Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Disable ActiveSync

Posted on 2014-10-21
Last Modified: 2014-11-05
I trying to device a way to disable ActiveSync for all users who aren't members of the ActiveSync Allowed Security group.  I can run the below to enable disable it based on group membership but how can I disbale everyone except for those who are members of this secuirty group?

$activesync=Get-ADGroupMember "ActiveSync Allowed" -Recursive | Get-ADUser -Properties mail
foreach($member in $activesync){set-CASMailbox -Identity $member.Name -ActiveSyncEnabled $false -ErrorAction SilentContine -WarningAction SilentlyContinue

Is there anyway to disable activesync as a default for any newly created users.  I know there use to be a way to accomplish this in previous versions of exchange if I'm not mistaken but doesn't see possible in Exchange 2010.
Question by:georgedschneider
  • 3
  • 2
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40395785
There has never been a way to disable ActiveSync by default. It has always required disabling afterwards.

To answer your specific question, the best way is to disable everyone, then enable those that need access. Do it out of hours so if the change is cached it has limited impact.

Alas for new users you will need to disable them manually or start using scripts to create users instead, where the service can be disabled as part of provisioning.

As a further safeguard, setup ActiveSync device policies. Quarantine or block every connection attempt until you allow it. Loads of scripts around which will approve everything that is already connected.
You could then write a script to approve devices belonging to members of the group and run it at regular intervals.


Author Comment

ID: 40396809
Is there not a way to write the script where if user is not a member of group ActiveSync Allowed then disbale?
LVL 63

Accepted Solution

Simon Butler (Sembee) earned 500 total points
ID: 40397610

Author Comment

ID: 40398306
If activesync is disabled then reenabled minutes after what will the end user expirence on their device?  Will mailflow just stop or will  they see a popup.  Will they lose their setup?
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40401791
It can take some hours for ActiveSync being disabled to actually take effect, because of the way ActiveSync works. The only way to force it is to restart IIS.
Therefore if you disable it and then enable it, then nothing should happen on the clients. If a client does happen to connect in that window, then nothing will happen on the device.


Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The following article is intended as a guide to using PowerShell as a more versatile and reliable form of application detection in SCCM.
The Nano Server Image Builder helps you create a custom Nano Server image and bootable USB media with the aid of a graphical interface. Based on the inputs you provide, it generates images for deployment and creates reusable PowerShell scripts that …
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…
how to add IIS SMTP to handle application/Scanner relays into office 365.

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question