Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Exchange ActiveSync and PPC6700 problems: error 85010006

Status
Not open for further replies.

jer007

Technical User
Feb 16, 2004
94
0
0
CA
I just picked up a PPC6700 and am trying to get it to sync via exchange activesync. I'm running Exchange 2003 SP2 on a Windows 2000 Advanced Server SP4 machine. Everything looks like it is configured correctly however when I try to sync I get the following error on my PPC:

Your account in Microsoft Exchange Server does not have permission to synchronize with your current settings. Contact you Exchange Server administrator.

Support code: 0x85010006


My Exchange Server has exchange activesync enabled and in Active Directory it is enabled for my account. The only info I've been able to find on this problem is that it may be linked to IIS but I haven't found any solutions posted.

Thanks for any help you may be able to provide.

-Jeremy Neufeld
 
Can you try it with another account (username/pwd) like a test account or something?
 
Just tried a test account, I get the same error.
 
hmm.. did you copy over the root certificate from your mail server to the device and install it?
 
I copied the certificate off my desktop. Does it need to be the root certificate from the mail server? If so, how do i copy the certificate off the server?
 
I actually have two certs that I need to copy to my smartphone's and pocket pc's.

both were issued from my internal CA.

One is a cert that is issued to my excahnge/domain controller that ensures the identiy of my domain controller. And the other is a cert that ensures the name of the dns name that the ppc is try to connect to, exp, mail.mydomain.com

pretty sure i downloaded one of the certs via and the other via the CA doing a Start, Run, mmc, adding the certificate snap-in, and choosing computer account.

not sure though.. let me try and find my notes.
 
snootalope, just wondering have you found anything in your notes?
 
This is all I found:

"Created new Root cert and subordanate cert on Exchange server. One for the root server and one for mail.mydomain.com and copy BOTH to the pda and install… then connect to mail.mydomain.com and use ssl."

So, one ROOT cert for your Exchange server, and one cert for mail.yourdomain.com

Also, be sure your connecting to mail.yourdomain.com and not the external IP address of your router/firewall. The certificate MUST match the name you connected to!!
 
I don't have a subdomain for my mail. The address is just My DNS is pointing to my router/firewall and is using portforwarding to reach the exchange server. Could this be creating a problem?
 
Non the ppc I am trying to connect to domain.com. When accessing outlook web I go to
I don't have a subdomain of mail.domain.com set up. Don't know if it's nessesary or not.
 
no, not nessasary.

Right, from your pocket PC you'll want to connect to if that's the way you have it setup.

do you have your firewall/router set to forward all 443 requests to your exchange server?

If your ISP has the MX record for your domain setup to be mail.yourdomain.com, you'll want to connect to from PPC, but if you can get your OWA via the PPC shoud be the same.

SO... If I were you I'd download the root cert from your Exchange server. Just connect to your OWA in internet explorer, and double click the little padlock icon down in the lower right. You'll figure that out from there.. Put that cert on your PPC, as well as the cert from your CA, if you have one, that's for yourdomain.com

let'me know..
 
The domain name and port forward is setup correctly. I have also installed the certificates and nothing has changed.

I'm starting to get suspicious of IIS. My exchange 2003 server is running on Win 2000 advanced server. I'm contimplating upgrading to Win Svr 2003 and trying that. Do you think that by running on IIS 6 any change would be seen?

The other solution I was thinking of, but don't know how to accomplish is to use IIS on my existing Windows 2003 server. I'm just not sure if the exchange web data can be on a different server than the exchange server itself (let me know if this doesn't make sense)
 
hmm.. I'd guess you'd be complicating it even more by bringing in another box. Although, I wouldn't discourage you from upgrading to 2003 server SP1 if you had the chance. I don't know what your domain setup is and how many users you got, but I'd definitly do some serious research before upgrading OS's.

You could always setup a second exchange server on 2003 and test further if you think that's the case..

Try this, from the PPC, open the internet browser and goto - does that work?
 
on the ppc I get the following:

The page cannot be displayed

http 403.1 Forbidden: execute access forbidden
 
what if you try it from your computer on the same network as the Exchange server?
 
I get a login prompt. I enter my user name & pw and get the same 403.1 error
 
Open your IIS Admin, web sites, default web site, and right clicky your OMA virtual directory. On the Directory Security tab, hit Edit under Authentication and access control. Make sure anonymous access is UNCHECKED, along with Integrated.., Digest.., and .Net Passport. the ONLY thing that should be checked is basic authentication. on Default Domain, hit the select button and choose your domain. then ok your way out of there. try loging into again..
 
I get the same thing. Anonymous access was unchecked and Basic was the only thing that was. I hit edit by Basic Authentication and changed it from "\" to domain. After that I still get the 403.1 on the PPC and my PC
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top