Comments on: Creating ActiveSync Device Access Rules in Exchange Server 2010 https://practical365.com/creating-activesync-device-access-rules-exchange-server-2010/ Practical Office 365 News, Tips, and Tutorials Wed, 08 Apr 2020 17:35:19 +0000 hourly 1 https://wordpress.org/?v=6.6.1 By: Manas Dash https://practical365.com/creating-activesync-device-access-rules-exchange-server-2010/#comment-229143 Wed, 08 Apr 2020 17:35:19 +0000 https://www.practical365.com/?p=4969#comment-229143 In reply to Paul Cunningham.

But how to distinguish device ID for same model and same branded mobile ?

It will be same for both person if they work in a company with using generic email id and same department.

For Example :
Samsung Galaxy J2 SM-J200G

]]>
By: <div class="apbct-real-user-wrapper"> <div class="apbct-real-user-author-name">Paul Cunningham</div> <div class="apbct-real-user-badge" onmouseover=" let popup = document.getElementById('apbct_trp_comment_id_42758'); popup.style.display = 'inline-flex'; "> <div class="apbct-real-user-popup" id="apbct_trp_comment_id_42758"> <div class="apbct-real-user-title"> <p class="apbct-real-user-popup-header">The Real Person!</p> <p class="apbct-real-user-popup-text">Author <b>Paul Cunningham</b> acts as a real person and passed all tests against spambots. Anti-Spam by CleanTalk.</p> </div> </div> </div> </div> https://practical365.com/creating-activesync-device-access-rules-exchange-server-2010/#comment-42758 Thu, 16 Feb 2017 00:35:23 +0000 https://www.practical365.com/?p=4969#comment-42758 In reply to Sean.

Not possible, unfortunately. You can use the different policies to apply different device requirements like PIN/passcode strength etc, but the device access rules apply to the entire organization regardless of which policy is applied.

If you want to get down to more granular policy stuff like that you’ll need an MDM solution like Intune, MobileIron, Airwatch etc.

]]>
By: Sean https://practical365.com/creating-activesync-device-access-rules-exchange-server-2010/#comment-42270 Wed, 15 Feb 2017 13:20:59 +0000 https://www.practical365.com/?p=4969#comment-42270 Hi guys! Paul, as always – GREAT post… again!

But I need some help please! We have 4 ActiveSync Policies configured in Exchange 2010. I have no problem creating the access rules etc, but how can I create the access rule to apply ONLY to one specific Ativesync Poliy?

]]>
By: Paul Cunningham https://practical365.com/creating-activesync-device-access-rules-exchange-server-2010/#comment-13246 Tue, 24 May 2016 11:44:55 +0000 https://www.practical365.com/?p=4969#comment-13246 In reply to Chris Cundy.

No. Device access rules apply to everyone. Except for when the device ID has been added to a mailboxes list of allowed device IDs, because that will mean the device is allowed no matter what device access rules exist.

]]>
By: Chris Cundy https://practical365.com/creating-activesync-device-access-rules-exchange-server-2010/#comment-13245 Tue, 24 May 2016 11:26:49 +0000 https://www.practical365.com/?p=4969#comment-13245 Is there any way to link an ActiveSync Device Policy to an ActiveSync Access Rule and make sure the access rule is only applied to one person for testing?

I have a testing device policy setup but I want to be able to test on different devices without affecting other users.

]]>
By: Mohamed Ali https://practical365.com/creating-activesync-device-access-rules-exchange-server-2010/#comment-13244 Thu, 07 Apr 2016 15:41:10 +0000 https://www.practical365.com/?p=4969#comment-13244 Hi Paul,

Is there any way to check when the device is allowed and who’s allowed (We have multiple admins)? My default org access level is quarantine. Thanks!

]]>
By: <div class="apbct-real-user-wrapper"> <div class="apbct-real-user-author-name">Paul Cunningham</div> <div class="apbct-real-user-badge" onmouseover=" let popup = document.getElementById('apbct_trp_comment_id_13243'); popup.style.display = 'inline-flex'; "> <div class="apbct-real-user-popup" id="apbct_trp_comment_id_13243"> <div class="apbct-real-user-title"> <p class="apbct-real-user-popup-header">The Real Person!</p> <p class="apbct-real-user-popup-text">Author <b>Paul Cunningham</b> acts as a real person and passed all tests against spambots. Anti-Spam by CleanTalk.</p> </div> </div> </div> </div> https://practical365.com/creating-activesync-device-access-rules-exchange-server-2010/#comment-13243 Wed, 30 Mar 2016 01:59:44 +0000 https://www.practical365.com/?p=4969#comment-13243 In reply to Mike.

Most customers I’ve worked with solve this by using an application-aware reverse proxy or load balancer, and excluding the /Microsoft-Server-ActiveSync virtual directory from general access.

]]>
By: Mike https://practical365.com/creating-activesync-device-access-rules-exchange-server-2010/#comment-13242 Tue, 29 Mar 2016 15:12:34 +0000 https://www.practical365.com/?p=4969#comment-13242 Paul, we use an MDM server that forwards all ActiveSync calls to the CAS. So direct ActiveSync traffic from device to the CAS is forbidden, only the MDM server should be able too. How could we prevent the direct calls? OWA uses the same URL, so no redirect possible. EAS needs to be turned on for the users as well. Is there a way to tell the Exchange to only accept calls from a certain IP? IIS restrictions maybe? Thank you

]]>
By: Rebecca Ferguson https://practical365.com/creating-activesync-device-access-rules-exchange-server-2010/#comment-13241 Wed, 23 Dec 2015 18:14:30 +0000 https://www.practical365.com/?p=4969#comment-13241 Nevermind! I found it in Exchange admin center>Mobile>mobile device accessmobile device mailbox policies. Thank you!

]]>
By: Rebecca Ferguson https://practical365.com/creating-activesync-device-access-rules-exchange-server-2010/#comment-13240 Wed, 23 Dec 2015 18:10:05 +0000 https://www.practical365.com/?p=4969#comment-13240 Hi Paul-

I accidentally made a device rule I did not mean to make. I cannot figure out how to delete it. Pls help

]]>