the system, and each time you connect it is being blocked.
What exactly did you do to remove the partnerships? Did you do that through Exchange/OWA or just on the device?

Run this: (replacing SERVERNAME with the name of your Exchange 2007 server)

Get-Mailbox -server SERVERNAME -ResultSize:Unlimited | ForEach {Get-ActiveSyncDeviceStatistics -Mailbox:$_.Identity} |ft identity,devicemodel,LastSuccessSync

That will show all the devices that Exchange knows about.

Simon.
Ok - text from that query is below...
We wiped the device first, then when it was handed back in we 'removed' the wipe (even though it had wiped it seemed to want to do that first) then removed the partnership. There are no mobile devices showing up for the 'old' user at all, and activesync for his account is disabled.
\Identity DeviceModel LastSuccessSync
-------- ----------- ---------------
Jeff.Aiken@ems.mycompany.com\AirSync-Poc... Palm Treo 850e 10/23/2009 8:08:53 PM
Gary.Champagne@mycompany.com\AirSync-Poc... 10/13/2009 3:33:47 PM
david.court@mycompany.com\AirSync-Pocket... Palm Treo 850e 10/8/2009 11:38:03 PM
Mario.Danis@mycompany.com\AirSync-Pocket... Palm Treo 850e 10/23/2009 8:14:44 PM
Fern.Dominelli@mycompany.com\AirSync-Pal...
Fern.Dominelli@mycompany.com\AirSync-Pal...
Fern.Dominelli@mycompany.com\AirSync-Pal... 10/23/2009 7:59:51 PM
Fern.Dominelli@mycompany.com\AirSync-Poc... 8/28/2009 8:36:23 PM
Cindy.Dube@mycompany.com\AirSync-PocketP... Palm Treo 850e 10/20/2009 9:23:23 PM
Greg.Gilbert@mycompany.com\AirSync-Pocke... NEON400 10/23/2009 8:08:42 PM
michael.macisaac@mycompany.com\AirSync-P... Palm Treo 850e 10/23/2009 8:10:11 PM
michael.macisaac@mycompany.com\AirSync-P... 6/9/2009 6:58:23 PM
Suzanne.Malette@mycompany.com\AirSync-Po... 10/23/2009 6:45:28 PM
Donna.Moroso@mycompany.com\AirSync-Smart... 10/23/2009 8:10:35 PM
Connie.Morphet@mycompany.com\AirSync-Pal... 10/23/2009 8:18:29 PM
Connie.Morphet@mycompany.com\AirSync-Sma... SPH-i325 8/29/2009 1:26:32 AM
Nano.Debassige@ems.mycompany.com\AirSync... 10/23/2009 8:08:53 PM
Iain.Stephen@mycompany.com\AirSync-Pocke... SAMSUNG SCH-i910 10/23/2009 8:15:42 PM
Iain.Stephen@mycompany.com\AirSync-Pocke... TITA100 4/14/2009 6:52:06 PM
The account the phone was assigned to is not there, nor is the new user we are trying to associate the device with.
Hello Again,

Well, I just factory re-set the phone again this morning and sync'd it with my account as a test (tried that last week but had already tried to connect it to other account first)...  

Doing this allowed the phone to sync with my credentials.  So that means the device is not the issue.

I removed the partnership with my account and I factory-reset the phone again.  I changed the user's password to make 100% sure that I have his credentials right and it still won't let me connect.

So - it would appear that there is a problem with his account, and that was the problem all along...  but now I am just as lost as I don't see anything that would cause this - Activesync is enabled in Exchange 2007 for this user... his account was originally set up as a 'copy' of another account that has a functional smartphone.  Where else would this be getting blocked by either policy or permissions?
ASKER CERTIFIED SOLUTION
Avatar of iain_stephen
iain_stephen
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial