Update September 27, 2017 – Apple iOS 11 Breaks Windows Server 2016 and Exchange 2016

by Michael Bianchi, Senior Systems Engineer

Update September 27, 2017: Apple has released iOS version 11.0.1 which includes a fix. Download here: https://support.apple.com/en-us/HT208136.

Today, September 19, 2017 Apple has made their highly anticipated release of Apple iOS version 11 available for general download and installation. There is a current incompatibility with iOS 11 communication to Windows Server 2016. This is a problem with iOS devices using ActiveSync communication to Microsoft Exchange 2016, hosted on Windows 2016 server OSes. A fix may be introduced in a future OS build, but there is no current indication of timing.

The root of the issue involves iOS 11 negotiating using HTTP/2 TLS connections by default, instead of trying HTTP/1.1 and then attempting HTTP/2; which is supported in Windows Server 2016.

 

As a temporary workaround, make the following registry changes on all Microsoft Exchange 2016 Servers running on Windows 2016 as seen in this Microsoft Support Article (4032720):

https://support.microsoft.com/en-us/help/4032720/how-to-deploy-custom-cipher-suite-ordering-in-windows-server-2016

 

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters

EnableHTTP2Tls = 0 (REG_DWORD)

  • Default is 1

EnableHttp2Cleartext = 0 (REG_DWORD)

  • Default is 1

A server restart is required after making changes to take effect. This modification should allow for ActiveSync access of newly, updated Apple iOS 11 devices.

Please contact Helient if you require any assistance with iOS 11 and Windows Server 2016 compatibility.