App restrictions descriptions for Ivanti Email+ (Android Enterprise)
1 min
the app restriction described in the following table are available for email+ for android enterprise before configuring new restrictions, the user should update to the latest email+ application and then the administrator should configure new restrictions when there are multiple values available within a restriction, the different features should be specified as a list of comma separated strings, with or without a space a semicolon between them will not work restriction value enter/select one description email address substitution variable for email address required defines the email address for the email account ivanti epmm typically, enter $email$ you can also enter combinations of these variables, depending on your activesync server requirements $userid$, $user custom1$, $user custom2$, $user custom3$, $user custom4$ ivanti neurons for mdm typically, enter $ exchange host fqdn of the activesync server or standalone sentry required the fully qualified domain name (fqdn) of the activesync server or standalone sentry example mysentry mycompany com exchange username substitution variable for username required defines the username for the email account ivanti epmm typically, use $userid$ if your activesync server requires a domain, use \<domain name> \\$userid$ example mydomain\\$userid$ depending on your activesync server requirements, you can also use combinations of these variables $email$, $user custom1$, $user custom2$, $user custom3$, $user custom4$ ivanti neurons for mdm typically, use $ if your activesync server requires a domain, use \<domain name>\\$ example mydomain\\$ depending on your activesync server requirements, you can use $ email password the user’s password for the activesync server if you provide a password, email+ does not prompt the device user for the password recommends leaving this field blank ivanti epmm only you can use the variable $password$ if you have checked save user password in settings > preferences ivanti epmm then passes the user’s password as the value to the device if you plan to use the $password$ variable, be sure to set save user password to yes before any device users register if a device user was registered before you set save user password, email+ prompts the user to enter the password manually default if restriction is not configured user is prompted for activesync password device id (ivanti epmm only) $device uuid no dashes$ required ssl required check box select if you want secure communication using https to the server that you specified for exchange host default selected trust all certificates check box select to allow the app to automatically accepts untrusted certificates typically, you select this option only when working in a test environment default not selected prompt email password check box select to prompt the user for the email account password when the user attempts to launch email+ default not selected if the restriction is not selected, email+ provides the password to the activesync server when email+ connects with the server the activesync server counts the initial connection initiated by email+ as a password attempt therefore, recommends selecting this restriction if the email server allows only a small number of password attempts email login certificate ivanti epmm $cert alias\ certificate enrollment setting name$ ivanti neurons for mdm certificate setting from the dropdown list configure for certificate based authentication to the activesync server or to standalone sentry ivanti epmm the certificate enrollment setting name is the name you gave to the certificate enrollment setting, which is configured in configurations > add new > certificates or certificate enrollment ivanti neurons for mdm the certificate setting is configured in configurations > add > certificate or identity certificate for certificate based authentication, the authorization mode restriction must also be set to certificate based authentication email signing certificate ivanti epmm $cert alias\ certificate enrollment setting name$ ivanti neurons for mdm certificate setting from the dropdown list specifies the certificate to use for signing s/mime emails ivanti epmm the certificate enrollment setting name is the name you gave to the certificate enrollment setting, which is configured in configurations > add new > certificates or certificate enrollment ivanti neurons for mdm the certificate setting is configured in configurations > add > certificate or identity certificate email encryption certificate ivanti epmm $cert alias\ certificate enrollment setting name$ ivanti neurons for mdm certificate setting from the dropdown list specifies the certificate to use for encrypting s/mime emails ivanti epmm the certificate enrollment setting name is the name you gave to the certificate enrollment setting, which is configured in configurations > add new > certificates or certificate enrollment ivanti neurons for mdm the certificate setting is configured in configurations > add > certificate or identity certificate signing digest algorithm sha 1 sha 256 sha 384 sha 512 configures signature algorithm the restriction is empty by default if there is no value or invalid value set, then sha 1 is used email safe domains comma separated list of safe domains specifies the safe domains example mycompany com,mycompany net,internal mycompany com ensure that there are no empty spaces before and after the comma email addresses not in the safe domain list are displayed in red color in email+ you may want to use this key value pair if your company has multiple domains and you want to identify the company domains as opposed to domains that are not company domains to disable this feature, you can set the value to " " default if the restriction is not configured only the domain of the user's email address is considered safe all other domains will be highlighted in red allow logging check box select to allow email+ to log data in the android logging system if selected, the send logs and download logs options are available in email+ in general settings in the mail app device users can send log files via email+ by the tapping send logs option or download logs by tapping the download logs option the download option is useful if emails cannot be sent due to sync issues log data is useful for problem diagnosis typically, you select this option in a test environment default not selected allow export contacts to email check box select to give device users the option to export contacts as an attachment in an email default check box is selected allow detailed notifications checkbox select to allow device users see detailed notifications the details can include sensitive information such as email subject and body previews, or event titles and times default check box is not selected device users see normal notifications show picture by default checkbox select to allow device users to automatically see images in an email the setting turns on the \<font color="#323232">show pictures\</font> option on the device device users can override the configuration in the uem by turning the \<font color="#323232">show pictures\</font> option on or off on the device if you change the value, email+ does not change the show pictures option until email+ does a full synchronization a full synchronization occurs only when you change certain fundamental values like email address, or when the device user uninstalls and reinstalls email+ default check box is not selected the show pictures option is turned off default signature ivanti epmm $default$ ivanti neurons for mdm the default email signature the value entered is the default email signature for all emails however, the device user can override the default email signature at any time after the device user defines the default email signature, email+ does not use the value entered in this field, even if the value is updated for ivanti epmm, with $default$, the system default is used if $default$ is not configured, a signature is not provided default if the restriction is not configured (system default) sent by email+ gal search minimum characters a number the minimum number of characters for email+ to use for automatic global address list (gal) lookup in mail and contacts when entering a name, after the specified number of characters, email+ starts searching the gal and presents the matches that it finds on your exchange server, set the minimum number of characters for gal search to the same value you set for this key if you do not, gal search will not work properly in email+ default 4 max attachment size (mb) a number specifies the maximum size in megabytes of an email that email+ will send without a warning to the device user the maximum size includes the body of the email plus its attachments also applicable for delegated mailbox allowed values are integers starting with 1 if the exchange server has an email size limit that is less than the maximum size entered, the exchange server does not deliver the email default 10 mb max mail body size a number specifies the maximum limit for email message body size that can be received by the email+ app default 4 mb default sync period 1 2 3 4 5 specifies the default period for which emails are downloaded 1 emails received over the last one day 2 emails received over the last three days 3 emails received over the last seven days 4 emails received over the last two weeks 5 emails received over the last one month if configured, all options will be available in email+ device users can change the default value if the max sync period restriction is also configured, options greater than sync period specified in the restriction will not be available on the device default 2 max sync period 0 1 2 3 4 5 specifies the maximum number of days for which emails are downloaded 0 all emails 1 emails received over the last one day 2 emails received over the last three days 3 emails received over the last seven days 4 emails received over the last two weeks 5 emails received over the last one month default 0 disable usage statistics checkbox disables sending email+ analytics default unchecked optional features block external gal skip empty links show formatting multiple accounts allow shortcuts calendar delegation entrust certificates smime suppress certificate email check delegated shared mailbox calendar folders microsoft teams meetings graph api block external gal disables global address lookup (gal) of email+ contacts in the native contacts app configure the value only if the google account configured for android enterprise supports gal skip empty links some exchange servers block custom links and the hyperlinks are stripped from the email body for example, the url mibrowser // that is used to launch web\@work and may not become click able when sent via email the work around for this problem is, email+ has additional capability to detect such emails and automatically fetch their body as mime data that is unmodified by exchange we recommend that administrators evaluate this capability in their environment by adding "skip empty links" into the "enabled features" kvp fetching mime data may not work in all configurations show formatting enables the “always show formatting” option if it was not previously changed manually multiple accounts enables secondary email account on the same device allow shortcuts enables the user to create shortcuts for launch calendar, contact, notes, and tasks calendar delegation enables the add delegated calendar option entrust certificates enable support for entrust certificate for android enterprise cloud the email+ app now fetches these certificates from the keystore this is applicable for android enterprise device registration mode such as profile owner, device owner, and epo with microsoft office 365 using modern auth the email+ android enterprise apps uses the certificates is as follows authorization cert this certificate is used to login to the email+ app signing /encryption this certificate is used for smime functionality smime suppress certificate email check automatic certificate verification using email address is suppressed and the user can manually add a certificate using the keystore and galoptions delegated shared mailbox delegated shared mailbox enables the delegated mailbox option when this value is removed all added delegated mailbox accounts are removed from email and setting's screen " add a mailbox " button is removed under email screen and setting's screen if only primary account is added then the arrow to expand and collapse to show different mailbox's and add a mailbox label are also removed if secondary account is available then arrow to expand and collapse to show different mailbox's will be available but add a mailbox label is not available calendar folders syncs all the calendar folders and their events to the primary account this feature is currently available for the primary mail account microsoft teams meetings to enable microsoft teams in the calendar settings graph api to enable microsoft graph api for delegated and shared mailbox and calendar functionality disabled features save attachment print show snippet personal events crl signature check eas 16 save attachment disables the save attachments option when this value is added the "save as" button is not available for email attachments attachments can still be opened in docs\@work print disables the print option for email messages show snippet this option removes "text preview" setting and disables message preview displaying if this option is enabled the user can set the number of lines visible for message preview, through email+ app settings on the mobile device by default the number of lines set for preview is set to two personal events disables the "overlay personal events" option in the calendar settings by admin crl signature check disables crl check for the email signature certificates eas 16 disables support for exchange activesync16, default network timeout a positive integer the value is represented in seconds the value overwrites the default connection timeout value for all requests you may want to configure the key value pair to manage slow connections with the activesync server or for syncing large folders and emails if the value is 0, negative, or non integer, the default value is used default 90 seconds authorization mode basic authorization certificate based authentication modern authentication defines the authentication method to the exchange activesync service basic authorization user name and password certificate based authentication identity certificates modern authentication enable modern auth for corresponding protocol enables oauth 2 0 authorization modern auth authority url and modern auth resource url when configured through sentry uses the following values modern auth authority url https //\<sentryhostname>/proxyservice modern auth resource url https //\<sentryhostname> for certificate based authentication, the email login certificate restriction must also be configured if you have configured certificate based authentication and there are errors in your configuration, the authentication method defaults to basic default basic authorization alert unsafe domains checkbox select to alert email+ users if the recipients in an email or calendar invite include addresses that are not in a safe domain if the restriction is configured, but safe domains (email safe domains) are not configured, only the domain of the user's email address is considered safe device users have the option to either proceed or cancel sending the email default not selected an alert is not displayed for addresses not in a safe domain show dialing confirmation checkbox select to present a confirmation dialog when users tap on a phone number in an email tapping on the phone number in the dialog, dials the phone number tapping the back arrow cancels the call default if no key value is configured not selected users do not see a confirmation dialog when a user taps on a phone number in email+, the number is automatically dialed display order first last last first sets the default display order for contact names in search results device users can change the display order in email+ in settings > contacts first last contact names in search results are displayed with first name followed by the last name last first contact names in search results are displayed with last name followed by the first name default first last use display name true false true enables display name in email+ settings > contacts by default false disables display name in email+ settings > contacts by default default true modern auth authority url https //login microsoftonline com/common this is enabled to specify microsoft office 365 authority url modern auth resource url https //outlook office365 com this is enabled to specify microsoft office 365 resource url security classification json default value for this key is empty enables the email classification feature if present, it specifies the list of classification values to be used and all the supported permutations see document classification capabilities section for more information allow certificate revocation check true false this is enabled to check certificate validity the crl check for server certificate is performed when allow certificate revocation check is set to true and trust all certificates is set to false allow files from personal apps true false enable this option to allow import or add attachments from personal profile applications for example, importing certificates from storage or attaching images from photo gallery report phishing email address enable the 'report phishing' option on view screen in the "more" menu the suspicious mail is deleted and sent to a pre configured (for security review) email address organize by date true false disables email treading for email messages false "email threading” is turned "on" show week number true false displays the week number in the week and month view for calendar you can enable or disable week number view from device settings default true exchange host for ews fqdn of the ews server to support ews authentication when exchange host restriction contains not the fully qualified domain name (fdqn) of the ews server, exchange host for ews restriction should have a fdqn as the value for the ews server if not configured, the value of exchange host restriction is used as the ews server ews authentication mode basic authentication modern authentication certificate based authentication defines the authentication method to the ews basic authentication username and password modern authentication enable modern auth for corresponding protocol enables oauth 2 0 authentication certificate based authentication support delegated calendar with certificate based authentication default basic authentication (optional) encryption algorithm 3des (currently used by email+, the most compatible and default) aes256 aes192 aes128 configures encryption algorithm the restriction is empty by default if there is no value of invalid set, then 3des is used calendars sync period 0 sync all events 1 sync events for one month 3 sync events for three months 6 sync events for six months calendars sync period is added to sync all calendar events matching the sync period provided in email+, with default value set to 1 for syncing one month calendar events msal client id replaces the default application id used by the microsoft authentication library (msal) with a custom value msal resource scope defines the resource scope required by msal to acquire access tokens for protected resources specify the multiple scopes with a single comma separated string (for example, user read, mail read, and so on) exchange graph host email graph host graph microsoft com this key allows the admin to enable or disable graph api operations cns host for graph notification server host https //cns mobileiron com/prod enabled delivery of notifications for delegated mailbox and calendar activities through microsoft graph
