The AD attribute is not updated, but you can get the real-time connection data 
from the CAS server. I filed a bug with the Exchange team to fix that. They 
update last sync time all the time, so  it cannot cost too much more to update 
DeviceUserAgent. When you block you block based on what's presented to the CAS 
server and not what is in AD. 

Somewhere I have a script to find it on the CAS server. I will try to find it 
in the morning. 

-----Original Message-----
From: Michael B. Smith [mailto:[email protected]] 
Sent: Tuesday, August 03, 2010 3:57 PM
To: MS-Exchange Admin Issues
Subject: RE: Androids, iPhones, Exchange and Security -- Do they mix?

So, a user had a partnership that started with iOS 3.

They've upgraded their iPhone to iOS 4.0.0. But, as you noted in your blog 
post, that isn't reflected in the DeviceUserAgent because the partnership was 
established BEFORE that.

Given that, how do you block partnerships established BEFORE 4.0.1 but are 
running 4.0.0 ???

Regards,

Michael B. Smith
Consultant and Exchange MVP
http://TheEssentialExchange.com


-----Original Message-----
From: KevinM [mailto:[email protected]] 
Sent: Tuesday, August 03, 2010 6:51 PM
To: MS-Exchange Admin Issues
Subject: RE: Androids, iPhones, Exchange and Security -- Do they mix?

What do you mean ?? 

-----Original Message-----
From: Michael B. Smith [mailto:[email protected]] 
Sent: Tuesday, August 03, 2010 3:09 PM
To: MS-Exchange Admin Issues
Subject: RE: Androids, iPhones, Exchange and Security -- Do they mix?

Thanks - good table.

But how did you overcome the "already existing partnership" issue? That's what 
I can't figure out to handle.

Regards,

Michael B. Smith
Consultant and Exchange MVP
http://TheEssentialExchange.com


-----Original Message-----
From: KevinM [mailto:[email protected]] 
Sent: Tuesday, August 03, 2010 5:46 PM
To: MS-Exchange Admin Issues
Subject: RE: Androids, iPhones, Exchange and Security -- Do they mix?

I started writing something about it, but I only posted half of it. Been busy 
and stuff... 

Basically the DeviceUserAgent string is different for 4.0.0 vs. 4.0.1 so we 
just did a block on the CAS servers for 4.0.0. There is a table in the blog 
post that identifies each version. Getting the table was the hard part, and 
from searches last week I was the only to publish it.  -- see my blog post for 
a bit more. I would paste the goodies here but the table does not look good in 
plain text

http://www.hedonists.ca/2010/07/22/blocking-the-iphone-part-i 



-----Original Message-----
From: Michael B. Smith [mailto:[email protected]] 
Sent: Tuesday, August 03, 2010 2:33 PM
To: MS-Exchange Admin Issues
Subject: RE: Androids, iPhones, Exchange and Security -- Do they mix?

I'd like to know how you are detecting that! :-)

Regards,

Michael B. Smith
Consultant and Exchange MVP
http://TheEssentialExchange.com


-----Original Message-----
From: KevinM [mailto:[email protected]] 
Sent: Tuesday, August 03, 2010 5:24 PM
To: MS-Exchange Admin Issues
Subject: RE: Androids, iPhones, Exchange and Security -- Do they mix?

Note to all other BPOS users in Europe and North America..  -- we are going to 
block all IOS4.0.0 devices tonight.

We've had things go out in the RSS feed, and in emails, ETC --  If this is the 
first you have heard of it and you need a list of devices ping me off list and 
I can help. For that matter if you have any BPOS issues ping me directly and I 
can help.

-----Original Message-----
From: Jay Dale [mailto:[email protected]] 
Sent: Tuesday, August 03, 2010 1:44 PM
To: MS-Exchange Admin Issues
Subject: RE: Androids, iPhones, Exchange and Security -- Do they mix?

We use Microsoft BPOS with our IPhones, so not as much on-hands control.

Jay Dale
 Senior Systems Administrator
o:713.785.0960 x290


-----Original Message-----
From: Jon D [mailto:[email protected]] 
Sent: Tuesday, August 03, 2010 3:35 PM
To: MS-Exchange Admin Issues
Subject: Androids, iPhones, Exchange and Security -- Do they mix?

How is everyone allowing Androids and iPhones to connect to their exchange 
server?
I've been looking into it, and it seems like the newer smartphones are not much 
different than full on computers minus the antivirus and firewalls.

- iPhone had a pdf exploit released today.
- The 2.2 Android Froyo apparently bypasses all exchange security.
- Looking at the Android marketplace, there are free click button apps to 
disable exchange policies.
- People are putting custom ROMs on their Androids made by who knows who.

I'm assuming it's going to get nothing but worse.
How does everyone deal with these things?




Thanks in advance.




.



























Reply via email to