Hello EE. I am having a hell of a time trying to get one iphone4 user to to access OWA on Exchange 2010. I was able to successfyully set up 3 others with no problem. It keeps giving me "Exchange Account Unable to verify account information."
The only difference between her phone and the others is the OS is running 4.2.1 and the others are running 4.1. Inheritable permissions is checked on her AD profile. I was getting event id 1503:
Exchange ActiveSync doesn't have sufficient permissions to create the "CN=User,OU=XXXXX_XXXXX Administrators,DC=MHACS,DC=local" container under Active Directory user "Active Directory operation failed on MHAS.MHACS.local. This error is not retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-031521D0, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
".
Make sure the user has inherited permission granted to domain\Exchange Servers to allow List, Create child, Delete child of object type "msExchangeActiveSyncDevices" and doesn't have any deny permissions that block such operations.
Details:%3
After checking allow inheritable rights in security tab I stopped getting that error but I still can not sync the phone. I tried with and without SSL. I do have a valid SSL ceert from GoDaddy. The other 3 phones gave no problems.. I have Exchange 2010 running on Windows 2008 R2 standard with a DC running Win 2008 R2 Enterprise. My luck she happens to be an Executive Administrator and is a domain admin as well. Any help would be appreciated.
ExchangeWindows Server 2008
Last Comment
Alan Hardisty
8/22/2022 - Mon
expert02232010
You have verified that ActiveSync is enabled for the mailbox in exchange?
Can the user use the web browser to access OWA through the phone?
InSearchOf
ASKER
Yes on both counts.
Alan Hardisty
Are you adding /owa to the end of the Fully Qualified Domain Name that you are configuring your iPhone with? If you are - you should not be - you only should be entering something like mail.domain.com and not mail.domain.com/owa
FYI - OWA is Outlook Web Access and has nothing to do with getting mail to an iPhone. What you are referring to is Activesync.
I tried it without anything after .com but no change
Alan Hardisty
Email Address: users email address e.g. user@domain.com
Server: Whatever the certificate name includes e.g. mail.domain.com or www.domain.com or whatever you have configured
Domain: Internal Domain Name e.g., internaldomain (not internaldomain.local
Username: Users username e.g., user
Password: Users network password
Description: Whatever takes your fancy to describe the account on the phone.
Okay - can you please run the Exchange Activesync Test (Not Exchange Activesync Autodiscover Test) on https://testexchangeconnectivity.com and port the results (hiding your domain name / IP Address).
Please run one for the working user and one for the non-working user and post both results.
Thanks
Alan
InSearchOf
ASKER
I do not have access to the wtestorking one but this is what I got from the non working one
The last part of the test failed. this is what it said.
An ActiveSync session is being attempted with the server.
Errors were encountered while testing the Exchange ActiveSync session.
Test Steps
Attempting to send the OPTIONS command to the server.
The OPTIONS response was successfully received and is valid.
Additional Details
Headers received: Allow: OPTIONS,POST
MS-Server-ActiveSync: 14.1
MS-ASProtocolVersions: 2.0,2.1,2.5,12.0,12.1,14.0,14.1
MS-ASProtocolCommands: Sync,SendMail,SmartForward,SmartReply,GetAttachment,GetHierarchy,CreateCollection,DeleteCollection,MoveCollection,FolderSync,FolderCreate,FolderDelete,FolderUpdate,MoveItems,GetItemEstimate,MeetingResponse,Search,Settings,Ping,ItemOperations,Provision,ResolveRecipients,ValidateCert
Public: OPTIONS,POST
Content-Length: 0
Cache-Control: private
Date: Mon, 07 Mar 2011 21:37:22 GMT
Server: Microsoft-IIS/7.5
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
Attempting the FolderSync command on the Exchange ActiveSync session.
The test of the FolderSync command failed.
Tell me more about this issue and how to resolve it
Additional Details
Exchange ActiveSync returned an HTTP 500 response.
Alan Hardisty
What browser are you using?
Alan Hardisty
Okay - you say you have checked the Inherited permissions - please uncheck - apply - then re-check and apply - then test again.
Can the user use the web browser to access OWA through the phone?