Jump to content

Recommended Posts

Posted

Hi, we are running Exchange 2003 (Ent) and have about 10 school owned devices which use ActiveSync on it to sync emails. This is fine and we are happy to continue with this but my question is how to prevent others from connecting their personal phones to the server? Is this possible?!

 

Would welcome any thoughts and suggestions.

 

Thanks

 

Si

Posted
In 2003 it is easy - just dont allow mobile messaging on the properties of users you don't want connecting (browse to the user in AD on the exchange box, right click, exchange tasks and disable mobile messaging.... something along those lines anyway - don't have a VM to hand!)
Posted
Thanks for your reply but i didn't word my q very well. Believe it or not there are some staff who have a school smartphone but still want the emails on their personal phone. Is it possible to do it on a per (authorised) device basis? Thanks.
Posted

Hi Si84,

I think I'm still missing something!

My previous post told you how you could enable or disable activesync for specific users. Have you tried it?

 

I'm curious why you want to prevent people connecting though...

If people were itching to connect i'd embrace it rather than look to flick it off.

Posted

As others have said I would be happy about the staff buyin and want to encourage it however if you have issues with it are they based on the security of staff devices. If so you can setup security requirements for the devices which require them to have a password on the device along with it being a certain complexity. This page shows you the setup Exchange 2003 Mobile Messaging Part 2 - Uncovering the Device Security Policies

 

If you still need to block other devices one method, which would be manual would be to install and use the Activesync Admin tool as shown here Exchange 2003 Mobile Messaging Part 3 – Installing, Administering, and Using the Microsoft Exchange Server ActiveSync Web Administration tool & http://www.microsoft.com/downloads/details.aspx?FamilyID=e6851d23-d145-4dbf-a2cc-e0b4c6301453&DisplayLang=en this would let you see what devices are connecting and also delete their partnerships forcing them to re-setup the link. You can also remote wipe devices from it so be careful as I am sure it would make for a very angry staff member if you wiped and bricked their personal phone :evil:.

 

The only other way I can think of is using a non-public SSL certificate and not giving it out to staff so that their deviced dropped out with an encryption error unless they were provided the correct cert or grabbed it off a school device.

 

Would be interested to hear what the issue is with it though if you are able to give out that information as that level of staff buyin would be welcomed here.

Posted
Would be interested to hear what the issue is with it though if you are able to give out that information as that level of staff buyin would be welcomed here.

 

It could be as simple as per device licensing not covering personal devices.

Posted
It could be as simple as per device licensing not covering personal devices.

 

That would make perfect sence and something that I had not considered :)

Posted

Hi all, thanks for the responses.

 

There are a couple of reasons for doing it


    it is against our school's AUP that personal devices are connected to the school's network


    if we say yes you can do it then we end up supporting their personal phones


    if they really need email on the go then the school provides them with a phone


    our data security policy requires phones to offer encryption and be able to be wiped remotely if lost or stolen to protect unauthorised access to emails which could potentially contain sensitive information. If a member of staff loses their personal phone we don't have the ability to do this

 

I completely agree that if staff are interested then they should be encouraged (my first reaction to requests is almost always 'yes we'll have a look and see if we can do that' and not 'no clear off!') but at the end of the day, the school pays for them to have email on a device and we are paid to maintain that device. They have to have their work phone on them so why do they really need it on a personal device too?

 

Again thanks for all your responses.

 

Si

Posted
Hi all, thanks for the responses.

 

There are a couple of reasons for doing it


    it is against our school's AUP that personal devices are connected to the school's network


    if we say yes you can do it then we end up supporting their personal phones


    if they really need email on the go then the school provides them with a phone


    our data security policy requires phones to offer encryption and be able to be wiped remotely if lost or stolen to protect unauthorised access to emails which could potentially contain sensitive information. If a member of staff loses their personal phone we don't have the ability to do this

 

I completely agree that if staff are interested then they should be encouraged (my first reaction to requests is almost always 'yes we'll have a look and see if we can do that' and not 'no clear off!') but at the end of the day, the school pays for them to have email on a device and we are paid to maintain that device. They have to have their work phone on them so why do they really need it on a personal device too?

 

Again thanks for all your responses.

 

Si

 

Just to pick up on a couple of points:

 

- Completely understand personal device mention in AUP, but should that extend to phones when all they can do is access controlled services via specific ports?

- Not much support needed once working. Other than setting up initially, I can hand on heart say I've never been given a support task for mobile devices picking up email.

- Why take a chunk of money out of a dwindling budget if staff already have a decide which they are willing to use (normally also using their own data allowence!)

 

- Very valid point, and I can't recall whether you can do this with Exchange 2003. I know for a fact you can with Exchange 2010 so would also assume 2007? (It may be worth a Google search?)

 

Those are all meant for discussion / consideration, not as a "you're doing it wrong" kind of argument. What works well for one school may not suit another, and you know best what suits you :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...