How to block exchange active synce on personal cell phones

Posted on 2015-01-21
Last Modified: 2015-04-20
  How you do block users from using Exchange Active Sync to access e-mail on their personal cell phones but allow company owned devices to access do it?
Question by:masterofall
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 76

Accepted Solution

Alan Hardisty earned 250 total points
ID: 40562685
You can achieve this using the built-in Allow/Block/Quarantine option:

When a device attempts to gain access it can be quarantined until approved or denied, thus you get the ability to block and allow the devices you want.

You may have to remove all Activesync devices after setting this up so that everyone has to go through the ABQ process.


Assisted Solution

NICK S earned 250 total points
ID: 40563236
Allow block quarantine is best option , but most simple method would be to enable active sync using below command

Set-CASMailbox -Identity: "username" -ActiveSyncAllowedDeviceIDs: "<DeviceID_1>"

this will allow only device which is in allow list , you can also add multiple device IDs if you want

Expert Comment

by:Minecraft_ Enderman
ID: 40563806
1. Retrieve the device ID after the user has synchronized the device with the Exchange server.

Get-ActiveSyncDeviceStatistics -Mailbox:"<EmailAlias>" |fl DeviceID

2. Prevent that device from synchronizing with Microsoft Exchange.

Set-CASMailbox -Identity: "EmailAlias"
-ActiveSyncBlockedDeviceIDs: "<DeviceID_1>","<DeviceID_2>"

3. Enable a Device for Exchange ActiveSync

Set-CASMailbox -Identity: "EmailAlias" -ActiveSyncAllowedDeviceIDs: "<DeviceID_1>","<DeviceID_2>"

Author Closing Comment

ID: 40733210

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
As tax season makes its return, so does the increase in cyber crime and tax refund phishing that comes with it
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question