Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Free Fix HTTP 500

HTTP 500 on Microsoft-Server-ActiveSync: every mobile device stops syncing

11 min read Updated October 4, 2026 Exchange Server

Fix it now

When every phone stops syncing within the same few minutes, the phones are not the problem. HTTP 500 means the ActiveSync application ran and threw; HTTP 503 means nothing was there to take the request, which is normally a stopped or rapid-failed application pool. Both are fixed on the server, and devices resume on their own.

Elevated Exchange Management Shell on the affected server

Get-WebAppPoolState MSExchangeSyncAppPool
Start-WebAppPool MSExchangeSyncAppPool
Get-ActiveSyncVirtualDirectory | Format-List Server,InternalUrl,ExternalUrl
Get-MailboxDatabaseCopyStatus *
Test-ServiceHealth
  1. Browse to https://<your namespace>/Microsoft-Server-ActiveSync from the server itself. An authentication prompt is healthy; an immediate 503 means the application pool is not running.
  2. Start the sync pool and watch whether it stays up for five minutes. A pool that stops again is crashing, and rapid-fail protection will then answer 503 to everything.
  3. Check free disk space on every Exchange volume. A full logging or transport volume takes application pools down before it takes anything else down.
  4. If devices are looping rather than failing, look for HTTP 449 in the IIS log: that is provisioning, not an outage, and the fix is in the mobile device mailbox policy.
  5. Read the MSExchange ActiveSync entries in the Application log around the failure and work from their text rather than from the event number.

Do not tell users to remove and re-add their accounts while the server is broken. It creates a fresh partnership per device, a burst of full resynchronisation when the server recovers, and a pile of stale partnerships to clean up.

If devices start syncing again, stop here. If they do not, the next section follows a request through the server and shows where each status is produced.

Why it happens

A device connects to the ActiveSync path on the Default Web Site, authenticates there, and the front end proxies the request over HTTPS to the Exchange Back End site on the server holding the active copy of that mailbox’s database. Any hop can fail, but the device only ever sees the status the front end hands back, which is why a dismounted database and a broken IIS configuration look identical from a phone.

503 and 500 separate two very different situations. Microsoft’s published description of 503 is that the server is temporarily unable to handle the request; on an Exchange server that means the request could not be handed to an application at all, because the pool is stopped or IIS has shut it down under rapid-fail protection after repeated worker crashes. 500 is published as the server encountering an unexpected condition that prevented it from fulfilling the request: the application took the request and then failed.

HTTP 449 is not an error. The Exchange ActiveSync protocol documentation states that when protocol version 2.5, 12.0 or 12.1 is in use, a 449 is returned in place of status 140 RemoteWipeRequested, 141 LegacyDeviceOnStrictPolicy, 142 DeviceNotProvisioned, 143 PolicyRefresh or 144 InvalidPolicyKey. Every one of those is a provisioning or policy condition, so a device looping on 449 has a policy it cannot satisfy rather than a server that is down.

The codes the device shows are coarser than the ones in the IIS log, but Microsoft does publish them. 0x85010014 maps to E_HTTP_SERVER_ERROR with the user-facing text “Can’t connect to the server”. 0x85010004 maps to E_HTTP_FORBIDDEN – “Can’t connect to the server right now. Wait a while and try again, or check the account’s settings.” That second one matters: it is a 403 from the server, not a network failure, so it sends you to device access rules and the mailbox’s ActiveSync state rather than to the firewall.

The application pool is stopped or keeps dying

You have this one if Immediate 503 for every device, and the sync pool shows as Stopped or stops again within minutes of being started.

  1. Start it with Start-WebAppPool MSExchangeSyncAppPool and check its state again five minutes later.
  2. If it stops again, look for the worker process failure in the Application log and for Event ID 5011 from the Windows Process Activation Service in the System log.
  3. Check the pool’s identity and .NET version have not been altered from what Exchange configured.
  4. Fix the crash rather than raising the rapid-fail limits, which only hides how often it is happening.

A volume has filled

You have this one if Several application pools misbehave at once, mail flow slows or stops, and a drive holding logs or transport queues is at zero free space.

  1. Check every Exchange volume, not just the database drives.
  2. Clear old IIS logs and old Exchange logging files, keeping whatever retention you are required to hold.
  3. Restart the affected pools once space is back, or run iisreset /noforce if several are stuck.
  4. Add scheduled housekeeping, because Exchange logging grows without limit by default and this returns otherwise.

The virtual directory or its authentication was changed

You have this one if HTTP 500 for everyone, starting right after a cumulative update, a hand edit or a hardening exercise.

  1. Compare the settings against a healthy server: Get-ActiveSyncVirtualDirectory | Format-List Server,InternalUrl,ExternalUrl,*Authentication*.
  2. Confirm the internal and external URLs are populated and match names the certificate covers.
  3. If the configuration is wrong and you cannot say why, recreate it with Remove-ActiveSyncVirtualDirectory and New-ActiveSyncVirtualDirectory, using -Role to target the front end or back end copy.
  4. Run iisreset /noforce, set the URLs again and retest.

Record the current URLs and authentication settings before removing anything. Recreating discards all of them.

The back end cannot serve the mailbox

You have this one if HTTP 500 for a subset of users who turn out to share a database, or for everyone when one database holds most mailboxes.

  1. Check database state with Get-MailboxDatabaseCopyStatus * and mount anything dismounted.
  2. Confirm the mailbox server holding the active copy is healthy with Test-ServiceHealth and Get-ServerHealth.
  3. In IIS Manager, confirm the Exchange Back End site still has a certificate bound to its HTTPS port.
  4. Test a single mailbox end to end rather than judging from a phone.

Devices are stuck in a provisioning loop

You have this one if The endpoint answers, the IIS log shows 449 responses repeating, and no application error is ever recorded.

  1. Read the policy that applies: Get-MobileDeviceMailboxPolicy. A policy requiring something the devices cannot do produces exactly this.
  2. Check organisation-level device access settings and any device access rules that may be quarantining or blocking a device family.
  3. Allow or release the affected devices, then let one complete a full synchronisation before judging the change.
  4. Check Get-CASMailbox <user> | Format-List ActiveSyncEnabled,ActiveSyncBlockedDeviceIDs for a mailbox that is failing on its own.

Full reference

Sorting the symptom before touching the server

What you see Where to work
503 immediately, for everyone The application pool is stopped or in rapid-fail protection
500 for everyone The application is running and failing: configuration, disk, or the back end
Devices loop on 449 Provisioning and the mobile device mailbox policy
A device reports 0x85010004 E_HTTP_FORBIDDEN. The server answered with a 403: device access rules or the mailbox’s ActiveSync state
A device reports 0x85010014 E_HTTP_SERVER_ERROR. The server-side failure above, seen from the device
One mailbox only That mailbox, its device partnerships or its database
External devices only The published URL, the reverse proxy or the certificate chain

Where each status is produced

Status Published meaning Produced by
500 The server encountered an unexpected condition that prevented it from fulfilling the request The ActiveSync application, or the back end it proxied to
503 The server is currently unable to handle the request due to temporary overload or maintenance IIS, before the request reaches any application
449 Returned in place of ActiveSync status 140, 141, 142, 143 or 144 on protocol versions 2.5, 12.0 and 12.1 The provisioning layer, deliberately

The device-side codes Microsoft publishes

Code Mapping User-facing message
0x85010014 E_HTTP_SERVER_ERROR Can’t connect to the server
0x85010004 E_HTTP_FORBIDDEN Can’t connect to the server right now. Wait a while and try again, or check the account’s settings

Microsoft’s guidance for both is to verify the server name first. For the forbidden case it adds a second check that is easy to miss: where the account uses certificate-based authentication, confirm the certificate is still valid and replace it if not. That is a genuinely different investigation from a 500, and the two codes are one digit apart.

Testing the endpoint properly

  • Test-ActiveSyncConnectivity is the Exchange cmdlet for this, and it takes -ClientAccessServer, -URL or -MailboxCredential for a single mailbox. Microsoft’s own reference notes that it works best on Exchange 2010 and that Managed Availability supersedes it on later versions, recommending Invoke-MonitoringProbe instead, so treat a clean result as one data point.
  • The Microsoft Remote Connectivity Analyzer tests from outside your network, which is the only way to see what a device on a mobile network sees.
  • Get-MobileDeviceStatistics -Mailbox <user> tells you when a real device last synced successfully, which is more honest than a synthetic test.
  • Reading the IIS log directly and filtering the sc-status column for anything other than 200 remains the fastest way to see the pattern across all devices at once.

The event with no published description

Event ID 1008 from the MSExchange ActiveSync source turns up around these failures and Microsoft publishes no description for it. Read the entry rather than the number: the description field carries the component and the exception, which is what you need. Be wary of search results for “Event ID 1008” in particular, because a Perflib event with the same number and a completely different meaning dominates them.

When it is one mailbox rather than the server

  • Check the mailbox’s own ActiveSync state: Get-CASMailbox <user> | Format-List ActiveSyncEnabled,ActiveSyncBlockedDeviceIDs,ActiveSyncMailboxPolicy.
  • Check whether a device access rule or the organisation’s default access level is quarantining the device family.
  • Check whether the mailbox has accumulated a large number of stale device partnerships, and remove the ones for devices that no longer exist.
  • Check the user’s Active Directory object for the permission problem that produces Event ID 1053, which is a different article and a different fix.
  • Only then move the mailbox, which is a large hammer for a problem that is usually a permission or a policy.

Every code this article covers

Code What it points at Source
HTTP 500 Internal server error: the server encountered an unexpected condition that prevented it from fulfilling the request Microsoft Learn
HTTP 503 Service unavailable: the server is currently unable to handle the request due to temporary overload or maintenance Microsoft Learn
HTTP 449 Returned in place of ActiveSync status 140, 141, 142, 143 or 144 on protocol versions 2.5, 12.0 and 12.1. A provisioning instruction, not a fault Microsoft Learn
Event ID 1008 An MSExchange ActiveSync entry logged around request failures. Microsoft publishes no description; read the event’s own text not published by the vendor
0x85010014 E_HTTP_SERVER_ERROR, shown to the user as “Can’t connect to the server” Microsoft Learn
0x85010004 E_HTTP_FORBIDDEN, shown as “Can’t connect to the server right now. Wait a while and try again, or check the account’s settings”. The server answered with a 403 Microsoft Learn

Confirm the fix worked

  1. Browsing the ActiveSync path from the server returns an authentication prompt rather than an error page.
  2. The sync application pool is running and is still running an hour later.
  3. Get-MobileDeviceStatistics -Mailbox <user> shows a recent successful sync for a real device.
  4. The IIS log for the ActiveSync path shows 200 responses rather than 500, 503 or repeating 449.
  5. A second mailbox on a different database syncs as well, which rules out a single database.

Questions people ask about this

Do I need to buy anything to fix this?

No. Every cause here is configuration or capacity on a server you already license. Mobile device access is part of Exchange; there is no separate mobility licence for on-premises ActiveSync.

Should I tell users to remove and re-add their accounts?

Not while the server is broken. It creates a fresh partnership for every device, a burst of full resynchronisation when the server recovers, and a pile of stale partnerships afterwards. Fix the server and let the devices reconnect.

Why did it break at exactly midnight?

That is the signature of a disk filling or a scheduled job. Log rotation, a backup that failed to truncate, or a maintenance task that ran long are the usual suspects.

What does 0x85010004 actually mean?

Microsoft maps it to E_HTTP_FORBIDDEN, so the server answered the device with a 403. Look at device access rules, the mailbox’s ActiveSync state and, where certificate-based authentication is in use, whether that certificate is still valid. It is not a network failure.

Is a device looping on 449 broken?

No. A 449 is the protocol telling the device to provision and retry, and it is returned in place of the provisioning status values on older protocol versions. A loop means the device cannot satisfy the policy, so look at the mobile device mailbox policy rather than at the server.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

License Error MapiExceptionTooManyMountedDatabases: Standard Edition hits its database cap Free Fix Error -1216 attached database mismatch and other mount-time JET failures Free Fix Event ID 41 in MSExchange OWA: something went wrong loading OWA or ECP License Error 452 4.3.1 insufficient system resources: Exchange back pressure explained
โ† Back to Knowledge Base