How to secure device using ActiveSync from Syncing with unauthorzied devices with same OS platform

Hi Experts

I've Google this question in different ways, but didn't find the answer I'm looking for, so I thought I would try here.

We are in the midst of discussions on ActiveSync usage, as whether to move away from strictly BBs and BES environment that we have now, which is working fine as is... but...  

We recently migrated to using Office 365 and I've got all our BBs now activated in the Blackberry Cloud Services that is integrated with Office 365.  We have users requesting BB10 devices(Q10/Z10), currently BBCS with Office 365 doesn't provide Enterprise Activation for BB10 devices. I have not been able to get any info as to if and when RIM plans to upgrade their BBCS to BES10 platform. So if we let Users get BB10 devices we have to Use ActiveSync protocol, and with that, Users are asking if we'd consider another platform such as IPhone or Android.

Question that came out of that is if a Users has a Corporate Authorized IPhone for Example: also owns a Personal IPad(popular).  Are we able to prevent them from Syncing the two iOS devices?  If I understand correctly, if they are fully Synced the email from the authorized phone can find it way over to the Unauthorized personal IPad if the User was to enable Syncing of devices, am I correct in that assumption? and if Yes, this is possible with iOS and perhaps even Android devices? Is there a way for us to prevent Syncing of Devices in that way, via ActiveSync policies or on the Phone itself?

Thank you
Note: I'm on Atlantic Canada time
CATHY-ITAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Jamie McKillopIT DirectorCommented:
Hello,

The Exchange mail account will not sync between the devices. Only the iCloud me.com address will sync between devices. If you have device quarantine tuned on in your Exchange environment, you can control which devices are allowed to sync with your Exchange server. Unless the user starts forwarding all their email to an outside address, the mail will not end up on any other iOS devices.

-JJ

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
CATHY-ITAuthor Commented:
Yes, I do have quarantine turned on to allow me to approve devices. Thanks for confirming our question.

Just a quick opinion, do you consider ActiveSync a secure alternative to use instead of BES? Or should I be pushing to stay with BES and wait for RIM to upgrade the Blackberry Business Cloud Services to BB10 version to allow BES connection with BB10 OS devices.
Jamie McKillopIT DirectorCommented:
In my opinion, BES security is over hyped. We are really looking at two distinct security components. The fist is the data flow between the server and the device. BES is more secure with its 256bit encryption but we rely on the 128bit encryption ActiveSync uses for everything else on the internet. If you are allowing your users to use webmail, the security level is the same as ActiveSync. The other component is the device itself. Again, Blackberry has better device security than competing devices but it isn't a trivial process to get data off Andriod or iOS devices that have a proper passcode. The reality is that unless you operate in an ultra high security environment, such as the defense industry, your data isn't likely going to be worth the cost and effort to crack into the data stream or the device itself.

-JJ
CATHY-ITAuthor Commented:
That's the general notion I had, but definitely different opinions out there about it.  Though I do like that the BES can Push other Policy that ActiveSync just doesn't have.

Thanks Again
CATHY-ITAuthor Commented:
Thanks again
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Email Clients

From novice to tech pro — start learning today.