I currently use my work exchange server to hold all my emails and contacts...but my sever requires that i have a password on my mogul.
Just wondering if anybody knows how to get around this and disable it? I hate having to type in a password every 15 minutes whenever i want to look at my phone...such a pain! I would much rather just have it whenever the phone starts...or maybe even like every 2 hours or so...not 15 minutes!!
Please helppppp!!!!
Thanks!
I'm attached to a Zimbra server for email/contacts. I just checked it's user options and did not see an option for that.
I do speculate that it's an option on the Exchange though. It's been a few years since I managed one. You'd probably be in good shape checking with your admin about this...
what I do
TripFlex said:
I currently use my work exchange server to hold all my emails and contacts...but my sever requires that i have a password on my mogul.
Just wondering if anybody knows how to get around this and disable it? I hate having to type in a password every 15 minutes whenever i want to look at my phone...such a pain! I would much rather just have it whenever the phone starts...or maybe even like every 2 hours or so...not 15 minutes!!
Please helppppp!!!!
Thanks!
Click to expand...
Click to collapse
I have my password saved under the phones activesync settings.
He's talking about the hardware security policies pushed to the handset by Exchange Server.
Yes - there are ways to disable and alter the effective policies on your handsets. However, they are in place because you are accessing your company server and any sensitive information on your phone should be protected from loss. (for this reason, I always strongly dissuede people from using personal handsets for company/government/official business) As a piece of IT/Communications gear, those phones are subject to the same security requirements enforced across the entire organization.
If you must be the weak link in your company's security, you can find hints to open a vulnerability here: http://forum.ppcgeeks.com/showthread.php?t=43428
Related
When I set up an exchange account the phone ask me to set a password. Now every time I turn on my phone it or wake it up it asks me to enter the password. How do I remove the password???
If you were forced to set a password when you set up exchange activesync then the password is enforced, you can't remove the need for a password as long as you sync to that server.
The IT policy is set by whoever administers the server for all connected devices, most companies would use that setting for example to protect their data.
Who is hosting your exchange? Is it a work account?
It's 1&1. I really wish i knew that before i bought. Everytime I wake up the phone I have to put in a darn code. Is there any way around this? Very annoying.
Only way around it is to remove the exchange connection.
It's a server-wide policy - to cope for some users needing passwords, maybe even their own staff it will have been set up.
I'd stick with it personally, the device is more secure when lost with it enabled... I carry a wizard and Blackberry - both need password entry but I'm used to it
This week end I tried to sync my oulook mailbox and it asked me to accept new security policy.
It was in fact my company that upgraded to latest Outlook mail server with push functionality.
I was very happy and push is working fine.
But now I also have this annoying Pin code to enter every hour.
Also even when I entered the code and I am free to use my phone during one hour, I noticed that each time I turn it on I have a blank screen for 1 seconde before it loads the today page slowly.
This password feature is not nice at all and I really want to get rid of it.
I am pretty sure we will be able to find some regkey to unlock this stupid security policy like in HKLM\security\Policies\Policies.
It has to be a user choice in the end.
Do you know if I stop syncing with my server if i can remove it?
no, as I've said twice already, if you're using exchange activesync then this policy is enforced.
It's not user choice, if you're syncing your device with your employers equpment it's their data, they're legally entitled to protect it. If you're syncing with a third party server then the device will do as its told... the server is considered authorative - the same is true of Blackberry.
If you can find a way to alter the policy the checksum of your settings will differ to that stored on exchange, when the device next syncs it will see the change in policy and enforce the correct settings, turning the security back on.
Seriously guys, if you want exchange activesync then live with the policy , if you don't then disable the server connection.
remove the activesync service then yes you should be able to edit again to disable.
of course the thing mentioned above is not a solution...
i'm hal-way there and spoke with the rom makers to find a complete solution...this one is just temparary...
SeanH said:
I have been using a registry hack everyday to prevent my WM5 device from locking itself every 30 minutes. At around 7:00pm the company I work for forces a policy to my device using push email. At that time I open a registry editor and modify \hklm\security\policies\policies\00001023 from 0 to 1. That prevents the unit from asking for a password for 24 hours.
Click to expand...
Click to collapse
good luck
remen said:
of course the thing mentioned above is not a solution...
i'm hal-way there and spoke with the rom makers to find a complete solution...this one is just temparary...
good luck
Click to expand...
Click to collapse
I've decided I'm not going to be able to help on this one. It's your company's choice to enforce that security policy and not mine to help you get around it. I'm not being rude, I'm just not able to put time into research to do that at this moment.
Good luck.
I tried to set up ActiveSync/Direct Push on my 8525 to sync my corporate email without needing a laptop. I seemed to have gotten part way through the process:
The server pushed to me the new password policy complete with x-digit requirement and x-minute timeout.
When it came time to sync, it bombed (I tried another device - I just think my company doesn't allow ActiveSync).
I'm convinced IT isn't supporting that feature,
Problem - HOW DO I GET RID OF THE PASSWORD POLICY! I'd like to go back to my plain 4 digit PIN with the big keypad. I see some reg entries that must be associated, but I'm not sure.
I did a search on the forums, but didn't find anything. I appologize if this a newbie post ...
AFAIK there is no easy way to do this other than hard resetting the device. I had the same problem I had to hard reset it.
I could be wrong.. but from what i have read the password policy is set on the server and not the phone.. you would probably have better luck talking to your IT people than editing the policy on the phone..
shogunmark said:
I could be wrong.. but from what i have read the password policy is set on the server and not the phone.. you would probably have better luck talking to your IT people than editing the policy on the phone..
Click to expand...
Click to collapse
It is definitely set on the phone. It has to be disabled on the Exchange server before you can remove it from your phone. Once it's disabled on the Exchange server it requires a soft-reset before you can remove the lock.
Hi,
I have the same problem on my trinity ;-)
I delete the exchange server in activesync but security et here :-(
I found the solution :
"
Originally Posted by SeanH
I have been using a registry hack everyday to prevent my WM5 device from locking itself every 30 minutes. At around 7:00pm the company I work for forces a policy to my device using push email. At that time I open a registry editor and modify \hklm\security\policies\policies\00001023 from 0 to 1. That prevents the unit from asking for a password for 24 hours."
I had this problem on the HTC Kaiser as well; the SeanH solution works like a charm! The tick mark is NO longer grayed out!
Thanks!
006fazer said:
Hi,
I have the same problem on my trinity ;-)
I delete the exchange server in activesync but security et here :-(
I found the solution :
"
Originally Posted by SeanH
I have been using a registry hack everyday to prevent my WM5 device from locking itself every 30 minutes. At around 7:00pm the company I work for forces a policy to my device using push email. At that time I open a registry editor and modify \hklm\security\policies\policies\00001023 from 0 to 1. That prevents the unit from asking for a password for 24 hours."
Click to expand...
Click to collapse
I've read a few threads after searchign on Android and Exchange but can't really find what I'm after.
I need to enforce a security policy if users want to sync their exchange account. There's a few people in the office who want Android devices (we provide them with a device) but until there's somethign which enforces something along the lines fo a PIN after 20 mins ala WinMo then we can't do it.
Anyone have any ideas if it's coming or if there's an app to do it? I've tried Touchdown but just seems the same as the Hero Exchange app to me.
I've not tried Touchdown, but they say they support PIN enforcement.
http://www.nitrodesk.com/dk_touchdownFeatures.aspx
Regards,
Dave
Yes, Touchdown and Roadsync both support the PIN function (they ignore it somehow, as android doesn't have a PIN function!)
although i do believe that it is technically possible to exclude individual accounts from the policy on the server (although not exactly the best idea in terms of security).
Alternatively, just do what we did at work and say 'No, you cannot have an Android Phone for your Work Phone'.
Since the ROM update on the HTC hero, I have been able to access my work email (a massive highly secured company who generally know what they are doing) and I know for a fact that they enforce this kind of security arangement on mobiles that want to connect - however android has somehow got around this and there is no remote enforcement and I can use my phone for these emails via PUSH. (I use the gesture lock as a password) You could get them to sign an agreement that they will apply this kind of thing to their phone manually. I don't know if there is an app for remote wipe.
Your company isn't allowing you in some backdoor or anything... depending on their version of exchange they are simply allowing you to use activesync through exchange.
What we all really need is an andriod client to take advantage of exchange 2007's exchange web services protocol, activesync is old technology and limited.
O.P. - You can limit users on a single user basis, if you're running windows active directory. Need a little more info on what you are trying to accomplish. If you're allowing them to use their mail client setup they are saving a password that is not clear text and is hashed... you can install a remote wipe on the phone and if they lose it, simply wipe it and forget it.
Is there any way to get out of having to enter a pin because of the exchange server security requirements? I don't have any info on my work email I am worried about.. so it would be nice not to have to have a PIN/Password to be able to use it.
I have an exchange, it doesn't have to ise a pin at all, I just put it on to the native the email app
Just open and your in.
If the Exchange is setup to require PIN, not all are, then no you will not be able to get around it. It depends on the IT policy who is running the Exchange environment. They can set it to wipe your phone as well if they wish. Both the native app and Touchdown will do this. If they allow other methods of accessing Exchange, then this will not be an issue. However if they are requiring a PIN then they probably don't.
clintre said:
If the Exchange is setup to require PIN, not all are, then no you will not be able to get around it. It depends on the IT policy who is running the Exchange environment. They can set it to wipe your phone as well if they wish. Both the native app and Touchdown will do this. If they allow other methods of accessing Exchange, then this will not be an issue. However if they are requiring a PIN then they probably don't.
Click to expand...
Click to collapse
Ok. Guess I'll see if I can access it through other means than exchange. Not sure. Just hate typing in the pin all the time!!
Thanks for the info though
I run an exchange server myself with a few activesync devices running. It sounds like the pin you are describing is imposed by your system administrator, when I set up an account on an evo or inc all I need is my domain credentials and a server address.
I also run an Exchange setup. I can verify that a few native e-mail apps from 2.1 days somehow bypass certain Exchange requirements, much to my dismay (Motorola comes to mind). They pretty much lied to Exchange and said they were compliant when they weren't and didn't enforce some rules. However, all the new stuff follows the ActiveSync rules, assuming that's the setup you're aiming for. I suppose if you really wanted to bypass the security you could check to see if they left IMAP or POP open, but then they'd just be some not-very-smart sysadmins.
Also, you shouldn't need anything more than your e-mail address and your password to ActiveSync. After the initial attempt at syncing it will ask for you to verify the security permissions. If it drops out and asks for your server name, domain, and such then tell your admins to fix AutoDiscover.
Oh, and while the thought of your admins being able to wipe on command is scary, you will have the ability to remote wipe your device in the event you lose it. It'll be accessible under OWA, so that's handy.
Hi,
I configured our exchange server for corporate push mail on my Galaxy Note with March 2012 firmware. There's "optional encryption" requirement in the policy, where Exchange server ask for encryption if the device supports it.
Since Galaxy Note supports encryption, it enabled the encryption and asked me for a password.
Now, each time the screen locks, I have to enter a complicated password (consisting of characters, digits & a special character!) to unlock it! The phone became very unusable!
I understood from the post of "Eviip" in the page below that this is actually a requirement from Samsung side when you enable encryption, since my Exchange policy definitely does not require this. All other colleagues with Androids that can't do encryption or using iPhone's can just type a 4-digit pin code and use their phones.
http://www.google.com/support/forum/p/Google+Mobile/thread?tid=6355566b726a0932&hl=en
Is there anything I can do for this, except buying a 3rd party mail application?
Weird, because as far add I understand it GB doesn't support device encryption, only ICS does...
What ROM are you running?
Also, did the exchange policy configure the encryption or did you do it? Because as I understand it the exchange policies don't demand device encryption, just mail stream encryption (but I'll look into that further) and that is pretty innocuous stuff...
Sent from my GT-N7000 using Tapatalk
I see the same behaviour (gNote running 2.3.6 XXLA6; ActiveSync / Exchange Server 2007 SP2). With ActiveSync policy pushed through to device, I have to use strong password to unlock, even though the policy only calls for 4-digit PIN.
I'm using TouchDown mail client as a workaround (at least for the next 30 days) but hoping the ICS update due out "soon" will fix the "problem".
Is there any feedback avenue to Samsung regarding this "feature"?
thomas_d_j said:
I see the same behaviour (gNote running 2.3.6 XXLA6; ActiveSync / Exchange Server 2007 SP2). With ActiveSync policy pushed through to device, I have to use strong password to unlock, even though the policy only calls for 4-digit PIN.
I'm using TouchDown mail client as a workaround (at least for the next 30 days) but hoping the ICS update due out "soon" will fix the "problem".
Is there any feedback avenue to Samsung regarding this "feature"?
Click to expand...
Click to collapse
touchdown is no option for me, because it supports 2 different exchange accounts at a time only with "profiles", which is unusable for me!
regarding your problem: i know for sure that there were some hacks for this (a modified apk which doesn't incorporate the lock requirements. the downside is: with every rom upgrade you would have to redo this hack, as the mentioned apk may change in the system itself to a newer version...
Yeah, same to me
I 've update to 4.0.3 ICS but now I want to no use password or PIN for unlock screen mean that can I not use my exchange policy? (cause my GN haven't any privacy data to secure
so can you show for me? thanks!
I finally gave up with this and used the patch that I found in the forums (for rooted phones). It works pretty well!
http://forum.xda-developers.com/showthread.php?t=1117452