ActiveSync devices causing accounts to lockout

Posted by Abdullah on Server Fault See other posts from Server Fault or by Abdullah
Published on 2012-03-17T06:43:39Z Indexed on 2012/03/18 18:01 UTC
Read the original article Hit count: 869

When a user changes his account password for whatever reason (read: expired), and the old password is stored in his mobile device connected through EAS. This will cause his account almost immediately - as it should according to the lockout policy defined in the AD. It was easy to figure out that part. The hard part is keeping it from happening. I looked everywhere. Nothing. Basically there are four parts to the puzzle: the EAS device, the TMG (ISA) server, the EAS protocol and finally the AD. None of them have a way to stop the EAS device from failing to authenticate. So I figured I'll have to come up with a clever workaround. And the only thing I could come up with is to create a group for all EAS users and exclude them from the lockout policy, which obviously defeats the whole purpose of the policy, or to educate the users to update their devices with the new passwords, which is impossible.

The question: Can you think of any other way to prevent EAS from locking out the accounts?

Environment: Mostly iOS devices all through EAS. TMG 2010. Exchange 2007. AD 2008 R2.

© Server Fault or respective owner

Related posts about active-directory

Related posts about exchange