joanie_wexler
Writer

Holiday phone flood could test enterprise security

Opinion
Dec 8, 20092 mins

Options for plugging ActiveSync security holes

By the time we’re all singing Auld Lang Syne, another 50 million smartphones will have joined the worldwide business environment during the year, according to IDC. Many will likely be Apple iPhones received as holiday presents. These “rogue” devices can worm their way onto your corporate network via the ActiveSync protocol.

The iPhone isn’t the only mobile phone that supports ActiveSync, which allows mobile users to synchronize their devices with e-mail, calendar, and contact info in their Exchange mailboxes. Windows Mobile and Symbian devices support the protocol, too. But the popular iPhone is the one most likely to sneak into the enterprise in volume after the holidays.

8 ways to expense an iPhone

ActiveSync is enabled by default for all users on Microsoft Exchange servers and many organizations leave it turned on. That means that users with ActiveSync-enabled phones can generally point them at the Exchange server and get into the corporate network without much fanfare other than perhaps a password.

In addition to enforcing the use of complex passwords or disabling the feature altogether (defeating its purpose), there are other alternatives for plugging the potential ActiveSync security hole, too.

For example, start-up MobileIron supports a feature called ActiveSync Sentry in its MobileIron mobility management products.

The software detects “all the devices trying to connect via ActiveSync,” explains CEO Bob Tinker. “We make [deny/allow] decisions based on who the user is and whether proper security policies are supported. For example, enterprises may only want iPhone 3G S phones connecting because those are encrypted.”

He adds that ActiveSync Sentry can detect whether an iPhone has been modified or jailbroken and, if so, block it from the network.

Symantec is also beefing up its suite of mobile security products and one component addresses the ActiveSync issue similarly. The company’s Network Access Control (NAC) Mobile Edition evaluates each attempted connection to the Exchange server and “if it doesn’t have proper security software or configurations, we’ll block it, even if it’s a legitimate employee,” says Khoi Nguyen, group product manager for mobile security at Symantec.

NAC Mobile Edition lists for $29.99 per internal corporate device you want to manage, and the server component comes free with it. The server component provides a “way of keeping rogue ActiveSync devices out of the enterprise,” he says.

joanie_wexler
Writer

Joanie Wexler is an independent writer and editor who has spent 20+ years writing about computer networking technologies, their business potential, and implementation considerations. She serves clients at technology companies and industry publications writing educational materials on all aspects of IT.

More from this author