Configure Microsoft IIS permissions for gatekeeping
- If your organization uses Microsoft Exchange Server, see Configure Microsoft Exchange to allow only authorized devices to access Exchange ActiveSync.
- If your organization uses Microsoft 365, see Configure the mobile device access policy in Microsoft 365.
- On the computer that hosts the Microsoftclient access server role, open the Microsoft Internet Information Services (IIS) Manager.
- In the left pane, expand the server.
- Expand Sites > Default Web Site.
- Right-click the PowerShell folder. Select Edit Permissions.
- Click the Security tab. Click Edit.
- Click Add and enter the <new_group> that was created when you configured the Microsoft Exchange permissions for gatekeeping.
- Click OK.
- Confirm that Read & execute, List folder contents, and Read are selected. Click OK.
- Select the PowerShell folder. Double-click the Authentication icon.
- Select Windows Authentication. Click Enable.
- Close the Microsoft Internet Information Services (IIS) Manager.