SOLUTION: Syncing with Exchange and using Self Certified SSL Certificate - Windows Phone 7 General

Right got my Trophy on Saturday and setting it up to work with work e-mail (Exchange 2003) has been tricky to say the least! However I seem to have fixed it and thought I'd share as a weekend of googling and binging couldn't bring an answer.
I wasn't getting any sync with the server and a variety of error codes, despite having installed our certificate as recommended across the web (e-mailed to myself via Hotmail).
Error Code: 80072EE2
Error Code: 85010014
Error Code: 80072EFD (this was the most popular)
Error Code: 80072FA8
Given that the cert had worked fine with my TD2, Android Phones, iPhone and Nokia this was infuriating to say the least, especially when there is a lot to like about the rest of the phone.
What had I done wrong?
Setup Hotmail first, then Facebook and then turned my attention to Exchange. Was running through the wizard in the hope of being prompted to load a cert (a la Nokia EAS, but no luck). We don't have self discovery and only use our external IP address to connect to the server (no URL) so had to let it fail three times before being allowed to enter the advanced options. So unsurprisingly with everything in place I got a cert error. Read up how to get it on the device (e-mail to yourself on an already working e-mail account, in my case Hotmail). Still no luck.
After that it all become a non-productive cycle of googling error codes on the web, "power cycling" (turning on and off by a posher name), deleting the account, reinstalling the certificate, reinstalling the account, etc, etc with no luck.
So how'd I solve it - simple, but worth writing down should anyone else not want to waste a weekend! (Caveat - worked for me, can only hope it works for you)
1 - Hard reset the phone to start from scratch
2 - As part of the initial setup process entered my Windows Live ID for my Hotmail account.
3 - Connected to Wi-fi to speed up sync.
4 - Once all synced went to my Hotmail Inbox and installed the copy of the certificate I'd sent myself before.
5 - Did a "power cycle" - Turned off phone and then briefly removed battery to be extra sure.
6 - Turned phone back on and added Outlook Account.
7 - All is now working fine - I have contacts, appointments and mail as well as push in both directions (changes made on Outlook come through to device and vice versa).
Now very pleased with the phone, but why this was such a trial between two Microsoft products is beyond me!

it might be worth getting an ssl from godday $30
save your self a weekend of pain

I just sent the cert to my exchange account and logged in to OWA, clicked the cert, installed it, set up the exchange sync.


Timeout-Messages cannot be downloaded to your mobile device

I have a couple of POP3 accounts on my O2 XDAIIs. I used to be able to download my email from ISP without problems.
Lately, when there is any email waiting, it will connect and try to download and pop up the following message "Messages cannot be downloaded to your mobile device. Make sure you are connected and that your e-mail account settings are correct. Then, try to download messages again."
The other POP3 accounts work fine, even with the same ISP, and this POP3 account used to work when I first got the unit. The POP3 account in question works fine from my Treo using the same SIM card (I have Cingular).
I searched all over the web and forums, I see many have the problem and some have not been able to resolve it. I tried:
1) Soft and Hard Reset
2) Deleting and reentering the account
3) Used the Sprite Mail cleanup utility (which basically cleans all emails and attachments)
4) Tried a registry key that had worked for some: HKEY_LOCAL_MACHINE\Software\Microsoft\Inbox, create new DWORD ForceOffSSL and give it a value of 1.
5) Checked with my ISP – they could not see any problem with the account and works with anything else but my O2 XDA IIs.
6) I tried the Flemail 2006 program (formerly WebIS) and it worled for email. But the program is so buggy and slow that I had to delete it. This tells me the problem is with the native pocket outlook.
If there is NO email, it will connect, check and disconnect with no error.
There is a timeout somewhere. The other accounts can connect and download without problems.
Has anybody else had this problem and does anybody have any suggestions?
No one else has had this problem? Any suggestions?
I know it is device specific as it works on the same GSM account on a Treo.
PPC6700 with same problem
I just purchased the PPC 6700 and I love the device itself, but I have had many problems with it after owning it for only 4 days.
1. Sprint failed to let me know that my phone had to be updated. Thanks! I only found out about this update after 1 hour of phone tech support trying to find out why my phone randomly went into flight mode. What a pain in the ***.
2. I have my own servers and cannot download my mail from them or my home isp. Sprint by the way repeatedly told me this must be an issue with you server. I told him after being on the phone for 3 hours (I could tell he wasn't happy) "You must be right! Microsoft has always developed software much more then anything ever put out in the Unix world".
So the only help I guess I can offer to you is "Yes, I have the same problem with the native outlook that comes with WM5.0
likegadgets said:
No one else has had this problem? Any suggestions?
I know it is device specific as it works on the same GSM account on a Treo.
Click to expand...
Click to collapse
Whenever I see this (and I see it a alot) on mt XDA IIs, I just select Accounts|Clear <account>
If it doesnt work immediately then I restart the Outlook Inbox app and/or disconnect/reconnect.
Been through searching registry/deleting this & that database file / re/installing accounts. Havent had to do that for ages.
I access 5-6 pop accounts from various servers, several are my wife's. My bet is that it has something to do with whether the current status of the emails downloaded in your device matches the server etc - due to the function that you can delete the emails from the server by downloading, deleting and then deleting from the 'deleted items' folder and re-sycning
ME TOO! Any resolution??
I am having the SAME EXACT PROBLEM with my new 6700...did you ever find a resolution?
I am having the same problem on a Hermes / TyTN.
My first TyTN was fine. I have 3 email accounts. 1 uses SSL and the other 2 don't. There were no problems using either account.
Having replaced my 1st TyTN with a new one (due to poor wifi on first device) I now get the message 'Messages cannot be downloaded to your mobile device. Make sure you are connected and that your e-mail account settings are correct. Then, try to download messages again'.
The only solution is to use the ForceOffSSL setting for my 2 none-SSL POP3 accounts. Then I have to reboot the TyTN without the ForceOffSSL settings to use my SSL POP3 account.
Continually changing the ForceOffSSL setting and rebooting is annoying, so for the time being I'm using nPOP email client for my non-SSL accounts.
getting an email timed out on cingular 8525
I am getting the same message 'Messages cannot be downloaded to your mobile device. Make sure you are connected and that your e-mail account settings are correct. Then, try to download messages again'. I am having the same problem intermittently with Htc Tytn with a pop account yahoo. I seem to connect without a problem on the internet but i do get this error intermittently. any solution?
Same here ... cannot send mail via OptOnline Account
OK...I got a resolution to this last night on the Cingular forum.
Quick answer is that OOL's SMTP Server is locked down. I needed to change the outgoing server to Cingular's (
Thanks to anyone who took the time to click-in on this thread.
Happy New Year, all!
Hi all, OK, this marks my first post on this board. I've been a lurker for a few months, and have settled into a Cingular 8525 as my first Pocket PC Phone.
I noticed a few days ago that I could not send mail via my OptOnline Account, unless I was using WiFi or the 8525 was tethered to my home PC via ActiveSync. I was thnking all along that it was probably due to some piece of third party software that I installed over the past few weeks (a hearty thanks to all on these forums who develop and/or market their wonderful wares, btw).
But today, for a lack of anything else to do, I hard reset and tried simply setting up that one account to try my machine out in its pure form. Lo and behold, I still get the same error, 'Messages cannot be downloaded to your mobile device. Make sure you are connected and that your e-mail account settings are correct. Then, try to download messages again.'
As a matter of fact, it seems this message itself is in error, since it happens when I try to SEND a message, not when I try to receive them. I have even received emails in this account at the same time this error message appears, but at any rate, messages in my outbox do not get sent.
As far as I can tell, all the settings are correct. I have played with them, and tried all the permutations I can think of, but this baby will not send mail via this account. My XpressMail and Hotmail accounts work fine, both sending and receiving, and I can browse the web fine via My ISP or WiFi.
I have spent a lot of time searching the web for an answer to this problem, but it seems it's been quite prevalent with WM5.0 devices for well over a year, and still does not have an answer.
So ... my first post ... which should have been a thank you all, and Happy New Year, has turned into a request for the talents of you folk who know so much more than I regarding these devices.
Can anyone please lend a hand? Also ... is it "legal" to cross-post this message onto other forums on this board?
Thanks so much to anyone who can provide a solution.
-Paul Slabowski (a.k.a. pvs)
I got it working
Like others in this thread I was getting the "unable to download messages to device" error when sending. My solution is:
Try leaving the 'domain' field blank.
It's on the Server Information page, and also on the Outgoing Settings if you 'Use separate settings' for your outgoing server.
Hope this helps you.
Domian Blank
My Domain is blank and frankly im just getting very agrivated by this. Does anybody eles have other advice to give towards this "cannot download message"?
I've got WM6, I've tried clearing and deleting the account, soft resetting the phone, making sure the domain field is empty, etc. It still gives this error for my POP account while my IMAP account is fine. Anyone find a solution?
Yes, deleting the domain really works in some cases (f.e. Gmail), but the same error occurs in my other account although I delete the domain. And funny thing is that it occurs only when there are some emails in outbox, receiving emails seems to work normnally :S
I'm still encountering this problem after trying everything on this post...
any other ideas?
Just had the same problem tonight. My mail server recently changed IP addresses, so I suspect DNS issues were the cause of my problem. I tried using the new IP address in place of the host name, but that didn't work for me. The account settings didn't seem fixable. Deleting the email account entirely and adding it back did the trick.

WM6 Exchange EMail help

I am currently using WM6 and am trying to get EMail through our Exchange server setup; however, my Dash s620 will not properly save the server's address.
The address for our OWA is (ex)
and this address works fine in Internet Explorer etc, but when I enter this into the phone it removes the /exchange and only saves up to :8888, which then gives me "Error synchronizing" when trying to connect. Our Exchange server does have Exchange ActiveSync enabled along with Direct Push enabled.
Any ideas?
Thanks in advance
I think that you have to check your ActiveSync settings on Exchange. I know that Microsoft have a lot of KB's about that.
It does the same thing on mine, erases exchange, but mine is cool. Are you sure you are putting in the Domain?
jt76542 said:
It does the same thing on mine, erases exchange, but mine is cool. Are you sure you are putting in the Domain?
Click to expand...
Click to collapse
Yeah I've tried every which way I could think of for the login credentials.
I'll sift through some more MS articles tomorrow afternoon, see if I can't find anything... baffled though, really.
K this is going to be a huge PITA I can tell.
I adjusted the Virtual Directory for the default web site in Exchange System manager to point directly to /exchange, eliminating the need for anything after the :8888. It works fine in IE etc, quickly brings up a login prompt. Using the phone's IE and going to the works fine, prompts a login accordingly...
I configured a coworkers Blackberry to use our OWA and it works fine, but I'm not sure if it uses Push Email (Exchange ActiveSync).
What is it about the Dash that won't mesh? The server is not using SSL so I couldn't see it being a certificate issue (maybe it still is?). Is there anyone around who manages an Exchange Server and could perhaps shed some light on common settings that need to be adjusted for Exchange ActiveSync?
Such a nuisance
ActiveSync on the phone reports "The server could not be reached. Please verify the server name." Support code: 0x80072EE7
It reports back with this no matter how I enter the address (which again, works fine in IE). Devil phone
8888 is definetly not standard for publishing ActiveSync.
the software will connect to either MailServer:80 if the SSL checkbox is cleared or MailServer:443 if the checkbox is checked.
don't think you'll get ActiveSync connect to something else.
Why don't you change your port back to 80?
you are already exposing your server to internet without any form of protection (no SSL so your password can be sniffed over the network) and having port 8888 buys you nothing in terms of security since any port scanner will report the port as opened and eventually get the HTTP banner from the IIS Server.
So, get back to a standard config and you'll love your DASH again.

please help me fix my EXCHANGE server

hey guys,
am desperately trying to fix my home based exchange server. it's been running fine with 100% uptime since last december. about a week back i was twiddling with some settings in windows and completely destroyed it.
i lost my backup of the entier machine too (it's pretty much a dedicated box for exchange). hence did a rebuild.
however now i'm just not getting it to start up. symptoms:
- OWA (outlook web access) worked. both secure and insecure modes. works on my pc.
- does not work on my PDA - OWA works but no activesync
- disabled ssh and followed the instructions here
- the phone now gives error support code 85010004 "your account in microsoft exchange server does not have permission to synchronise with your current settings. contact your exchange server administrator."
kind of annoying!
- form based authentication is enabled
- basic authentication and integrated windows authentication are ON
- same error whether or not i require SSL.
any tips?
I occasionally get the exact same error message when I sync with my company's exchange server, I have to do a soft reset on the phone and then it works fine. No idea how to fix it so bump
we had quite a few issues originally and think this is one of them i think.
Most revolved around having a recognised accessible dns address that allowed a direct link.
never got ssl to work.
the other issue was getting appropriate certificates that were private to be issued when creating the sync partnership.
can u sync internally using exchange server via a cradled activesync?
get this 2 work first, then look to external push.
I ended up paying it engineers to get it to work over an sbs 2003 box as it was all to much.
but dns addresses being made public, that were also accessible internally (reverse lookup i think) along with no ssl and certificates being correct were our main hurdles.
issue fixed i'm all live! after all that effort i really feel i should open this up to those who don't want to spend days fixing it up...
check currently looking for testers for 1-2 days before i make a subscription based service!

SSL SMTP Mail Setup Wizard Problem

Got my desire yesterday, having defected from Windows Mobile and spent all yesterday and today getting very frustrated!!
I sucessfully set up my various email accounts - except one which requires a SSL outgoing SMTP server on port 465. When I put the correct settings into the setup wizard it simply fails to complete the account setup.
If I change any of the fields to an incorrect parameter, it gives an error but at least lets me save the settings and exit the wizard.
With the correct settings in place - it communicates with the server stating: "Verifying account information" and then promptly does nothing (it doesn't hang up, it just returns to the SMTP screen). The only way I can get out of the wizard is to enter an incorrect setting. This means that whilst receiving emails on this account is no problem, I am unable to reply to them or send any emails from this account.
I know there is nothing wrong with my ISP (T-mobile uk) because I am using the same SIM from my Touch-pro where this account worked fine for the previous 18 months.
Can anyone help please, before this very expensive piece of kit gets thrown out of the window
ricky173 said:
Got my desire yesterday, having defected from Windows Mobile and spent all yesterday and today getting very frustrated!!
I sucessfully set up my various email accounts - except one which requires a SSL outgoing SMTP server on port 465. When I put the correct settings into the setup wizard it simply fails to complete the account setup.
If I change any of the fields to an incorrect parameter, it gives an error but at least lets me save the settings and exit the wizard.
With the correct settings in place - it communicates with the server stating: "Verifying account information" and then promptly does nothing (it doesn't hang up, it just returns to the SMTP screen). The only way I can get out of the wizard is to enter an incorrect setting. This means that whilst receiving emails on this account is no problem, I am unable to reply to them or send any emails from this account.
I know there is nothing wrong with my ISP (T-mobile uk) because I am using the same SIM from my Touch-pro where this account worked fine for the previous 18 months.
Can anyone help please, before this very expensive piece of kit gets thrown out of the window
Click to expand...
Click to collapse
Hmm I had this issue where it wouldn't progress with the SSL option, and just kept verifying then doing nothing. I presumed it meant the server connection I needed wasn't actually SSL and switched to TSL and then it worked.
ricky173 said:
Got my desire yesterday, having defected from Windows Mobile and spent all yesterday and today getting very frustrated!!
I sucessfully set up my various email accounts - except one which requires a SSL outgoing SMTP server on port 465. When I put the correct settings into the setup wizard it simply fails to complete the account setup.
If I change any of the fields to an incorrect parameter, it gives an error but at least lets me save the settings and exit the wizard.
With the correct settings in place - it communicates with the server stating: "Verifying account information" and then promptly does nothing (it doesn't hang up, it just returns to the SMTP screen). The only way I can get out of the wizard is to enter an incorrect setting. This means that whilst receiving emails on this account is no problem, I am unable to reply to them or send any emails from this account.
I know there is nothing wrong with my ISP (T-mobile uk) because I am using the same SIM from my Touch-pro where this account worked fine for the previous 18 months.
Can anyone help please, before this very expensive piece of kit gets thrown out of the window
Click to expand...
Click to collapse
I got the same problem. It verifies and then goes back to the SMTP screen. Tried to change the security type from SSL to TSL to Nothing and still doesn't work. Only worked if I changed the port number to a wrong one which means I can receive but cannot send
I'm also having this issue. Very annoying!
I have opened a ticket with HTC over this and will let you know what they say...
I have the same problem. Reading another thread, this seems to come from the inability of Android to handle certificates properly. This is thread 663874 (for some reason the forum doesn't allow me to post the actual link) in this same sub-group.

Exchange DirectPush/ActiveSync not pushing

We run Exchange 2003 here. Push sync is apparently not working on our T-Mobile HTC Desires. The device makes no attempt to sync unless and until you visit the Mail app. We're due to be upgrading to Exchange 2010 this year but until then I'm wondering if anyone else has similar experiences or ideas for a workaround (other than changing to a 5 minute poll frequency).
Actually this seems to be just one of many things (e.g. buggy IMAP implementation) that's broken with the stock Mail app. Haven't tried a reboot yet but even if that fixes this for our phones, it's hardly a "fix"...
Go to Settings > Accounts & Sync and make sure 'Auto-sync' is checked. I was stumped for the better part of a week before I figured out why my Gmail/exchange push wasn't working - this was the reason.
Have you tried Touchdown to see if that works ok? Whilst it is a paid app, it is better suited to a corporate environment than the standard HTC offering.
@carrige: 'fraid not. Syncing is all set up correctly.
@foxmeister: Yes, TouchDown is on my radar. So far however, none of my users require Task syncing, which as far as I can see is the only particular feature advantage that TouchDown has over the HTC app (assuming the app works). Plus, TouchDown is uglier.
I appear to have found the solution though. It's obscure, so bear with me.
Ever since we started using DirectPush, our Exchange server has been logging errors along the following lines:
Event Type: Error
Event Source: Server ActiveSync
Event Category: None
Event ID: 3005
Date: 13/05/2010
Time: 11:32:22
User: OURDOMAIN\joe.bloggs
Unexpected Exchange mailbox Server error: Server: [ourserver.ourdomain.local] User: [[email protected]] HTTP status code: [400]. Verify that the Exchange mailbox Server is working correctly.
For more information, see Help and Support Center at
Click to expand...
Click to collapse
Push email and Outlook Web Access always worked fine, so I just filed this under "annoyances". Well, it transpires that the problem is down to a misconfiguration within IIS. From
Removed this error message by removing all host headers from the Default Website in IIS. Go to Properties for the default Website for IIS:
- Click on ''website'' tab.
- Click on ''advanced'' next to IP Address.
- Remove all headers except an entry for ''Default 80'' with no host header value.
Click to expand...
Click to collapse
Now, this doesn't make sense, since we enforce HTTPS on a custom port. Nevertheless, making this change has simultaneously stopped the annoyance logging, and resolved the push email problem on the HTC mail app.
Exchange Active Sync on HTC Desire stopped pushing
Hi Rob - got a similar problem that only started on Tuesday this week 11th and haven't been able to figure it out. Guess it must be EAS on 2003 on my home server as I haven't lost any other functionality on the phone (eg internet access data connection, SMS etc)
However I don't have the error 400 code on my server admin and trying the fix you suggested didn't work as there were no header to delete.
Any clues? Seems to be a widespread problem...? Thanks.
If you force a sync and look in your application/security logs, can you see the connection being made by the phone?
Fixed it
Rob - thanks for advice. I seem to have fixed the problem by deleting the acount and re-instating it. Not very scientific and doen't help understand whay it broke in the first place, but at least it work now.. Lets see how long it lasts.
BTW called Orange and whilst they were very helpful, they weren't aware of a generic problem.
Also, have now changed the APN setting which were mostly blanks so could have been these (or lack of them( that might have caused the problem.
Southbarn said:
Rob - thanks for advice. I seem to have fixed the problem by deleting the acount and re-instating it. Not very scientific and doen't help understand whay it broke in the first place, but at least it work now.. Lets see how long it lasts.
BTW called Orange and whilst they were very helpful, they weren't aware of a generic problem.
Also, have now changed the APN setting which were mostly blanks so could have been these (or lack of them( that might have caused the problem.
Click to expand...
Click to collapse
Interesting that you resorted to removing the account, I had to do the same when my HTC Desire stopped being able to send emails. Receiving was fine, but impossible to send. Deleted account and re-installed, problem resolved.
Only issue now, which is what I was searching for when I came across this thread, is that occassionally I get emails that simply will never arrive on the handset. At home I mix between WIFI and GSM connection, and push appears to work perfectly. Today I discovered that 3 or 4 internal corporate emails of 20 or more received during my manual sync off-peak period, just will not come down to the phone. They are on the server, on my laptop, but not on the phone. Touchdown, running in paralll to Android mail client, has them perfectly.
Any ideas anyone?
For me unfortunately the conclusion is absolutely inescapable. In a corporate environment, the niggles with the stock HTC mail app are unacceptable.
But the good news is that Touchdown is only $20, which really isn't that much to pay if you take into account the overall cost of whatever package your users are on. After a short trial of Touchdown, I'm going to start deploying it to my user base shortly.
Shame on HTC for releasing the phone to market with so many bugs. But I suppose that's what we get for being early adopters...

