iPhone 5C Unable to Verify Information when adding exchange 2010 Account

Posted on 2014-01-07
Last Modified: 2014-01-13
Environment Exchange 2010 - I am Domain Admin, used iPhone 4S on ios 6 for 18 months using EAS with no problems.  Recently got iPhone 5C ios 7 for testing purposes and getting the  "Unable to Verify Account Information.

To add the account I have tried using "mobile data" and "Wireless Routers" in both my home and business environment.

My AD account is not locked out.

I have selected the security tab and reconfirmed inherit permissions which was the step required post upgrade from exchange 2003 to 2010 two years ago.  Even though other members of the team do not  have this box ticked and they are able to set up their exchange on this same device.

I have also tried it with it matching a user who can add their account with the inherit box unticked.

I have wiped phone and re set up as brand new handset.

I have migrated my mailbox to a different mailbox database on a different siteand attempted to re add.

I have added the account saved then turned off use SSL at this point i am continually prompted for exchange account password.  It does not accept my exchange password for this.

I have tried using OWA on the handset and it contimually asks for password again this feature has always operated fine.

I believe their is a deeper issue with my AD profile but i would not know where to start.

This has worked for other users and other domain admins so the problem is not the handset.

Anybody had this before? Any solutions?

Can anybody make any suggestions as to if my AD profile could become corrupt in a manner that would affect my authentication like this.  ?
Question by:FMabey
  • 4
  • 3

Expert Comment

ID: 39762634
Have you verified that the device is authorized to access Exchange?  
Check out the article below for more information on that:

If a device is not authorized, you can get the Unable to Verify Account Information message that you stated.
LVL 76

Expert Comment

by:Alan Hardisty
ID: 39762639
You shouldn't run an Activesync mobile whilst being a domain Admin - whilst it can work, it won't allow you to add new devices because of security permissions.

Please have a read of my article for details:

You could re-add the Inherited permissions on your account and quickly add the iPhone, but the inherited permissions will be removed hourly afterwards, so this is why MS recommend one account for Admins and one account for users and the Admins shouldn't use Mobile Accounts on those Admin accounts.


Author Comment

ID: 39764561
From that post it looks like i need to allow this particiular handset to connect, my colleague who has exactly the same permissions has set up his account on the very handset that does not allow me to connect and it works.

He puts in his credentials all the ticks, delete his account and add my credentials and unable to verify.

I believe what you are saying but i find this difficult to comprehend as I was working fine on an iphone 4s for 18 months then mid december i started testing this iphone 5c, there has been no change to how i interact with the network.  I am the only person experiencing this problem in a  department of domain admins.  Its my personal network account (that has admin priviliges) not the administrator account that we complete the bulk of the administration with.

does the information here change any of the suggestions diagnosis?
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

LVL 76

Expert Comment

by:Alan Hardisty
ID: 39764570
Can you add your colleagues account to your phone happily?  If you can, that rules out a problem with the handset.

Check your inherited permissions - they are probably unchecked.  If you tick the box, then add the account to your phone, it should hopefully add happily.

Once the sdprop process runs again, the inherited permissions will be removed and at that point, adding new accounts will be a problem again.


Author Comment

ID: 39764638
Colleague account is fine on the very same handset.

I have unticked the inherit apply ok and have just tried it 10 times, i then replicated sites and services just as a precaution proibably not necessary and treid again but nothing.

We tried adding my account to his company phone and it wouldnt work also tried adding it to an iphone 4s on ios 6 that wouldnt work so it is my individual account.  I just dont see anyway around it if everybody is working fine including using my devices.

where do we go from here?

Accepted Solution

FMabey earned 0 total points
ID: 39764706
SOLUTION:   Several weeks back myself and a collleague were just running some test on the Account Tab of Active Directory. If you select Log On To and specify your machine for the purpose of ensuring a particular user can only use a specified machine.   As we just discovered it also stops the use of mobile phones.....who knew that!

So removed my machine then select allow "allow log on to all computers"  

issue resolved...

Thanks for everybodies input into this, maybe this will come in handy for someone else in the future.
LVL 76

Expert Comment

by:Alan Hardisty
ID: 39764730
That makes perfect sense - but never seen that before cause problems with Activesync, but one for the memory bank!


Author Closing Comment

ID: 39776046
Self diagnosis

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains in simple steps how to renew expiring Exchange Server Internal Transport Certificate.
This article runs through the process of deploying a single EXE application selectively to a group of user.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
how to add IIS SMTP to handle application/Scanner relays into office 365.

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now