Microsoft - Exchange - Notes - ActiveSync

Exchange 2010, ActiveSync, and protected groups

With Exchange 2010 members of the Domain Admins group, by default, can no longer synchronize with an ActiveSync device.

This is done in the interest of security.

You can work around this with one of:

  1. Ensure that “Include Inheritable Permissions From This Object’s Parent” is set on the account: link.
    1. Repeat when setting up a new device to sync with ActiveSync.
  2. Mess with the properties of “CN=AdminSDHolders,OU=System,DC=yourdomain,DC=com” with ADSIEdit: link.

Both options result in a non-standard AD configuration so neither option is recommended.

The best option is to remove the users account from the Domain Admins group and create a separate account with Domain Admins membership. The users original account might then still need to be modified to make ActiveSync work: link.

Sources:
Mark Iwaszko's technical blog - Exchange 2010 ActiveSync not function for Domain Admins user
Share iT... - Exchange 2010 activesync doesn’t work domain admin group members
serverfault - Allow ActiveSync to former domain administrator in Exchange 2010
Microsoft TechNet Forums - Making ActiveSync work with a Domain Admin

See also:
TechNet Magazine > Home > Issues > 2009 > September > AdminSDHolder, Protected Groups and SDPROP