trying to connect to exchange using iPhone - Activesync.

I get the below error when trying to connect to exchange using my iPhone,
I am a domain admin so not sure what this error means,.

Exchange ActiveSync doesn't have sufficient permissions to create the "CN=xxx xxx,OU=Users,OU=xxx,DC=xxx,DC=local" container under Active Directory user "Active Directory operation failed on DC.xxx.local. This error is not retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-03152492, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
".
Make sure the user has inherited permission granted to domain\Exchange Servers to allow List, Create child, Delete child of object type "msExchActiveSyncDevices" and doesn't have any deny permissions that block such operations.
LVL 1
wannabecraigAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

ChrisCommented:
This is a fairly common issue usually seen after upgrading exchange.

Perform the following to fix:

Open Active Directory Users and Computers, go to “View” and select “Advanced Features”
Find the affected user, double-click and go to “Security” then click "Advanced"
Click “Include inheritable permissions from this object’s parent” and click OK.
Try again.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Nick RhodeIT DirectorCommented:
0
Alan HardistyCo-OwnerCommented:
The problem is:

"I am a domain admin"

You are a member of a group that resets permissions needed for Activesync to work - so you can either create yourself a new User account, or remove the Domain Admin rights from your existing account and create yourself a new Domain Admin account.

My article tells you more about this:

http://www.experts-exchange.com/Software/Server_Software/Email_Servers/Exchange/A_2861-Activesync-Working-But-Only-For-Some-Users-On-Exchange-2007-2010.html

Alan
0
Alan HardistyCo-OwnerCommented:
The accepted solution doesn't solve the problem permanently.  After an hour, the problem will reappear because you will still be a domain admin and the SDPROP process will strip the inherited permissions from the account again.

Alan
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Exchange

From novice to tech pro — start learning today.