trying to connect to exchange using iPhone -  Activesync.

Posted on 2013-10-21
Medium Priority
Last Modified: 2013-10-21
I get the below error when trying to connect to exchange using my iPhone,
I am a domain admin so not sure what this error means,.

Exchange ActiveSync doesn't have sufficient permissions to create the "CN=xxx xxx,OU=Users,OU=xxx,DC=xxx,DC=local" container under Active Directory user "Active Directory operation failed on DC.xxx.local. This error is not retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-03152492, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
Make sure the user has inherited permission granted to domain\Exchange Servers to allow List, Create child, Delete child of object type "msExchActiveSyncDevices" and doesn't have any deny permissions that block such operations.
Question by:wannabecraig
  • 2
LVL 12

Accepted Solution

Chris earned 1000 total points
ID: 39587797
This is a fairly common issue usually seen after upgrading exchange.

Perform the following to fix:

Open Active Directory Users and Computers, go to “View” and select “Advanced Features”
Find the affected user, double-click and go to “Security” then click "Advanced"
Click “Include inheritable permissions from this object’s parent” and click OK.
Try again.
LVL 22

Expert Comment

by:Nick Rhode
ID: 39587840
LVL 76

Assisted Solution

by:Alan Hardisty
Alan Hardisty earned 1000 total points
ID: 39587919
The problem is:

"I am a domain admin"

You are a member of a group that resets permissions needed for Activesync to work - so you can either create yourself a new User account, or remove the Domain Admin rights from your existing account and create yourself a new Domain Admin account.

My article tells you more about this:


LVL 76

Expert Comment

by:Alan Hardisty
ID: 39588041
The accepted solution doesn't solve the problem permanently.  After an hour, the problem will reappear because you will still be a domain admin and the SDPROP process will strip the inherited permissions from the account again.


Featured Post

Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

In my humble opinion (IMHO), TouchDown from Symantec is the best in class for this type of application, but Symantec has end-of-lifed it and although one can keep using it, it will no longer be supported or upgraded.  Time to look for alternatives t…
After a recent Outlook migration from a 2007 to 2010 environment, some issues with Distribution List owners were realized. In this article, I explain how that was rectified.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…

597 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question