Link to home
Start Free TrialLog in
Avatar of Sovereign2
Sovereign2Flag for United States of America

asked on

Activesync Backend Server

Every evening I have to check the /exchange virtual directory integrated windows authentication in order for mobile devices to receive email. When I go back the following evening the box is unchecked, what could cause this problem?
Avatar of Manpreet SIngh Khatra
Manpreet SIngh Khatra
Flag of India image

Is there anything on the event logs during that time ?
What is the Exchange version ?
What if you enable EVD Windows authentication and the do IISRESET and check ?
Also check this one from TechSoEasy
https://www.experts-exchange.com/questions/22056346/IIS-Exchweb-bin-keeps-loosing-Permissions-settings.html

- Rancy
Avatar of Sovereign2

ASKER

The Os is windows server 2003 EE SP2 with Exchange 2003 SP2. This setup has a FE server with to BE servers. The BE server that I have to select integrated windows authenication each evening is configured the same as the working BE server. As soon as I select integrated windows authentication under /exchange VD email is delivered immediately. I am not sure about EVD windows authentication. Integrated windows authentication is the option required for this to work.
https://www.experts-exchange.com/questions/27475836/Exchange-forms-based-authentication-and-integrated-security.html

If you have FBA (forms based auth) enabled, you cannot simulataneously have Integrated enabled for OWA. If you want both to work simultaneously, what I suggest doing is this:

1. Create a second OWA site in System Manager (I think this automatically creates a corresponding IIS web site- if not, create a new site in IIS first, then create the OWA site in ESM.

2. Configure the new OWA/IIS site to listen on a unique IP, port, or dedicated host header (to avoid a conflict with the current OWA/IIS site)

3. Configure one OWA site with ESM to use FBA, the other site configure for Integrated Auth.

4. Create an internal DNS record so that internal clients are sent to the OWA/IIS site with Integrated Auth, ensuring it's unique vs. the publicly accessible OWA/IIS site.

Let me know if you need more details, I've been deep in Ex 2007/2010 for the past 4 years so it's hard to remember all the details of 03!


Checkout the article might help your issue.

- Rancy
Avatar of ExchangePandit
ExchangePandit

Please have a look at this article:

http://support.microsoft.com/kb/937031/en-us

Note: This article applies to Exchange 2003 FE/BE topology as well.
ExchangePandit

Thanks for your article

However, This article references a mixed topology of exchange 2007 and 2003. My topology of which I am experiencing the problem above is a 2003 FE and two 2003 BE severs. I have read the article and it references the /Microsoft-Server-ActiveSync directory. The directory I have to continually check is /exchange virtual directory.

thks
ASKER CERTIFIED SOLUTION
Avatar of ExchangePandit
ExchangePandit

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ExchangePandit thanks for your response. I have opened the Exchange System Manager as you requested and the selection box is greyed out. I can't make the selection from there. Since I last made the change via IIS and rebooted, I haven't had a problem. I will monitor this for a few more days and if I don't have any problems. I will return to the post.

thks
The issue will reoccur, please follow the below to resolve:

Solution:

http://support.microsoft.com/kb/937031/en-us

Install hotfix on your Exchange 2k3 BACKEND--->Follow WORKAROUND to enable Windows integrated.

Cheers