Delegated mailbox
9 min
ivanti email+ supports delegated access for mailbox currently, we support delegation of up to four mailboxes in case of multiple mailboxes, each mailbox is independent and has its own delegated mailbox account settings when configuring the mailbox delegation, the owner delegates mailbox to another user (delegate) to manage it as per delegation level set on outlook the delegated user can add upto four delegated mailboxes from multiple owners \<font color="#000000">when multiple accounts are available then only mailboxes delegated to primary account can be added to email+\</font> to configure delegated mailbox on android appconnect or android enterprise , configure the following key value pairs or restrictions add delegated shared mailbox value to enabled features key value pair or to optional features restriction to add the add mailbox option in the email+ app when you select the add a mailbox option, email+ searches email address in gal and provides list of contacts to add mailbox if the search result is successful, the 'mailbox added ' pop up is displayed and delegated mailbox is added once delegated mailbox is added, the add mailbox option appears in the navigation drawer and settings email+ supports delegated mailbox permissions similar to microsoft exchange server such as reviewer, editor, and author level permissions ivanti email+ 4 7 0 supports only 'reviewer' level permission starting ivanti email+ 4 10 0 all permissions levels are supported in email+ delegated user can now save draft mail in the delegated mailbox the delegated drafts folder is not synced with the server and only available locally delegate can store draft emails in " drafts " folder these folders are local and are not synced with the server delegated mailbox with reviewer permission can perform the following actions mark as unread or read download and view attachments from mail or invite mails search of the delegated mails is out of scope for email+ 4 7 0 release all the folders are auto synced when the user clicks on each folder to start and stop the sync the delegated user can manually delete the delegated mailbox added from the email+ app microsoft server does not provide any permissions to load sub folders and doesn't return in requests for the sub folders synchronization so sub folder in the inbox is not displayed for added delegated mailbox of such accounts in email+ as well as on outlook the mailbox owner can change permissions from any role (reviewer/author/editor) to any role (reviewer/author/editor), also for existing drafts when the owner revokes access to delegated mailbox completely, or the user removes the delegated mailbox manually from the email+ settings, related drafts folder is removed with all its content when the owner revokes access to delegated calendar, all related drafts from the "delegated drafts", delegated mailbox "drafts", and outbox (if any emails are stuck there) folders are removed when the admin removes the delegated shared mailbox key value pair from the email+app config, then all delegated mailbox drafts are deleted from the app along with the other information from the delegated mailbox the mailbox owner can update the following permission combinations permission level combinations reviewer reviewer > author reviewer > editor reviewer > none author author > reviewer author > editor author > none editor editor > author editor > reviewer editor > none the following table displays the different delegation permissions and the actions they can perform action reviewer author editor reading emails yes yes yes downloading and viewing email attachment yes yes yes searching emails yes yes yes marking emails as read/unread yes yes yes flagging emails no no yes moving an email to a different folder within the account no no yes deleting emails no no yes sending emails with attachments no yes yes options to reply/reply all/forward emails no yes yes saving draft emails locally in the app reviewer cannot compose emails and create drafts the only possible way to create draft is an edge case when doing reply/reply all/forward a delegated calendar event yes yes yes responding to meeting invites from emails (no delegated calendar added) no no no responding to meeting invites from emails (dc added) becomes available if the delegated calendar of the same owner's account is added with author or editor permissions yes yes yes reading signed and/or encrypted emails yes yes yes sending signed and/or encrypted emails no yes yes reading emails with classification yes yes yes sending emails with classification no yes yes adding delegated mailbox to the email+ app to add the delegated mailbox to the email+ app on your android device, perform the following steps before you begin configure the enabled features key value pair and add the delegated shared mailbox value set both ews and exchange host set ews authorization mode, for modern auth, set value to modern auth for certificate based auth, set value to cert base procedure in the email+ app, go to settings > mail > accounts > add on the add delegated mailbox screen, type the email id of the mailbox owner delegated mailbox is added in mail section mailboxes the delegate gets access to inbox, sub folders, and smart folders support for smime the signing and encryption functionality is extended to support delegated mailboxes, the functionality works similar to that of primary account delegated user can read/send signed/encrypted emails depending upon the user permission read emails with classification the keychain is common for all mailboxes and not only for the mailbox you are working on the app searches certificates in the keychain and gal (same as the primary account) the process of adding certificates to the keychain is through email signing certificate and email encryption certificate kvps from the email attachment signing a delegate can view, search, reply, and forward signed emails in the delegator's mailbox (depending on permissions) in the received email, the sender's signing certificate can be verified if their public certificate is available in gal, or if it is available in the delegate's keystore in email+ otherwise, the certificate will be marked red as not trusted a delegate can sign emails with the actual sender's certificate (primary account) and send signed emails from the primary account on behalf of the delegator if the certificate of the signed email cannot be validated (there is no user certificate in the keychain and in gal), the red check mark icon is be displayed according to the existing logic encryption a delegate can encrypt emails with the actual sender's certificate (primary account) and send encrypted emails from the primary account on behalf of the delegator a delegate can decrypt emails if the delegator provides the delegate with their private certificates, and these certificates are added to the app keychain suppressing name check on certificate mismatch when the feature flag for suppressing name checks on certificate mismatch is enabled by admin, the feature is available for delegated mailboxes existing certificate associations are automatically accessible for delegated mailboxes the user can encrypt/decrypt emails using existing certificate associations and create new associations classification when classification is configured by admin, it is available for delegated mailboxes the user is able to parse emails in the delegated mailboxes having classification, reply/forward, and compose new emails the delegate receives a notification when a new mail is received in the delegated mailbox also, the delegated user receives following notification when the owner removes the access to the delegated mailbox mailbox access has been denied you cannot delegate a particular sub folder in a mailbox, you can only delegate only the mailbox ivanti email+ configurations supported for delegated and shared mailbox the following table lists the supported email+ and ews configurations before you begin ews must have basic auth enabled in internet information services (iis) manager (microsoft exchange server) for android if ews server is not accessible publicly (located in private network), then vpn should be configured update the host name in the email ews host key value pair email+ configuations additional configurations for ews supported android appconnect ivanti epmm and ivanti neurons for mdm with sentry, modern auth with or without email password kvp, microsoft office 365 add email ews host kvp with ews server value add ews min allowed auth mode = modern auth kvp yes android appconnect and android enterprise ivanti epmm or ivanti neurons for mdm, without sentry, modern auth with or without email password kvp, microsoft office 365 add ews min allowed auth mode = modern auth kvp yes android enterprise ivanti epmm or ivanti neurons for mdm, with sentry, modern auth with or without email password kvp, microsoft office 365 exchange host for ews should have value of the ews server ews authentication mode should have modern authentication value yes android appconnect and android enterprise ivanti epmm or ivanti neurons for mdm, with sentry + local certificate, basic auth with or without email password kvp, microsoft exchange versions 2016 and 2019, microsoft office 365 android appconnect add email ews host with ews server value android enterprise exchange host for ews should have value of the ews server yes android appconnect and android enterprise ivanti epmm, with sentry + group certificate, basic auth with or without email password kvp, microsoft exchange versions 2016 and 2019, microsoft office 365 android appconnect add email ews host with ews server value android enterprise exchange host for ews should have value of the ews server yes android appconnect and android enterprise ivanti epmm, with sentry + ms scep certificate, basic auth with or without email password kvp, microsoft exchange versions 2016 and 2019, microsoft office 365 android appconnect add email ews host with ews server value android enterprise exchange host for ews should have value of the ews server yes android appconnect and android enterprise ivanti epmm or ivanti neurons for mdm, with sentry, kerberos with prompt email password=true and enter password on email+ login screen, microsoft exchange versions 2016 and 2019 android appconnect add email ews host with ews server value android enterprise exchange host for ews should have value of the ews server yes android appconnect and android enterprise ivanti epmm or ivanti neurons for mdm, with sentry, kerberos with email password kvp with hard coded value (which is not probably a use case), microsoft exchange versions 2016 and 2019 android appconnect add email ews host with ews server value android enterprise exchange host for ews should have value of the ews server yes android appconnect and android enterprise ivanti epmm or ivanti neurons for mdm, without sentry, basic auth (with or without 'email password' kvp), microsoft exchange versions 2016 and 2019, microsoft office 365 yes android appconnect and android enterprise ivanti epmm or ivanti neurons for mdm, with or without sentry, certificate based auth, microsoft exchange versions 2016 and 2019, microsoft office 365 android appconnect add 'ews min allowed auth mode' = cert base kvp android enterprise add 'ews authentication mode' should have 'certificate based authentication' value yes android appconnect and android enterprise ivanti epmm or ivanti neurons for mdm, with sentry, kerberos (without 'email password' kvp), microsoft exchange versions 2016 and 2019 no
