Solved

How to remove the forced lock screen and Pin requirement in SBS2011 activesync?

Posted on 2012-04-11
12
7,744 Views
Last Modified: 2012-06-21
I have a client that wants the forced policy removed from the exchange server that applies to smart phones.
anyone know a quick link to the instructions?  at the moment I don't want to read a big document explaining how to understand the whole policy, just want to remove the forced pin and lock screen settings.  for androids and iphones.
0
Comment
Question by:R. Andrew Koffron
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
12 Comments
 
LVL 8

Accepted Solution

by:
didnthaveaname earned 400 total points
ID: 37835291
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 37835314
I take it that your customer is aware that if they do this and a phone is lost, that they won't be able to remotely wipe the device, so data on the device would be compromised very easily?
0
 
LVL 76

Assisted Solution

by:Alan Hardisty
Alan Hardisty earned 100 total points
ID: 37835320
Also - unless the Policy Refresh Interval has been set in the Policy, which it isn't by default, you will have to remove all accounts on all the phones before the settings would be removed from the devices, then setup the accounts again having enabled the Policy Refresh Interval before adding the accounts back.
0
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 16

Author Comment

by:R. Andrew Koffron
ID: 37835324
@alanhardisty, yupp explained it, but they don't care. and also the company doesn't  actually own any of the phones. and most importantly the person that pays me doesn't want to hear anything except "ok it's fixed" just remove and re-add.

@didnthaveaname, thanks looks like what I needed. will let you know as soon as client has a chance to tell me.
0
 
LVL 16

Author Comment

by:R. Andrew Koffron
ID: 37835343
@alanhardisty where is the policy refresh interval setting?
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 37835370
Exchange Management Console> Organization Configuration> Client Access> Exchange Activesync Mailbox Policies> Default Policy Properties> General Tab> Refresh Interval (hours).

If you set the interval and then make changes to the policy, the interval will then determine how often the devices check in for Policy Changes.  No Interval - no check in for changes.

Do you know the reason behind losing the setting?  Is it because the password interval is too short and they are getting pissed off (like I did) with having to enter the PIN too often?  If that is the case, you can change the interval to be much longer e.g., 2 hours without use before needing to be entered.
0
 
LVL 16

Author Comment

by:R. Andrew Koffron
ID: 37835397
@alanhardisty I did offer to lengthen the time. but they're just pissed off at it. so won't listen. I'll re-address it in a while. everything else is going great and they love the SBS2011 so they'll be all shinny in a month or so:)
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 37835418
I understand - but would never recommend removing it completely, but then as long as you have advised them of the risks and they acknowledge that, then you can't do much else.

You could ask them to try a 2 hour lock - or longer if you want for a week and see if they are happier and if not, then remove it completely?  Might be worth asking?
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 37835459
Having said that - SBS 2011 will only let you set a 60 minute max inactivity timeout before you need to re-renter the PIN.
0
 
LVL 16

Author Comment

by:R. Andrew Koffron
ID: 37835470
well I'll go back and try and turn it on in a while, when they're not mad about it. especially when general employees start getting access.
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 37835475
Well - if you at least have the Policy refresh interval set - then you can turn it on / turn it off and the devices will at least pick up the change, whereas by default, they get the 5 minute timeout and no refresh of the policy.

Good luck switching it on as and when you do :)

Alan
0
 
LVL 16

Author Closing Comment

by:R. Andrew Koffron
ID: 37835838
thanks guys, worked perfectly,  
I split the point based ont he refresh interval setting that will prevent future need for rebooting and deleting accounts off phones.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Lotus Notes – formerly IBM Notes – is an email client application, while IBM Domino (earlier Lotus Domino) is an email server. The client possesses a set of features that are even more advanced as compared to that of Outlook. Likewise, IBM Domino is…
If you troubleshoot Outlook for clients, you may want to know a bit more about the OST file before doing your next job. IMAP can cause a lot of drama if removed in the accounts without backing up.
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question