Exchange Server - Device Wipe in ActiveSync Mobile Admin

Asked By M
01-Feb-10 04:59 PM
Hello:

I have been looking for info on what exactly gets wiped and the wiping
algorithm. So far the best info I found was from the article below. I still
need some clarification on the following:

1.) Does the remote wipe algorithm meet any accepted IT security standards
(DoD, NSA, et al.)?
2.) With Exchange Server 2003 SP2, does the remote wipe on a Windows Mobile
6 device also wipe removable storage card, or is this feature only on
Exchange Server 2007?

http://technet.microsoft.com/en-us/library/cc182279.aspx

Local and Remote Device Wipe

When a mobile device is lost or stolen, the potential security risk can be
significant. Mobile devices often contain sensitive business data, including
personally identifiable information of employees and customers, sensitive
e-mail messages, and other items. Exchange ActiveSync helps address this
risk by providing two levels of device wipe capability for Windows Mobile
5.0 powered devices with MSFP or later.

Wiping the device locally or remotely has the effect of performing a factory
or "hard" reset; all programs, data, and user-specific settings are removed
from the device. The Windows Mobile device wipe implementation wipes all
data, settings, and private key material on the device by overwriting the
device memory with a fixed bit pattern, greatly increasing the difficulty of
recovering data from a wiped device.

Note:
Device wipe in Windows Mobile 6 includes wiping the removable storage card.

--
Thank you.

Regards,
M
MCTS, MCSA
Windows Mobile 5.0
(1)
Exchange Server 2007
(1)
Exchange Server 2003
(1)
ActiveSync
(1)
Firmware
(1)
Wipes
(1)
MSFP
(1)
MCSE
(1)
  Rich Matheisen [MVP] replied to M
01-Feb-10 11:34 PM
That really depends on the device and the firmware/software it is
running. You'd probably get a better answer to the question in a forum
the focuses on the devices themselves.
---
Rich Matheisen
MCSE+I, Exchange MVP
  M replied to Rich Matheisen [MVP]
03-Feb-10 09:49 AM
I am surprise that I could not find more info about this. It seems like a
security hole if the wiping algorithm is not that good and the wiped data
could be easily recovered.

--
Regards,
M
MCTS, MCSA
help
Exchange Server Error after installing Forefront I just installed ForeFront on an Exchange 2007 with Transport Hub role on it. After I reboot, "Exchange Transport Service" fails to start, because it's dependant on FESIMC service, which doesn't start. I've tried it Windows 2003 with and without SP2, and I get the same thing. I've installed the hotfix rollup for Exchange 2007. Any idea? Hi, Any error message when trying to start the FESIMC service? Leif
Exchange Server Exchange SCR included with Exchange Server Does Exchange SCR included with Exchange Server 2007 Beta 1 require Windows Clustering or does it work independant of Windows clustering? In
Exchange Server Outlook 2007 with Exchange and foreign addresses to the GAL- "One or more parameter values are not valid" This a problem that I have isolated as best as I can. I'm using = Outlook 2007 against an Exchange Server (I don't know what version). = When initiating a new email message or replying to an email address = outside of the Exchange GAL I get the error "Could not complete the = operation. One or more parameter values
Exchange Server Exchange Server component Client Access Role failed. I am getting this error installing exchange 2007 on x86 hardware. I cannot find my exchange 2003 server on the domain. . . Event Type: Error Event Source: MSExchangeSetup Event Category: Microsoft Exchange Setup