Link to home
Start Free TrialLog in
Avatar of wannabecraig
wannabecraigFlag for Ireland

asked on

trying to connect to exchange using iPhone - Activesync.

I get the below error when trying to connect to exchange using my iPhone,
I am a domain admin so not sure what this error means,.

Exchange ActiveSync doesn't have sufficient permissions to create the "CN=xxx xxx,OU=Users,OU=xxx,DC=xxx,DC=local" container under Active Directory user "Active Directory operation failed on DC.xxx.local. This error is not retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-03152492, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
".
Make sure the user has inherited permission granted to domain\Exchange Servers to allow List, Create child, Delete child of object type "msExchActiveSyncDevices" and doesn't have any deny permissions that block such operations.
ASKER CERTIFIED SOLUTION
Avatar of Chris
Chris
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Avatar of Alan Hardisty
Alan Hardisty
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
The accepted solution doesn't solve the problem permanently.  After an hour, the problem will reappear because you will still be a domain admin and the SDPROP process will strip the inherited permissions from the account again.

Alan