Exchange 2010. 403 error. activesync not working for some users.

Member_2_8001432 used Ask the Experts™
Hello Experts

We have some mobile users that has trouble connecting to exchange via activesync.

When using exchange analyzer and activesync tester i get the error 403 from both of them, saying access denied.

I used to fix this problem by enabling inherit in AD. But now it doesn't work.

I have enabled "Basic authentication" on the IIS side for active-sync folder.

Active sync policies from exchange have "allow non-provisible devices" enabled.

I am suspecting it could be an AD issue, since this user had a working activesync previously. no membership or permissions has been changed.
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®


just to add, i just created a new account, and created a new mailbox. Activesync works.
Senior Engineer
Here are my notes on troubleshooting ActiveSync.  Do this for your troubled users.

ActiveSync Mailbox Logging

Open Exchange management shell on any Exchange server. Run cmd below,
Set-CASMailbox aliasofUser -ActiveSyncDebugLogging:$true
To retrieve logs.
Get-ActiveSyncDeviceStatistics -Mailbox alias -GetMailboxLog:$true -NotificationEmailAddress

Set-CASMailbox aliasofUser -ActiveSyncDebugLogging:$false


1)  Delete the email account from the device. (Remove the profile)
2)  Find out what ActiveSync devices are associated with a user’s mailbox:
            Get-ActiveSyncDevice -Mailbox "Redmond\TonySmith"
3)  Remove the device in question from ActiveSync:  
            Remove-ActiveSyncDevice -Identity iPhone_TonySmith -Confirm $true
4)  Enable ActiveSync logging for the user’s mailbox:
            Run the following command on the server where the user’s mailbox is located “Set-CASMailbox alias -ActiveSyncDebugLogging:$true”
5) Re-add the device
6) Allow syncing to commence and complete
7) Dump the captured log file to an email address:
            Get-ActiveSyncDeviceStatistics -Mailbox alias -GetMailboxLog:$true -NotificationEmailAddress


i think your debug comment helped me solve it. Testing it now.

i saw in the log this:
WARNING: You currently have 10 Exchange ActiveSync partnerships out of 10 maximum partnerships allowed per user. After
you reach the maximum, no new partnerships can be created until you remove some from your account.

I have removed some devices and waiting for them to remove the old devices. Gonna try again. You might just have given me the solution!

Gonna test it first :)
Ensure you’re charging the right price for your IT

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden using our free interactive tool and use it to determine the right price for your IT services. Start calculating Now!

Scott CSenior Engineer

Yes.  Too many partnerships will cause that.

That article is a great read.  I personally know the author and worked with him first-hand at MS.


Yep, max devices were reached. Thanks!
Scott CSenior Engineer

Glad I could help.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial