Solved

MS exchange 2007 Active Sync on new accounts.

Posted on 2013-05-30
3
229 Views
Last Modified: 2013-06-03
Hi hope someone might help us out here.

When creating new exchange accounts in Exchange 2007 the default setting for a new accounts Mailbox feature ActiveSync needs to be disabled. How do we achieve this?

when creating new accounts we can off course do this by creating the account in PS with this option disabled as part of the command; or indeed create using the normal wizard then turn it off in the gui on completion. To me it should be off as default as it is a potential security issue for some users whom I might not want access outwith. Having this turned off as a default prevents admins from having to consider or completing this as an extra step.

I did see a note with regards to editing the ScriptingAgentConfig.xml file in Exchange 2010 but am unsure how this translates to 2007, if at all.

Anyway thank you in advance for any suggestions.
0
Comment
Question by:fletcher_l
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 4

Accepted Solution

by:
Jeffery Hayes earned 150 total points
ID: 39208430
Not as simply as one would have hoped.

http://technet.microsoft.com/en-us/library/bb124243(v=exchg.80).aspx 

* If you must disable Exchange ActiveSync across your organization, you can configure the Exchange ActiveSync virtual directory to refuse all connections by stopping the Web services on that virtual directory.*

http://technet.microsoft.com/en-us/library/bb124502(v=exchg.80).aspx How to disable Active Sync

However the best method I would simply do is within EMS by the following command.

Set-CASMailbox -identity adam@contoso.com -ActiveSyncEnabled $false

However if you would want this done as a daily thing for all new accounts created simply run this command.

Get-Mailbox -resultsize unlimited | where {$_.WhenMailboxCreated -gt (get-date).adddays(-1)}| Set-CASMailbox -OWAEnabled $false

PowerShell is the best method to get it complete if you ask me.
0
 
LVL 52

Assisted Solution

by:Manpreet SIngh Khatra
Manpreet SIngh Khatra earned 100 total points
ID: 39213878
There is no first hand way to achieve this but to run commands afterwards to achieve what you want

You can have this in a Scheduler and let it run every few hours and if it finds any new account it will disable .... but hope your disabling for all mailboxes in the environment ?

Get-Mailbox -resultsize unlimited | where {$_.WhenMailboxCreated -gt (get-date).adddays(-1)}| Set-CASMailbox -ActiveSyncEnabled $false

- Rancy
0
 

Author Closing Comment

by:fletcher_l
ID: 39215690
Thanks for your comments. Nice to confirm it was just a limitation of the system. As suggested seems a pretty obvious item to have turned off by default imo. I will work it in to our environment, I'm not a big fan of scheduled tasks so may apply it as part of company new account process to disable ActiveSync and consider a one time run to disable all those who currently do not use it. I'll monitor that and perhaps supplement it with the scheduled task to remove the "human element" a little.

Again Thanks. :-)
0

Featured Post

Revamp Your Training Process

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

An analysis of the phishing scam that has been affecting Google users, along with steps to take for protection, as well as what to do if you receive one of the emails.
Phishing attempts can come in all forms, shapes and sizes. No matter how familiar you think you are with them, always remember to take extra precaution when opening an email with attachments or links.
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

718 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question