FROYO and Exchange security not really there yet - Nexus One Q&A, Help & Troubleshooting

Hello,
i am running Froyo on my nexus one.
When configuring a new Exchange support, i get:
""SETUP COULD NOT FINISH.
This server requires security features your phone does not support""
Touchdown is working fine and reports the following securities features:
Allow simple password
Password/PIN required
Failed attempts 10
Min length 5
Min Complex 3
Timeout 1800 sec.
Password recovery
So the question are:
1) Which of this securities is not yet implemented natively in froyo?
2) Will it make it in the final froyo release?
If any of you has some inputs, it would be nice to share.
Thanks in advance!
Best
dico

Sorry I cannot help with your problem other than to say that I have exactly the same issue. I am really shocked that Google have not got this fully working. We are hardly talking about a new protocol here!
Whilst I have Touchdown and have done since moving to Android last year, this single problem has stopped my company giving everyone Android phones. Come on Google, get it sorted!

Maybe because the foryo we got is not final? Ever thought of a unfinisched product that you use, is not finisched?

jaapschaap said:
Maybe because the foryo we got is not final? Ever thought of a unfinisched product that you use, is not finisched?
Click to expand...
Click to collapse
I think the point is that proper exchange support should really have been there from day one.
You just don't build a serious, high end smart phone with out proper integration to corporate mail (read exchange ).
Unless you're Google apparently.

badomen said:
I think the point is that proper exchange support should really have been there from day one.
You just don't build a serious, high end smart phone with out proper integration to corporate mail (read exchange ).
Unless you're Google apparently.
Click to expand...
Click to collapse
Well, I work and live in the corporate world and use my phone as such a device. I guess I sort of agree with you there about the exchange support, I can't really legitimize why they didn't incorporate this almost-brainless sync method.
Does the security policy of your works exchange server require to have a screen lock pin, specifically mobile device security policies? I noticed, after wiping from Froyo(with screen lock pin prior to EX acct) to CM and then back to Froyo(no screen lock when configuring), that I received an error that setup could not finish, I assume this is because without having a screen lock policy set up on the phone the exchange server will not authenticate to my device. Check that out. Also, this is not a finalized product.

Mine works fine...and I manage the Exchange system here...no problems.
My biggest issue is that Google has provided half-ass support for Exchange, and this version is no different.
You can't even move an item to another folder from the inbox with the stock Froyo.
The Desire Rom has the functionality and ability, best interface and options compared to the stock Android.
The stock Rom sucks honestly...if it weren't for Desire...I would still have my iPhone, even they figured out, licensed and got working properly the Exchange support 18 months ago. Windows mobile devices have had this for 3-4yrs.

My first post! May as well make it contributory.
It is interested to note that one may need a PIN lock set up first *before* adding an exchange account that requires one... I know I haven't been able to get our 2.2 Nexus One's to connect to our corporate Exchange Server for my girlfriend and I.
Let me go change to a PIN lock and see what happens when I try to add the exchange account...

Yep, no go still. "Unable to open connection to server."
They really need to add a Verbose button to these error messages.

still not working
Hello,
I tried setting up a PIN code before starting up the email application.
Does someone knows where to find the email app log file to see what is not good?
Thanks in advance!
best
CJ

To be honest, I tried using touchdown (which as great as it is, still lacks a lot of features), then tried using the Froyo Email/Calendar apps... Nothing has ever worked smoothly with Exchange + Android. I ended up migrating my email server (luckly it is only a personal email server) to Google Apps, and I have never been so happy with the performance and stability.
It is a tough cookie to swallow, but gmail is much better then Exchange on Android...

Related

Remote Wipe in Froyo?

So far, I have not managed to remote wipe my Froyo Nexus One from Exchange. It just didn't work.
I'm wondering if this hasn't been implemented yet in the version I downloaded (the one that was publicized up last weekend) or if there's something I'm missing.
Has anyone every done this successfully?
Maybe when the finalized Froyo build is out. I would try it myself but what if it works
I'm stil unable to do this using FRF83. Has anyone else tried and had it successfully work?
Exchange sends the remote wipe command but the phone just doesn't acknowledge it.
I'm hoping Google isn't trying to quietly not include full ActiveSync capability into Froyo... it seems awfully late not to have features baked into incremental test builds after the source has been released.
You don't have the final release yet, chillax and wait for, then you can complain to your hearts desire about what isn't included.
I'm on FRF85B. Still doesn't work.
The admnistration settings are correctly configured I assume?(both server side and phone side)
I have the device setup connecting to my Exchange server. I can get mail fine. It updates my calendar fine.
Within Exchange, the device is setup and seen.
But when a Remote Wipe is initiated, nothing happens. I can see the request being sent, but the phone never acknowledges it. I get the standard security error the next time I try to sync and I can't send or receive any new mail, but I still have access to all mail that has already been pushed to me.
Even though our policy says that a PIN is required, I've never been prompted for a PIN. (Although, I do have a security pattern setup, so I dunno how that affects anything.)
Inside the device's Location & Security settings, there is an option for Select Device Administrators, but it doesn't do anything.
I don't know of any other configuration or administration options.
You may have to do a factory reset and implement the administrator from first boot.
You probably can't gain admin access to a device after the device is set up. That'd be a huge sercurity flaw.
Here's what the option looks like, under Location & Security Settings:
Device Administration
Select device administrators
Add or remove device administrators
It doesn't sound like I'd have to wipe in order to add.
ive tried a remote wipe too, but it didnt work :/
Probaby time to get in touch with Google Support.
I posted a bug report and heard back from someone at Google, saying that my issue only exists if Exchange is allowing unprovisioned devices.
So I turned that off. Now I'm getting "This Exchange Activesync Server requires security features your phone does not support."
At least it's a different message.
Now the word I'm getting from Google is:
(via http://code.google.com/p/android/issues/detail?id=9426)
"That's probably the "correct" response, as we only support the basic (EAS 2.5) features in Froyo. So if your server requires, for example, password history or expiration, or complex characters, then it won't be provisionable in Froyo. Our goal is to provide more policy support in future versions, but for now we support - password (PIN/alpha), minimum characters, max. fails to wipe, inactivity timeout, and remote wipe."
So there you have... still no full ActiveSync support in Froyo.
Success!
The password recovery policy is what was causing the holdup.
I had to create a custom policy for Android devices that didn't include this and everything worked as designed.
The next time I attempted to sync I had to confirm the Email app as functioning with a Device Administrator (which explains the odd Location & Security/Select Device Administrators button that nobody really knew what it did.). After allowing that, a PIN was enforced and a remote wipe was successful.
The only concern was that I was able to go in and remove Email as functioning with a Device Administrator. This prevented me from sending or receiving any new mail, but any already-synchronized email remained visible and readable.

Exchange ActiveSync Issues...

So I've gone through a total of 6 Palm Pre's & Sprint allowed me to choose a different device, so I just picked up a Hero...
The problem is, of course, lack of simple pin & remote wipe support for ActiveSync, so I am unable to use my corporate email on the device. I have tried using TouchDown & that doesn't even work. It seems that my work may have a filter I was told by support for TouchDown(I work for a large technology company, so IT policies are very strict).
My question, is there any way, by rooting or whatnot, to get my device to support ActiveSync fully? Or a way of somehow fooling EAS into thinking I have a simple pin setup & remote wipe available?
I really wanted to start using an Android device, but shoot, if i can't even get my work email on it, its pretty pointless...
Thanks alll!
So I've gone through a total of 6 Palm Pre's & Sprint allowed me to choose a different device, so I just picked up a Hero...
The problem is, of course, lack of simple pin & remote wipe support for ActiveSync, so I am unable to use my corporate email on the device. I have tried using TouchDown & that doesn't even work. It seems that my work may have a filter I was told by support for TouchDown(I work for a large technology company, so IT policies are very strict).
My question, is there any way, by rooting or whatnot, to get my device to support ActiveSync fully? Or a way of somehow fooling EAS into thinking I have a simple pin setup & remote wipe available?
I really wanted to start using an Android device, but shoot, if i can't even get my work email on it, its pretty pointless...
Thanks alll!
Click to expand...
Click to collapse
Thought 2.1 took care of those security issues. Only other option is touchdown in the market, it works with complex security options.
-------------------------------------
Sent via the XDA Tapatalk App

[Q] Captivate phone for IT

I'm in IT and plan on most likely getting a Captivate from work for my job. I will be using VPN to connect to my work network (ipsec) and then using a remote desktop app to support people remotly when I am not in front of a computer. (No WiFi at work)
I currently have an iPhone 4 as a personal phone, and I know that I can use the logmein app to connect to computers and use the phone at the same time. I'm assuming I can do this on the captivate also. I was hoping to get the fascinate for the flash, and the fact that Verizon works much better at one of my remote offices, but the fascinate will not be able to do voice + data at the same time right? Also from what I read it has less RAM available.
Does anyone else work in IT and use this phone? What are your experiences with it as far as helping you on the job?
1) ass-u-me : but, in this case, you're correct https://secure.logmein.com/welcome/...oid&campaign=us&destination=/welcome/android/
2) It is likely that the VZW will not be able to do both transmissions at once, based on network type, but since I don't have VZ, or access to a fascinate.. ICSFS
3) Does Verizon really work that much better (actual experience) or is it just what the bars on the phone say... don't trust the bar display as an accurate detail.
fastblack said:
I'm in IT and plan on most likely getting a Captivate from work for my job. I will be using VPN to connect to my work network (ipsec) and then using a remote desktop app to support people remotly when I am not in front of a computer. (No WiFi at work)
I currently have an iPhone 4 as a personal phone, and I know that I can use the logmein app to connect to computers and use the phone at the same time. I'm assuming I can do this on the captivate also. I was hoping to get the fascinate for the flash, and the fact that Verizon works much better at one of my remote offices, but the fascinate will not be able to do voice + data at the same time right? Also from what I read it has less RAM available.
Does anyone else work in IT and use this phone? What are your experiences with it as far as helping you on the job?
Click to expand...
Click to collapse
I can give you some incite in the IT category. I maintain multiple networks with the company I work for, and there are a handful of apps on the market place that act as an RDP connection for logging on to servers and whatnot with a FQDN (Which I'm sure would work with the IP, but haven't personally tried it). Of course, if you use listen/forward on certain ports, you can get into those as well. My company uses a program that utilizes an instance of VNC to manage the workstations. I haven't had the time to sit down and try to crack that one yet, but I'm sure it could be done somehow. Our company just made the switch over to Google Apps hosted email so I've never used Exchange with it, but I've heard it works just fine.
I'm thinking here........
Ah yes, we all use Outlook. Calendar invitations import right into Google calendar perfectly. Contacts/email can be synced using Samsung Kies, but only with the default TouchWiz launcher, which I do not prefer. Dropbox works perfectly, yay!
Off the top of my head that's all I can think of. If you have any questions regarding certain areas, please let me know, and I'll give you as much info as I have.
* Oh, and I can confirm, Verizon does not support Voice+Data at the same time. My buddy has a DROID X and he can't even get an email while on a call, much less have an RDP session going.
Here's my IT experience. I personally think the stock email has issues. Everything works fine except for 2 things:
1. Emails are not instant. I thought I had a bad phone, swapped it, and no improvement. With any other phone I had previously owned (iPhone 3g, HTC Fuze, Blackjack II), emails would always arrive at the same time or even before Outlook would get them. Now I get anywhere from 30 seconds to 10 minute delay.
2. No NTLM support. Even with an iPhone I can connect to local wireless using Safari and use my domain authentication to access our intranet. I have yet to find a way to negotiate windows authentication on this android. I hear that mozilla is putting out a mobile browser (Fennec I believe) that may support it. Or hopefully 2.2 will add this functionality.
There are clients for RDP and even a couple for VNC. I installed one for VNC but never used it. I used WYSE RDP and love it.
Other than those 2 issues,i love it. I haven't tried setting up the VPN yet (pointless to me without NTLM), but that's all I'm missing.
I wish I had a tab or phone that I could install something like an admin tool pack on that would give me Active Directory tools on the go (besides the obvious RDP to a server). Maybe I'll have to wait for a windows phone 7 tablet........unless someone knows something I don't, I'd loved to hear some good news.
Sent from my SAMSUNG-SGH-I897 using XDA App
I am in IT as well and find this to be leaps and bounds better when coming from blackberry 9700
I use remote rdp and logmein ignition. I have direct push with exchange 2007 and the Gal is supported.
One complaint i have is with the email client. If you have rules setup to automatically sort mail without it being read, gl finding it on the phone. I had to turn all rules off and have everything delivered to the inbox.
Other then that i can pretty much do everything i think except dell drac console. But i hardly ever need to use those and if i did, i got bigger problems and should whip out the laptop.
Sent from my SAMSUNG-SGH-I897 using XDA App
I'll second what was said here, as a server admin, my phone is indispensable. I use VNC and RDP all the time, leave my home computer signed into VPN(it's a work provided laptop that has port 3389 forwarded) and just RDP into that, and then use it on my work domain. Or use the mobile AP functionality with a netbook running 7 Enterprise w/ VPN. No worrying about hotspot locations.
Exchange works great for me on it, no issues with active sync on E2k7. I do kind of wish we had an OCS 2007 R2 compliant messaging app for it. That's about all I could really use that isn't already available.
swedishcancerboi said:
1. Emails are not instant. I thought I had a bad phone, swapped it, and no improvement. With any other phone I had previously owned (iPhone 3g, HTC Fuze, Blackjack II), emails would always arrive at the same time or even before Outlook would get them. Now I get anywhere from 30 seconds to 10 minute delay.
Click to expand...
Click to collapse
For me, ActiveSync to the Captivate is as fast as my BlackBerry 9700 using BES which is pretty darn fast! Now if only the email client worked with all my sub-folders and allowed me to move emails, etc., I'd be happy.
Search for issues with IMAP and Exchange accounts on the ANDROID platform. I've personally had my IMAP and Exchange email accounts disappear from my phone completely, 3 times in the last month.
This is a know issue across all the Android phones and a problem that is still present in Froyo, kinda disappointing that Google can't get their act together and fix this MAJOR issue.....
There are great email replacement apps out there that solve the problem. The best replacement in my opinion at least is K9. I wouldn't use the version in the Market as it's a few versions old but the latest releases can be found on the googlecode page.
Replacement Apps???
I never needed a replacement app on my BlackBerry or Iphone so I could receive email? That to me is just plain absurd and unacceptable.
Josh K. said:
Replacement Apps???
I never needed a replacement app on my BlackBerry or Iphone so I could receive email? That to me is just plain absurd and unacceptable.
Click to expand...
Click to collapse
Android is in its infancy. How many version of windows mobile where there before you got activesync direct push access? Did you have exchange support on the original iphone?
Clearly anyone with a brain can see that the android platform is the most open platform today and compared to all others is more like an actual computer then just a phone.
I came from a blackberry and I hate to admit that I was a fanboy for the last 5 years or so... But after going android, the blackberry is the biggest pos and I give RIM 2 years before they become PALM.
The fact that you can run a 3rd party app that can handle your email, your phone or your sms functionality is amazing. However hard developers try to make a one size fits all... it may work for majority, but not all.
I have had zero issue with android and exchange activesync. My accounts don't disappear. Maybe you should take a look at your environment and see what is going on behind the scenes on your mail server or probably at your crappy anti-spam filter. I got emails instantly on my captivate before i get them on my computer, just like my blackberry did.
Yeah, must be my filters causing the account settings to be wiped from my phone on multiple accounts instantaneously....
Come on dude?
http://code.google.com/p/android/issues/detail?id=4866
Kinda hard to make progress on a platform when your preventing the corporate world from adopting due to serious issues with non Gmail accounts?
I'm a Sr. Sys admin and my experience using the captivate on the job has been great. By connecting to our wpa2 enterprise I've SSH'd into routers and switches using Better Terminal (BTEP SSH Client). It's great not having to drag a laptop and a rollover cable into a server room while working with a switch. I've used the WYSE's beta client which supports RDP, VNC and VM View. I'm also a big fan of Astro file manager which has an add-on for connecting to SMB shares. We've also setup a Rove Mobile Admin server. it's an SSL encrypted publicly accessible server which utilizes an android app from which i can manage everything from BES, to SQL, to Exchange, to AD. Its an expensive license but very very well worth it. and while i do think the stock active sync client is usable i've found that TouchDown offers a much more advanced product complete with meeting invites and GAL support. Again, this is a great phone for for IT work!
Hmmm, I just wonder what is different about the heartbeat to Exchange with Android than it is with every other phone. I agree it could be some mysterious setting that needs adjusted on Exchange, but I'll probably worry about it after we upgrade from 03 to 07.
Doesn't matter......phone rocks.
Sent from my SAMSUNG-SGH-I897 using XDA App
i am a sytems and network admin, droid x with and touchdown and logmein has never failed me. wifi teathering with a laptop is great too.
Sent from my DROIDX using Tapatalk

Droid 4 Exchange Server Security: How do I remove?

Phone rooted, I swear I read something a bit back about ripping the encryption settings out of the phone so that I can connect to an exchange server without encryption/pin lock, but I cannot for the life of me google it back up. I like the stock email client and would prefer to continue using it, and the older email client I installed refuses to work with the exchange server. Aaaaand I like the little email widgets.
Can anyone point me in the right direction here towards what I need to do to set up my exchange account without it enforcing encryption/pinlock/camera disabling? It's my school's account, and there IT guy simply told me they aren't going to disable it on their side.
And besides free wifi tether, if there is anything else cool we can do once this phone is rooted, that'd be nice to know, too.
punkonjunk said:
And besides free wifi tether, if there is anything else cool we can do once this phone is rooted, that'd be nice to know, too.
Click to expand...
Click to collapse
AdFree is pretty sweet...blocks most ads (won't block audio ads in Pandora, though)
Yeah, adfree is pretty awesome. Titanium sounds neat, too, but I'm a little skittish about freezing anything that's needed to run the phone, and so far it's impossible to slow this thing down anyhow, but it may be useful. I can't seem to find an overclocking app that's tailored to this phone, but my understanding is that motomizer works and the internals are basically the droid RAZR. Tinkerin' with that a bit.
I found one thing regarding the email client and it's lock downs, but it suggested installing an older email client which apparently doesn't have a widget, and a fix involving adding and removing the account and then removing security settings, but neither of these worked.
siiiiigh. It's my schools email, which is really frustrating. I don't understand why they'd have those securities in place at all.
The reason that schools have hardcore security in place is because the teachers and administrators use the came e-mail client... it has to be secured in order to protect sensitive info.

email policy patch

I love Motorola phones and software and I love the Razr I but I'm stuck with Samsung phones because I can patch the annoying email policy enforced by our company and get rid of the password that I have to enter every few minutes.
is there a patch for the email application on Motorola phones?
i'm willing to donate or fund whoever is able to do it.
Note: Exchange policy requires a 6 digits numeric password every 10 minutes of inactivity. really annoying.
Dude wrong thread section to post
you have a thanks button and don't know what to do wit it...?
just press.it!
zkrayem said:
I love Motorola phones and software and I love the Razr I but I'm stuck with Samsung phones because I can patch the annoying email policy enforced by our company and get rid of the password that I have to enter every few minutes.
is there a patch for the email application on Motorola phones?
i'm willing to donate or fund whoever is able to do it.
Note: Exchange policy requires a 6 digits numeric password every 10 minutes of inactivity. really annoying.
Click to expand...
Click to collapse
Yeah ... wrong place for such questions ... however, "Moxier mail" was my way out .. and there also is "TouchDown" - both are Exchange clients which are keeping the pushed security policy within the application and not affecting the system.
ro_explorer said:
Yeah ... wrong place for such questions ... however, "Moxier mail" was my way out .. and there also is "TouchDown" - both are Exchange clients which are keeping the pushed security policy within the application and not affecting the system.
Click to expand...
Click to collapse
This works for me:
https://www.google.com/url?q=http:/...ds-cse&usg=AFQjCNGIxo7uKwggvwxvdOUcbUQhIAWaBw
also on my Razr I. You have to input the right name of the mail.apk (MotoEmail.apk)
tsgfrade said:
This works for me:
https://www.google.com/url?q=http:/...ds-cse&usg=AFQjCNGIxo7uKwggvwxvdOUcbUQhIAWaBw
also on my Razr I. You have to input the right name of the mail.apk (MotoEmail.apk)
Click to expand...
Click to collapse
Hi there.
Excuse my ignorancy but hod do I "input right name"? I've rather renamed email app to email.apk so the patch should find it automaticly but when I launched apply-patch, cmd window just jumped off for a second and no reboot was required so how do I know it worked? The reason why I ask is that my work email requires very strict exchange policy and requires full encryption of phone and sd too and this is what I'm trying to avoid (coudn't find the answer in original thread).
Thanks

Categories

Resources