Solved

Disable ActiveSync

Posted on 2014-10-21
5
112 Views
Last Modified: 2014-11-05
I trying to device a way to disable ActiveSync for all users who aren't members of the ActiveSync Allowed Security group.  I can run the below to enable disable it based on group membership but how can I disbale everyone except for those who are members of this secuirty group?


$activesync=Get-ADGroupMember "ActiveSync Allowed" -Recursive | Get-ADUser -Properties mail
foreach($member in $activesync){set-CASMailbox -Identity $member.Name -ActiveSyncEnabled $false -ErrorAction SilentContine -WarningAction SilentlyContinue


Is there anyway to disable activesync as a default for any newly created users.  I know there use to be a way to accomplish this in previous versions of exchange if I'm not mistaken but doesn't see possible in Exchange 2010.
0
Comment
Question by:georgedschneider
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40395785
There has never been a way to disable ActiveSync by default. It has always required disabling afterwards.

To answer your specific question, the best way is to disable everyone, then enable those that need access. Do it out of hours so if the change is cached it has limited impact.

Alas for new users you will need to disable them manually or start using scripts to create users instead, where the service can be disabled as part of provisioning.

As a further safeguard, setup ActiveSync device policies. Quarantine or block every connection attempt until you allow it. Loads of scripts around which will approve everything that is already connected.
You could then write a script to approve devices belonging to members of the group and run it at regular intervals.

Simon.
0
 

Author Comment

by:georgedschneider
ID: 40396809
Is there not a way to write the script where if user is not a member of group ActiveSync Allowed then disbale?
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 40397610
0
 

Author Comment

by:georgedschneider
ID: 40398306
If activesync is disabled then reenabled minutes after what will the end user expirence on their device?  Will mailflow just stop or will  they see a popup.  Will they lose their setup?
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40401791
It can take some hours for ActiveSync being disabled to actually take effect, because of the way ActiveSync works. The only way to force it is to restart IIS.
Therefore if you disable it and then enable it, then nothing should happen on the clients. If a client does happen to connect in that window, then nothing will happen on the device.

Simon.
0

Featured Post

PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
A recent project that involved parsing Tableau Desktop and Server log files to extract reusable user queries for use in other systems. I chose to use PowerShell to gather the data, and SharePoint to present it...
In this video we show how to create a Distribution Group in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >>…
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question