amset.info
from Sembee Ltd.
UK MS Exchange Consultants

Exchange - Net Admin - Outlook
Windows Mobile - Windows

Contact - Director's Blog

AddThis Social Bookmark Button


Exchange Server Home

Exchange Consultancy

Exchange Resources


Microsoft Exchange
Amazon Store


Basic Email Gateway Server

Company wide Contact List

Disabled User Account

Distribution Lists

DNS Configuration

Exchange and a
Dynamic IP Address

Event ID 1221

Filter Unknown Users

Global Mailbox Folder
Permissions from Server

Intelligent Message Filter

Internal Email Address
for External People

Mailbox and Management
Account

Message Tracking

Migrating to a new server

Multiple Domains

Offline Address Book Errors

Options when a Staff Member
Leaves

Outlook Web Access

PDAs, OMA and EAS

Permissions Best Practises

Post Install Configuration

Public Folders

Prerequisites for Exchange
System Tools

RPC over HTTPS

Secure your SMTP Relay

Shutdown Script

SMTP Services and Exchange

SMTP Diagnostics

Spam Cleanup

Switching From POP3
to SMTP Delivery

Telnet Test

Username Change

Microsoft Exchange Server
Page Last Reviewed: 20/02/2010

Exchange Server
Compatibility Information
Exchange
Server Version
Compatibility
5.5 No
2000 No
2003 Yes
2007 Yes
Exchange ActiveSync / OMA Troubleshooting

Author: Simon Butler, Exchange MVP, MCSE

Working with a Mobile Device Section Home Page

When Exchange ActiveSync (EAS) isn't working correctly, it can be a pain to troubleshoot as all you get are cryptic error codes.

The quickest way to troubleshoot EAS is to check whether Outlook Mobile Access (OMA) is working correctly. They share the same infrastructure and often if one isn't working then the other will fail as well.

You can do the initial troubleshooting on OMA with a standard web browser. Turn off "Friendly http error messages" first, so that you can see the true error.
Then browse to http://servername/oma and login using the credentials in the format of domain\username and the password.
You should get a folder list in a plain text format. If you get anything else, then it isn't working properly.
If you are using SSL, then you will need to browse to the SSL URL.

Major things to check...

Incompatibilities

The ActiveSync push only works over a mobile phone connection, so if you are trying to see the feature work over a wireless or wired network connection, you will not. Regular initiated sync should work over the wireless connection though.

Windows Mobile is not compatible with wildcard SSL certificates, so if you have one of those you will need to change it for a named host certificate.

Certificate Prompts

Browse to https://servername.example.com/oma where servername.example.com is the name on the certificate.

If you get a certificate prompt, then that will  cause EAS to fail, as it cannot handle the certificate prompt. Ideally you should be deploying this feature with a purchased certificate, but if you do need to use a certificate that isn't trusted by one of the built in root certificates, or need to import your own root certificate, then the certificate will need to be installed on to the device - see our instructions elsewhere on this site.

SSL and Forms Based Authentication - Exchange 2003 Only

Having SSL and Forms Based Authentication enabled can trigger the 85010014 sync errors. This is easily fixed, and is discussed here.

Authentication Settings - Exchange 2003 Only

The authentication settings on the virtual directories have caught some people out.

Again these are set in IIS Manager. On each virtual directory, click on Directory Security and then Edit under "Authentication and Access Control".

/exchange: Basic ONLY. Optional: set a default domain and a default realm*
/exchweb: Anonymous ONLY.
/exadmin: Integrated ONLY.
/OMA: Basic ONLY. Optional: set a default domain and a default realm*
/Microsoft-Server-ActiveSync: Basic ONLY. Optional: set a default domain and a default realm*

* If you are using SSL, then setting the default domain and default realm has no effect on your users requirement to enter the domain name as part of their username (domain\username). You must enable forms based authentication and Exchange 2003 Service Pack 2 or higher, which has an undocumented change that defaults to not requiring the domain\ - despite what the web page says.

Authentication Settings - Exchange 2007

If you suspect that the authentication settings are not correct on Exchange 2007, then simply recreate the virtual directory.

First, delete the existing directory using the Exchange Management Console (where EXCH01 is the name of the server).

If you aren't sure of the identity of the ActiveSync directory, as the command must be exact, then use the following command to show how Exchange sees the virtual directory:

Then create a new one:

Application Pools - Exchange 2003 Only

If the application pools aren't set correctly, then the web application doesn't run. Also in IIS Manager.

/exchange - ExchangeApplicationPool*
/exchweb - ExchangeApplicationPool*
/exadmin - ExchangeApplicationPool*
/public  - ExchangeApplicationPool*
/oma - ExchangeMobileBrowseApplicationPool
/Microsoft-Server-ActiveSync - ExchangeApplicationPool

* will probably show ExchangeApplicationPool but greyed out.

External Sites

Error Codes List: http://www.pocketpcfaq.com/faqs/activesync/exchange_errors.php

Microsoft Test Site: https://testexchangeconnectivity.com

 

Last Page Update:
20/02/2010
More Content from Sembee Ltd.
 
Resources on amset.info Other Sites Sembee Ltd.
Microsoft Exchange Command Prompt Getting Started Guide Microsoft Exchange Consultancy
Microsoft Outlook Login Scripts Director's Blog
Network Administration MS Exchange Resources  
Internet Explorer Knowledge Base search  
Microsoft Windows Recovery of MS Office content from Temp Files  
Microsoft Windows Mobile Troubleshoot the Automatic Updates Client  
Amazon Store UK ISP Status Pages  

© Sembee Ltd. 1998 - 2010.

Reproduction of any content on this web site is prohibited without express written consent. Use of this web site is subject to our terms and conditions. All trademarks and registered trademarks are property of their respective owners. This site is not endorsed or recommended by any company or organisation mentioned on this site. This site is to provide guidance only and as such we cannot be held responsible for any consequences of following the advice given.