Monitoring Benefit
The ActiveSync FolderSync Command test goes a step further than the HTTP OPTIONS test. Where OPTIONS only confirms the server answers and advertises its protocol versions, FolderSync authenticates as the test mailbox and retrieves its folder hierarchy — the first thing a real device does after connecting.
That makes the pair diagnostic when read together:
- OPTIONS passes, FolderSync fails — the service is reachable but the mailbox conversation is failing. Authentication, mailbox policy, or the account itself.
- Both fail — nothing is getting through. Treat it as connectivity and start with the path, not the mailbox.
This is the same test as Exchange Online - ActiveSync FolderSync Command Status, run from a remote probe rather than from the ENow web server.
Why the probe version matters
A probe tests the path your users actually take from their own site — its internet egress, proxy, firewall and DNS — rather than the clean data-centre path the ENow server enjoys. Comparing results across contexts is the fastest way to localise a fault:
| Pattern | What it points at |
|---|---|
| Fails everywhere, including the ENow server | Exchange, the namespace, or the test mailbox. |
| Fails from one probe only | That site's network path. |
| Fails from every probe but not the server | Something shared by the probe path — a common proxy or firewall policy. |
Status 138 (BadVersion)
If this test is failing with status 138, reported as Bad Version, and holding the dashboard in a red state, there is a known cause and it is not your environment.
Microsoft now blocks Exchange ActiveSync clients below protocol version 16.1 from connecting to Exchange Online. That change caused the FolderSync command test to fail with status 138 and raise alerts even where ActiveSync was working normally for real devices.
The test was updated in EMS 8.7 to align with Microsoft's requirement, and no longer raises these false alerts. If you are seeing status 138 on a version below 8.7, upgrading is the fix — there is no configuration change that resolves it, and no protocol setting on your side that needs adjusting.
How do we verify the monitoring test results?
- Run the Microsoft Remote Connectivity Analyzer from the probe's location — testconnectivity.microsoft.com, Exchange ActiveSync test. Running it from the ENow server tests the wrong path.
- Sign in as the test mailbox and confirm the account is healthy and not blocked, quarantined by mobile device policy, or subject to a device approval requirement.
- Test a second mailbox to separate an account-specific problem from a site-wide one.
- Confirm the probe is reporting — see Remote Probe - Connectivity Status. A probe that has stopped checking in turns its indicators red and says so on the detail page, so check there before working the test itself.
Where the settings are
Probe test accounts are configured under Server > Tuning Policy > Settings > Probe Configuration > Configure Probes…. Probe thresholds are separate from the server-side ones and live under Server > Monitoring Policy > Thresholds in the Remote Probes section.
One setup detail catches people out: the ActiveSync test account may need both its UPN and its email address configured, and they are not always the same value. If FolderSync fails immediately with an authentication error on a newly configured probe, check that first.
Where this is shown in the console
This check appears under Exchange Remote Probes > ActiveSync, which you can open directly:
https://<ENow web server>:20080/MailscapeWeb/Exchange/ExchangeActiveSyncRemoteProbe.aspx?server=<PROBE>
The probe name in the query string carries a suffix — for example LONDON-EXCHANGE rather than LONDON. You can also reach the page by selecting the probe's row under Exchange Remote Probes on the dashboard at /MailscapeWeb/Default.aspx.
Common warning or error results, and potential solutions
| Result | Potential solution |
|---|---|
Status 138, reported as Bad Version |
Microsoft blocks ActiveSync clients below protocol version 16.1 from Exchange Online. Resolved in EMS 8.7 — see the section above. Upgrading is the fix; there is nothing to reconfigure. |
| OPTIONS passes but FolderSync fails | Reachability is fine — work the mailbox. Check credentials, mobile device mailbox policy, and whether the account requires device approval. |
| Authentication failure on a new probe | Check the test account's UPN and email address are both correct for this test. |
| Fails after a password change | The probe holds its own copy of the credentials. Update them in Configure Probes… — changing the account password alone does not update the probe. |
| Certificate errors from one site | TLS inspection at that location. Exempt the namespace or trust the appliance certificate on the probe. |
| Slow but succeeding | Compare latency against other probes. A single slow site is usually its own link or proxy rather than Exchange. |
Reference: Exchange ActiveSync | Microsoft Learn
Comments
0 comments
Article is closed for comments.