Disable ActiveSync

Posted on 2014-10-21
Last Modified: 2014-11-05
I trying to device a way to disable ActiveSync for all users who aren't members of the ActiveSync Allowed Security group.  I can run the below to enable disable it based on group membership but how can I disbale everyone except for those who are members of this secuirty group?

$activesync=Get-ADGroupMember "ActiveSync Allowed" -Recursive | Get-ADUser -Properties mail
foreach($member in $activesync){set-CASMailbox -Identity $member.Name -ActiveSyncEnabled $false -ErrorAction SilentContine -WarningAction SilentlyContinue

Is there anyway to disable activesync as a default for any newly created users.  I know there use to be a way to accomplish this in previous versions of exchange if I'm not mistaken but doesn't see possible in Exchange 2010.
Question by:georgedschneider
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40395785
There has never been a way to disable ActiveSync by default. It has always required disabling afterwards.

To answer your specific question, the best way is to disable everyone, then enable those that need access. Do it out of hours so if the change is cached it has limited impact.

Alas for new users you will need to disable them manually or start using scripts to create users instead, where the service can be disabled as part of provisioning.

As a further safeguard, setup ActiveSync device policies. Quarantine or block every connection attempt until you allow it. Loads of scripts around which will approve everything that is already connected.
You could then write a script to approve devices belonging to members of the group and run it at regular intervals.


Author Comment

ID: 40396809
Is there not a way to write the script where if user is not a member of group ActiveSync Allowed then disbale?
LVL 63

Accepted Solution

Simon Butler (Sembee) earned 500 total points
ID: 40397610

Author Comment

ID: 40398306
If activesync is disabled then reenabled minutes after what will the end user expirence on their device?  Will mailflow just stop or will  they see a popup.  Will they lose their setup?
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40401791
It can take some hours for ActiveSync being disabled to actually take effect, because of the way ActiveSync works. The only way to force it is to restart IIS.
Therefore if you disable it and then enable it, then nothing should happen on the clients. If a client does happen to connect in that window, then nothing will happen on the device.


Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
A recent project that involved parsing Tableau Desktop and Server log files to extract reusable user queries for use in other systems. I chose to use PowerShell to gather the data, and SharePoint to present it...
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

687 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question