Exchange ActiveSync error 85010001 - "Your account in microsoft exchange server does not have permission to synchronize with your current settings. Contact your Exchange Server administrator"



I've had this issue with a Treo 700w for several days, and have tried
many suggested methods to resolve. These included:

- Setting a new exchange-oma virtual directory for syncing
- Enabling / Disabling form based authentication
- Verifying OMA was working correctly
- Trying with / without SSL (enabling / disabling ssl as an option for
/exchange virtual directory)

All of the suggested resolutions in many of the forums had limited
success with many of the posters / forum participants. I wanted to
get it out to everyone just how I managed to get this working, to
hopefully save them some time and headaches. NONE of the suggested
methodologies that were found from search engine results fixed the
issue.

Finally, after trying countless suggestions from other Exchange
administrators found via google and other search engine searches, I
did a comparison with another Exchange organization, directory for
directory, in the IIS Admin. What I found was interesting....

The "Microsoft-Server-ActiveSync" virtual directory had different
permissions set on one server (the one that worked) vs. another (the
one that has been problematic).

What I found was that on the "Directory Security" tab, under
"Authentication and Access control", "INTEGRATED WINDOWS
AUTHENTICATION" was checked on the system that was NOT working, but
was NOT CHECKED on the system that WAS working.

I unchecked the option on the problematic server, tried a resync from
the mobile device, and EVERYTHING WORKED PERFECTLY. It's amazing to
me that a small checkbox with such a seemingly innocuous affect could
cause me so many issues over the past few days, so again, I HOP THAT
THIS SAVES SOMEONE SOME TIME AND HEADACHE.

In summary: Exchange ActiveSync error 85010001 - "Your account in
microsoft exchange server does not have permission to synchronize with
your current settings. Contact your Exchange Server administrator" was
resolved by UNCHECKING "Integrated Windows authentication" in the
"Authenication and access control" option of the "Directory Security"
tab of the "Microsoft-Server-ActiveSync" virtual directory, as
accessed through the ISM.

.



Relevant Pages

  • Re: Exchange OMA issue
    ... provide Outlook Web Access, Exchange ActiveSync, and Outlook Mobile Access ... For Exchange-oma virtual directory and the virtual directory you created ... Open IIS Manager ... Select Edit in Authentication and access control box. ...
    (microsoft.public.windows.server.sbs)
  • Re: Mobile Access to Exchange
    ... Exchange mailbox by ActiveSync with error 0x85010004. ... authentication is not enabled on the Exchange virtual directory. ... Open IIS Manager ...
    (microsoft.public.windows.server.sbs)
  • RE: "blank email" issue using Activesync?
    ... The Exchange Server drive M:. ... 328841 Exchange and Antivirus Software ... Step 3:Please verify Authentication settings by the following steps. ... Open properties of virtual directory Exchange/Exchange-oma ...
    (microsoft.public.windows.server.sbs)
  • Re: Mobile Access to Exchange
    ... The Device Security Settings were enabled in the Exchange Manager> Global ... authentication is not enabled on the Exchange virtual directory. ... Open IIS Manager ...
    (microsoft.public.windows.server.sbs)
  • RE: SBS2003, Exchange 2003 & Mobile ActiveSync
    ... Exchange/Exchange-OMA virtual directory. ... Open IIS Manager ... Note:If you need to use SSL on the Exchange virtual directory, ... forms-based authentication is required for Exchange Server 2003 ...
    (microsoft.public.windows.server.sbs)