Link to home
Start Free TrialLog in
Avatar of SpiderPig
SpiderPigFlag for United States of America

asked on

Failes ActiveSync on Exchange 2010 after moving mailboxes from Exchange 2003 to Exchange 2010?!

Hello all,
I finished moving mailboxes from Exchange 2003 to Exchange 2010 last night. To test that everything is working fine, I took my iPhone and configured it to use Exchange (ActiveSync) to the Exchange 2010 server. I did updated all the NAT records and Firewall rules to point o the new Exchange 2010. From some reason the iPhone sync failed. When I checked the Windows 2008 R2 that hosts Exchange 2010 event log I noticed I am getting the following error:

Log Name:      Application
Source:        MSExchange ActiveSync
Date:          6/5/2010 9:37:23 AM
Event ID:      1031
Task Category: Requests
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      xxxxxx.xxxxxx.local
Description:
User "xxxxxxxx\administrator" cannot synchronize their mobile phone with their mailbox because  Exchange ActiveSync has been disabled for this user.

I did checked if this user has the ActiveSync enabled for him and it IS enabled! I am confused?! Any ideas why activesync stopped working here.

p.s. I do have a certificate key purchased from Godaddy and implemented on Web, IMAP, SMTP, and OWA, WEB. When I access OWA for this user it worked great!

Thanks.
Avatar of SpiderPig
SpiderPig
Flag of United States of America image

ASKER

By the way I am loging in with username only same password and the domain where iphone is asking for it. It used to work on the Exhcange 2003. I also config the Exchange 2010 OWA to login with username only without typing the domain infront of it, so typing the username only in the username should work...

Avatar of Alan Hardisty
You need to enable the inheritance on the 'AdminSDHolder' container from the ADSIEDIT.

The location will be --- Domain Partition --- > System --- > AdminSDHolder --- > Right click and go to the properties and under 'Security' tab check the box which reads 'Allow inheritable permissions'.

Replicate the changes between the Domain Controllers and try to sync the device once again.

Let us know how it goes.
@lastoflast - you have not read my article then!
I tried both solutions and both failed. I still getting Exchange account verification failed. Maybe I need to wait for this to sync?

How do I manually sync?

Thanks.
Can you remove the tick from the Inherited permissions box, then click apply, then put it back again and hit apply again please.

Once done, please try again.  Sometimes the settings need some encouragement.
Is the user an Administrative user?  Have you tried syncing a normal user account?
Yes the user is the administrator user, no I didn't try regular user. Let me try.

The unclick and click did not work.

Thanks.
Yes, regular user worked. I wonder why only the Administrator account does not work.

I use this every now and then to test ActiveSync to the Exchange, this is not permanent.
My article explains why this happens.
Yeah but there has to be a solution to this.

I am also getting this error message. I checked the firewall (Sonicwall TZ-190) but couldnt find anything there. Not sure if this is related. Probably not.

Log Name:      Application
Source:        MSExchange ActiveSync
Date:          6/5/2010 3:47:22 PM
Event ID:      1040
Task Category: Requests
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      xxxx.xxxx.local
Description:
The average of the most recent heartbeat intervals [351] for request [Ping] used by clients is less than or equal to [540].
Make sure that your firewall configuration is set to work correctly with Exchange ActiveSync and direct push technology. Specifically, make sure that your firewall is configured so that requests to Exchange ActiveSync do not expire before they have the opportunity to be processed.

For more information about how to configure firewall settings when using Exchange ActiveSync, see Microsoft Knowledge Base article 905013, "Enterprise Firewall Configuration for Exchange ActiveSync Direct Push Technology" (http://go.microsoft.com/fwlink/?linkid=3052&kbid=905013).
ASKER CERTIFIED SOLUTION
Avatar of lastlostlast
lastlostlast
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial