[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now


newly installed server2012 with exchange2013 - no mobile connect for user with domain-admin rights - all other users can connect

Posted on 2014-08-21
Medium Priority
Last Modified: 2014-12-04

we just installed a new Exchange 2013 on server 2012. Now we tried to connect some mobiles. For all users this worked fine. But only one user that is member of domainadmins-group cant connect. It was tested with iphone and android.
You can setup the account on the mobiles and it tells that everything is fine. But after completing all settings, the inbox says
"cant connect to server" (on iphone) and syncs without end and without error on android.

I deleted for testing the membership of damainadmins. This didn´t help.
OWA works for this user too. Only Mobiles can´t connect. Same mobiles can connect if i change the username of the account to another user.

Thanks for ideas or solutions

Question by:loosain
  • 2
LVL 19

Assisted Solution

by:Adam Farage
Adam Farage earned 1000 total points
ID: 40278033
Thats not it.

When a member is apart of the domain admins group, ActiveSync will not work due to permission changes on the AD user object but also because it is a restricted account. Make sure inheritable permissions are set on the AD user object, and then retest: http://blog.nick.mackechnie.co.nz/post/2009/11/20/Exchange-2010-Active-Sync-Issue.aspx

The main thing in the article is that "Include inheritable permissions from this object's parent" is set. without this, the Exchange Servers "special" permissions group will not be applied. By default, since the domain admins group is a restricted group this is unchecked.
LVL 19

Accepted Solution

R--R earned 1000 total points
ID: 40278249
Please check this from http://technet.microsoft.com


If the user is a member of certain protected groups such as Domain Administrators, it is normal for this box to be unchecked. If you are experiencing a problem with members of these protected groups you should check the permissions on the AdminSDHolder object.

Note: We recommend that you do not use accounts that are members of protected groups for e-mail purposes. If you require the rights that are afforded to a protected group, we recommend that you have two Active Directory user accounts. These Active Directory accounts include one user account that is added to a protected group and one user account that is used for e-mail purposes and at all other times.

Author Comment

ID: 40310565
i took the adminrights away from the customer, but nothing happend. how long does it take to take effect ? Or does it mean that one account had adminrights, it never gets mails on mobiles, even if this account is taken away from admingroups?

Author Closing Comment

ID: 40481501
After some time - it works - don´t ask why...

Featured Post

Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Are you looking for the options available for exporting EDB files to PST? You may be confused as they are different in different Exchange versions. Here, I will discuss some options available.
This article will help to fix the below errors for MS Exchange Server 2016 I. Certificate error "name on the security certificate is invalid or does not match the name of the site" II. Out of Office not working III. Make Internal URLs and Externa…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
Suggested Courses

873 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question