SBS2003 – ActiveSync Fun


I’ve had the same problem with Small Business Server 2003 and ActiveSync a few times now. Users get one of these new fangled phones, I go to set them up only to find it won’t quite work.

Exchange Connectivity Tester should be your first port of call. It runs through step by step to show you where it is failing. 9/10 times it is either a security certificate issue or….

FolderSync command test failed
Exchange Returned an HTTP 500 response

There are if you aren’t able to see any obvious problems I would recommend you save yourself some time and reset the IIS exchange virtual directories and then create a new one for Outlook Mobile Access. Its actually quite quick and simple although It does mean that no one can access OWA while you are doing it however  it shouldn’t take more than 15 minutes if you read through first. The following are two sections taken from Microsoft knowledge base articles.

Reseting the default virtual directories

 http://support.microsoft.com/kb/883380

  1. Back up your IIS Metabase. To do this, follow these steps:
    1. Start IIS Manager.
    2. Right-click Default Web Site, point to All Tasks, and then click Save Configuration to a File.
  2. Delete the virtual directories for Outlook Web Access. To do this, right-click Exadmin in the left pane of IIS Manager, and then click Delete. Click Yeswhen you are prompted with the question of whether you want to delete this item.Repeat this step for the following virtual directories:Quit IIS Manager.
    • Exchange
    • ExchWeb
    • Microsoft-Server-ActiveSync
    • OMA
    • Public
  3. Click Start, click Run, type cmd, and then press ENTER.
  4. Change to the following folder. In this example, Driveis the hard disk drive where Windows is installed:
    Drive:\inetpub\adminscripts
  5. Type adsutil, and then press ENTER. Important By default, CScript is not the default scripting host for Windows Server 2003. To run the adsutil command, CScript must be configured as the default scripting host. To do this, click Yes if you are prompted to register CScript as you default host for VBscript, and then click OK.Note If you receive a list of adsutil command options, CScript is already configured as the default scripting host for VBscript.
  6. Type adsutil delete ds2mb, and then press ENTER. Note To set the default scripting host to WScript, type WScript //H:WScript at the command prompt, press ENTER, and then click OK.
  7. Click Start, point to All Programs, point to Administrative Tools, and then click Services.
  8. To restart the Microsoft Exchange System Attendant service, follow these steps:
    1. Click Start, click Run, type services.msc, and then click OK.
    2. Right-click Microsoft Exchange System Attendant, and then click Restart.
    3. When you are prompted to restart the dependant Exchange Server services, click Yes.NoteWhen you restart the Microsoft Exchange System Attendant service, the Microsoft Exchange Information Store service is also restarted. In this scenario, your Exchange Server users lose connectivity to their Exchange Server mailboxes.The virtual directories are re-created. To verify that the virtual directories are re-created, start IIS Manager, and then view the Default Web site folder.Important If the virtual directories are not re-created after 15 minutes, restart the computer.
  9. Reset the access permissions to Anonymous. To do this, follow these steps:
    1. Start IIS Manager, right-click ExchWeb, click Properties, and then click the Directory Security tab.
    2. Under Authentication and access control click Edit, and then verify that the Enable anonymous access check box is turned on.
    3. Click to select the Integrated Windows authentication check box, click OK, and then click Apply.
    4. If an Inheritance Overrides dialog box appears, click Select All, and then click OK.
    5. Under Authentication and access control, click Edit, and then click to clear the Integrated Windows authentication check box.
    6. Click OK two times, and then quit IIS Manager.

Creating a new OMA Virtual Directory

Copy Pasted from http://support.microsoft.com/?kbid=817379

Disable the forms-based authentication for the Exchange virtual directory

// To create a secondary virtual directory for Exchange that is based on steps 1 through 7 of the following procedure, make sure that forms-based authentication is disabled for the Exchange virtual directory before you make the copy. Before you follow these steps, disable forms-based authentication in Exchange System Manager. Then restart Internet Information Services (IIS). To do this, follow these steps:

  1. Open Exchange Manager.
  2. Expand Administrative Groups, expand the first administrative group, and then expand Servers.
  3. Expand the server container for the Exchange Server 2003 server that you will be configuring, expand Protocols, and then expand HTTP.
  4. Under the HTTP container, right-click the Exchange Virtual Server container, and then click Properties.
  5. Click the Settings tab, clear the Enable Forms Based Authentication check box, and then click OK.
  6. Close Exchange Manager.
  7. Click Start, click Run, type IISRESET /NOFORCE, and then press ENTER to restart Internet Information Services (IIS).

Create a secondary virtual directory for Exchange server

// You must use Internet IIS Manager to create this virtual directory for Exchange ActiveSync and Outlook Mobile Access to work. If you are using Windows Server 2003, follow these steps:

  1. Start Internet Information Services (IIS) Manager.
  2. Locate the Exchange virtual directory. The default location is as follows:
    Web Sites\Default Web Site\Exchange
  3. Right-click the Exchange virtual directory, click All Tasks, and then click Save Configuration to a File.
  4. In the File name box, type a name. For example, type ExchangeVDir. Click OK.
    (If you are doing this on SBS2003 Backup then and Delete the Exchange-OMA virtual folder, you will find out why in a second)
  5. Right-click the root of this Web site. Typically, this is Default Web Site. Click New, and then click Virtual Directory (from file).
  6. In the Import Configuration dialog box, click Browse, locate the file that you created in step 4, click Open, and then click Read File.
  7. Under Select a configuration to import , click Exchange, and then click OK.A dialog box will appear that states that the “virtual directory already exists.”
  8. Select the Create a new virtual directory option. In the Alias box, type a name for the new virtual directory that you want Exchange ActiveSync and Outlook Mobile Access to use. For example, type exchange-oma. Click OK(It must be called exchange-oma on sbs2003)
  9. Right-click the new virtual directory. In this example, click exchange-oma. Click Properties.
  10. Click the Directory Security tab.
  11. Under Authentication and access control, click Edit.
  12. Make sure that only the following authentication methods are enabled, and then click OK:On the Directory Security tab, under IP address and domain name restrictions, click Edit.
    • Integrated Windows authentication
    • Basic authentication
  13. Click the option for Denied access, click Add, click Single computer and type the IP address of the server that you are configuring, and then click OK twice.
  14. Under Secure communications, click Edit. Make sure that Require secure channel (SSL) is not enabled, and then click OK.
  15. Click OK, and then close the IIS Manager.
  16. Click Start, click Run, type regedit, and then click OK.
  17. Locate the following registry subkey:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MasSync\Parameters
  18. Right-click Parameters, click to New, and then click String Value.
  19. Type ExchangeVDir, and then press ENTER. Right-click ExchangeVDir, and then click Modify.NoteExchangeVDir is case-sensitive. If you do not type ExchangeVDir exactly as it appears in this article, ActiveSync does not find the key when it locates the exchange-oma folder.
  20. In the Value data box, type the name of the new virtual directory that you created in step 8. For example, type /exchange-oma. Click OK.
  21. Quit Registry Editor.
  22. Restart the IIS Admin service. To do this, follow these steps:
    1. Click Start, click Run, type services.msc, and then click OK.
    2. In the list of services, right-click IIS Admin service, and then click Restart.
  23. If you want to reuse Forms-based Authentication on the Exchange server, follow these steps to re-enable Forms-based Authentication on the /Exchange virtual directory in Exchange System Manager.
    1. Open Exchange Manager.
    2. Expand Administrative Groups, expand the first administrative group, and then expand Servers.
    3. Expand the server container for the Exchange Server 2003 server that you will be configuring, expand Protocols, and then expand HTTP.
    4. Under the HTTP container, right-click the Exchange Virtual Server container, and then click Properties.
    5. Click the Settings tab, click to select the Enable Forms Based Authentication check box, and then click OK.
    6. Close Exchange Manager.
    7. Click Start, click Run, type IISRESET/NOFORCE, and then press ENTER to restart Internet Information Services (IIS).

Advertisements

5 comments

  1. Thanks · January 18, 2012

    My comment is that I like the way this looks like a book entry. 😀 thanks

  2. ask · April 27, 2015

    I have to thank you for the efforts you’ve
    put in penning this site. I really hope to view the
    same high-grade content by you later on as well. In fact, your creative writing abilities has encouraged me
    to get my own blog now 😉

  3. Cs 1.6 Pobierz · June 2

    Frequᥱϲia ddе teceptor orbisat demolay figuras s de
    аngеla bismarck linica reiѕ neto apostila de adobe audition 1.5 fabrica bom de
    vera foгtaleza ceara рacote viagem eua front page 98 free
    e books wicda gratis.

  4. Khawab Nama · June 5

    I am no longer sure where you are getting your information, but great topic.
    I must spend some time finding out more or understanding more.
    Thanks for magnificent info I was looking for
    this info for my mission.

  5. free google play cards · September 2

    A winning Cheque will be issued in your name by the Apple iphone 5S and
    Google Promotion Award Group, and also a certificate of prize claims will be sent alongside your winning Cheque.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s