Welcome to TechNet Blogs Sign in | Join | Help

The Official SBS Blog

The official blog for Small Business Server (SBS) support and product group communications.

News

  • Disclaimer: This posting is provided "AS IS" with no warranties, and confers no rights. This weblog does not represent the thoughts, intentions, plans or strategies of Microsoft. Use of included script samples are subject to the terms specified at http://www.microsoft.com/info/cpyright.htm
Remote Wiping a Device With No User Input

[Today's tip comes to us from Peter Gallagher.  Yes that Peter.]

 

If you have installed the Exchange 2003 ActiveSync Web Administration Tool (also known as MobileAdmin) you probably played with the Remote Wipe feature. You may have noticed that the user must click "OK" to wipe the device. Well, that may not fit your customer's needs. They may need to wipe the device NOW. You can do this however you have to be proactive about it. In order for Remote Wipe to hard reset the device without user input, the device has to have accepted *any* Exchange Server Security Policy. What this means is that you have to check the box for "Enforce password on device" and let that policy sync to the device.

When the device syncs, the user will get the following prompt:

If the user clicks "OK", a policy is then applied to the device. This policy requires a PIN to be entered on the device before the device can be used.

C:\Users\petergal.NORTHAMERICA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Outlook\8S8IIK9V\SnipImage (5).JPG

Notice the "Prompt if device is unused for" is enabled and grayed out (i.e. it can't be changed).

Now, since a policy is applied to the device, you can remotely wipe this device without user intervention.

The challenge is that now the user has to enter a PIN in the device to unlock (use) the device.

If you want to be really sneaky, you can then go back to Exchange and uncheck "Enforce password on device" and then have the user sync.

The new settings are pushed to the device and now "Prompt if device unused for" is able to be unchecked. Uncheck "Prompt if device is unused for" and now the user's phone is back to a default state and you can remotely wipe it without user intervention. Be careful here as now new devices cannot be wiped without user intervention, thus the "you have to be proactive" statement at the beginning of this post.

Posted: Thursday, January 11, 2007 2:25 PM by markstan
Filed under: ,

Comments

E-Bitz - SBS MVP the Official Blog of the SBS "Diva" said:

Engadget blogs about how the Iphone must connect to Exchange to be the true business killer app. http://www.engadget.com/2007/01/14/will-the-iphone-support-exchange-direct-push/

# January 19, 2007 10:32 PM

Jackson Liao @ Microsoft TechNet Taiwan 的部落格 said:

前一段時間接獲 Exchange 產品經理的回報, 在 TechNet 討論區 上有個 Exchange 2003 ActiveSync 與 Enforce Password on Device 問題

# April 2, 2008 11:21 AM
New Comments to this post are disabled
Page view tracker