Key-value pairs for Ivanti Email+ (Android AppConnect)
2 min
key value pairs for configuring email+ for android appconnect app behavior docid\ fqckqtshskvvfvl0nwfe3 describes the key value pairs available to administrators to customize email+ app behavior on android devices these key value pairs define app behavior such as providing detailed notifications to device users and exporting contacts from email+ key value pairs marked as ivanti epmm only are not applicable to ivanti neurons for mdm for ivanti neurons for mdm deployments, these variables are either provided as fields in ivanti neurons for mdm or are set automatically and do not require action from the administrator see configuring email+ for android appconnect in ivanti neurons for mdm docid\ hwkkyrlbdejknpnden8jm for a description of the fields in ivanti neurons for mdm some values can use the uem variables, such as $email$ for ivanti epmm and $ for ivanti neurons for mdm the uem substitutes the device user’s value when sending the app configuration to the device if you make a mistake in configuring the required key value pairs, the app displays a message to the device user that the configuration has an error, and to contact the administrator before configuring new key value pairs, the user should update to the latest email+ application and then the administrator should configure the new key value pairs when there are multiple values available within a kvp, the different features should be specified as a list of comma separated strings, with or without a space a semicolon between them will not work you can configure and customize the following features with key value pairs required key value pairs to configure an account on email+ docid\ fqckqtshskvvfvl0nwfe3 background email check and user notifications docid\ fqckqtshskvvfvl0nwfe3 certificates docid\ fqckqtshskvvfvl0nwfe3 s/mime docid\ fqckqtshskvvfvl0nwfe3 manage contacts docid\ fqckqtshskvvfvl0nwfe3 syncing docid\ fqckqtshskvvfvl0nwfe3 maximum size for email attachments docid\ fqckqtshskvvfvl0nwfe3 default signature docid\ fqckqtshskvvfvl0nwfe3 ssl docid\ fqckqtshskvvfvl0nwfe3 gal search docid\ fqckqtshskvvfvl0nwfe3 prompt the device user for password docid\ fqckqtshskvvfvl0nwfe3 show pictures docid\ fqckqtshskvvfvl0nwfe3 default network timeout docid\ fqckqtshskvvfvl0nwfe3 troubleshooting docid\ fqckqtshskvvfvl0nwfe3 key value enter/select one description required key value pairs to configure an account on email+ email address email address of the device user to validate that the account signed in is indeed the corporate account (the value is automatically set into modern auth ui, but can be changed there) ivanti epmm typically, this field uses the ivanti epmm variable $email$ you can also use combinations of these ivanti epmm variables, depending on your activesync server requirements $userid$, $user custom1$, $user custom2$, $user custom3$, $user custom4$ ivanti neurons for mdm typically, this field uses the ivanti neurons for mdm variable $ you can also use combinations of the user attribute variables, depending on your activesync server requirements the user attribute variables are listed in ivanti neurons for mdm in admin > attributes email device id the device id that the activesync server uses for the device ivanti epmm always use the ivanti epmm variable $device uuid no dashes$ ivanti neurons for mdm always use the ivanti neurons for mdm variable $ email exchange host fqdn of the activesync server or standalone sentry the fully qualified domain name (fqdn) of the activesync server or standalone sentry this kvp should be set to outlook office365 com example mysentry mycompany com email exchange username user id for the activesync server ivanti epmm typically, you use the ivanti epmm variable $userid$ if your activesync server requires a domain, use \<domain name> \\$userid$ for example mydomain\\$userid$ you can also use combinations of these ivanti epmm variables, depending on your activesync server requirements $email$, $user custom1$, $user custom2$, $user custom3$, $user custom4$ ivanti neurons for mdm typically, you use $ if your activesync server requires a domain, use \<domain name>\\$ example mydomain\\$ depending on your activesync server requirements, you can use $ background email check and user notifications allow detailed notifications true false true device users see detailed notifications the details can include sensitive information such as email subject and body previews, or event titles and times false device users see normal notifications default if no key value is configured false certificates the necessary certificate setting must have been created in the uem email login certificate the certificate setting from the dropdown list the uem sends the contents of the certificate as the value is also used when cba is configured (to check if supported by android) if the certificate is password encoded, ivanti epmm automatically sends another key value pair the key’s name is the following string \<font color="#000000">\<name of key for certificate\> mi cert pw\</font> the value is the certificate’s password default if no key value is configured certificates are not used email trust all certificates true false true email+ automatically accepts untrusted certificates typically, you enter true only when working in a test environment false email+ does not accept untrusted certificates default if no key value is configured false email certificate x, where x is 1 through 10 the certificate setting from the dropdown list email+ imports the certificate into its keystore of trusted certificates, and trusts any certificates derived from the ca root certificate in its keystore the certificate must be der encoded you can add up to ten certificate authority (ca) root certificates reasons for designating a ca root certificate as trusted standalone sentry requires a certificate, whose certificate authority is not in the email+ keychain, for device authentication a common scenario is if standalone sentry uses a self signed certificate or a certificate that is not derived from a well known certificate authority you specify this certificate to email+ in the key email login certificate it corresponds to the certificate you specified for device authentication in standalone sentry configuration in the ivanti epmm admin portal certificates configured for encrypting or signing s/mime emails are self signed or not derived from a well known certificate authority you specify these certificates in the keys email encryption certificate and email signing certificate use der format instead of normal pem format for email certificate x certificates the trusted ca root certificate is listed in email+ in \<font color="#323232">settings \> advanced settings \> keystore\</font> eas min allowed auth mode basic cert base modern auth defines the authentication method to the exchange activesync server basic uses user name and password cert base uses identity certificates for certificate based authentication modern auth\ uses enable modern auth for corresponding protocol enables oauth 2 0 authorization modern auth authority url and modern auth resource url when configured through sentry uses the following values modern auth authority url https //\<sentryhostname>/proxyservice modern auth resource url https //\<sentryhostname> for certificate based authentication, the key email login certificate must also be configured default if no key value is configured basic allow certificate revocation check true false the admin can use this kvp to check certificates validity the crl check for server certificate is performed only if th email trust all certificates kvp is set to "false" s/mime email encryption certificate the certificate setting from the dropdown list specifies the certificate to use for encrypting s/mime emails the uem sends the contents of the certificate as the value email+ imports the key into the keystore and selects the certificate as the encryption certificate if you change the certificate, email+ imports the new certificate into the keystore and selects the new certificate as the encryption certificate it leaves the previous certificate in the keystore if you delete the key value pair, email+ leaves the certificate in the keystore it changes its settings to specify that no certificate is selected as the encryption certificate using the email+ user interface, the device user can change the encryption certificate by manually importing one and selecting it for use encrypt all emails with the certificate or encrypt a specific email with the certificate email+ automatically encrypts emails if the emails in the thread are encrypted for more information about configuring s/mime for email+, see smime support in email+ for android for identity and encryption docid\ eewgjmotv28 ptbe5cpxm default if no key value is configured certificate is not configured for s/mime certificates use der format instead of normal pem format email signing certificate the certificate setting from the dropdown list specifies the certificate to use for signing s/mime emails the uem sends the contents of the certificate as the value email+ imports the key into the keychain and selects the certificate as the signing certificate if you change the certificate, email+ imports the new certificate into the keystore and selects the new certificate as the signing certificate it leaves the previous certificate in the keystore if you delete the key value pair, email+ leaves the certificate in the keystore and changes its settings to specify that no certificate is selected as the signing certificate using the email+ user interface, the device user can change the signing certificate by manually importing one and selecting it for use sign all emails with the certificate or sign a specific email with the certificate for more information about configuring s/mime for email+, see smime support in email+ for android for identity and encryption docid\ eewgjmotv28 ptbe5cpxm default if no key value is configured certificate is not configured email signing digest sha 1 sha 256 sha 384 sha 512 configures signature algorithm the default value is set to sha 1 the restriction is empty by default if there is no value or invalid value set, then sha 1 is used manage contacts allow export contacts true false true allows email+ users to export the email+ contacts outside of the appconnect container to the native contacts app device users can select the “sync to personal profile” option, in the settings of the email+ contacts app, to export the contacts exporting contacts allows users to see the caller id of incoming calls from phone numbers in the list of corporate contacts third party apps can also access the corporate contacts if contacts are not exported, users see the caller id only for personal contacts false device users cannot export the email+ contacts they see the caller id only for personal contacts when the device is retired or email+ is retired, the corporate contacts are removed from both email+ and the native contacts app default if no key value is configured true allow export contacts to email true false true device users have the option to export contacts as an attachment to an outgoing email the attachment is an unencrypted vcf (virtual contact file) file false device users do not have the option to export contacts as an attachment to an outgoing email default if no key value is configured true allow export contacts to sdcard true false true device users have the option to export the contacts to the sd card if the device user chooses the option, email+ exports the contacts as an encrypted vcf (virtual contact file) file the encrypted vcf file is readable only by email+ and other secure apps false device users do not have the option to export contacts to the sd card default if no key value is configured true limit contact export to name number all name number limits the exported contact information to each contact’s name and number information use this setting to minimize the exposure of corporate data all exports all the contact information this field is used only if allow export contacts is set to true if you enter a value other than all or name number, email+ uses the value all default if no key value is configured all email safe domains comma separated list of safe domains ensure that there are no spaces before or after the comma email addresses not in the safe domain list are displayed in red color when composing new emails or creating new calendar invitations in email+ you may want to use this key value pair if you company has multiple domains and you want to identify the company domains as opposed to domains that are not company domains to disable this feature, you can set the value to " " example mycompany com,mycompany net,internal mycompany com default if no key value is configured only the domain of the user's email address is considered safe all other domains will be highlighted in red email alert unsafe domains true false true users see an alert if the recipients in an email or calendar invite include addresses that are not in a safe domain if the key is configured but safe domains are not configured, only the domain of the user's email address is considered safe device users have the option to either proceed or cancel sending the email false an alert is not displayed for addresses not in a safe domain default if key value is not configured false syncing email max sync period 0 1 2 3 4 5 specifies the maximum sync period for which emails are downloaded 0 all emails 1 emails received over the last one day 2 emails received over the last three days 3 emails received over the last seven days 4 emails received over the last two weeks 5 emails received over the last one month default if no key value is configured 0 email default sync period 0 1 2 3 4 5 specifies the default period for which emails are downloaded 1 emails received over the last one day 2 emails received over the last three days 3 emails received over the last seven days 4 emails received over the last two weeks 5 emails received over the last one month if configured, all options will be available in email+ device users can change the default value if email max sync period is also configured, options greater than sync period specified in email max sync period will not be available on the device default if no key value is configured 2 additionally, the default value is used in the following cases if the value is not 1,2,3,4, or 5 the value is larger than the value for email max sync period after an upgrade, the app retains the default sync period set by the device user maximum size for email attachments email max attachment a number specifies the maximum size in megabytes of an email that email+ will send without a warning to the device user the maximum size includes the body of the email plus its attachments also applicable for delegated mailbox allowed values are integers starting with 1 if the exchange server has an email size limit that is less than the limit specified in email max attachment, the exchange server does not deliver the email default if no key value is configured 10 mb maximum size for email attachments email max body size a number specifies the maximum limit for email message body size that can be received by the email+ app default 4 mb default signature email default signature the default email signature the value of this key is the default email signature for all emails however, the device user can override the default email signature at any time after the user defines the default email signature, email+ does not use the value in the key, even if you update it default if no key value is configured sent by email+ ssl email ssl required true false true secures communication using https to the server specified in email exchange host typically, set this field to true unless you are working in a test environment default if no key value is configured true gal search gal search minimum characters a number the minimum number of characters email+ uses for automatic global address list (gal) lookup in mail, calendar, and contacts when device users enter the specified number of characters of a name, email+ searches the gal, and presents the matches that it finds on your exchange server, set the minimum number of characters for gal search to the same value you set for this key if you do not, gal search will not work properly in email+ default if no key value is configured 4 gal search display name true false true enables display name in email+ settings > contacts by default false disables display name in email+ settings > contacts by default default if key value is not configured true contacts display order first last last first sets the default display order for contact names in search results device users can change the display order in email+ in settings > contacts the values are case sensitive; enter in lower case first last contact names in search results are displayed with first name followed by the last name last first contact names in search results are displayed with last name followed by the first name default if key value is not configured first last prompt the device user for password prompt email password true false true email+ prompts the user for the email password before attempting to connect to the email server false when email+ first launches and connects to the email server, email+ provides the password set in the email+ configuration to the server if a password is not configured, an empty string is provided to the server in this case, after the connection is established, email+ prompts the user for a password if the email server limits the number of password attempts, the server counts the first connection as one failed attempt set the value of this key to true if the email server allows only a small number of password attempts example if the email server allows only three attempts, setting this value to true ensures that device users get three attempts, not two attempts kerberos based authentication is designed to work without user passwords since setting prompt email password to true always prompts the user for a password, be sure the value is false (the default) if using kerberos based authentication default if no key value is configured false email password user’s password for the activesync server if configured, email+ does not prompt users for a password delete this key if you want the device user to enter the password when using email+ recommends deleting the key ivanti epmm you can use the ivanti epmm variable $password$ if you have checked save user password in settings > users\&devices > registration ivanti epmm then passes the user’s password as the value to the device if you plan to use the $password$ variable, be sure to set \<font color="#323232">save user password\</font> to \<font color="#323232">yes\</font> before any device users register if a device user was registered before you set \<font color="#323232">save user password\</font> , email+ prompts the user to enter the password manually for google accounts, as part of a larger setup for synchronizing google account data, you can use $google autogen password$ for more information, see “synchronizing google account data” section in the for your device platform default if no key value is configured email+ requests device users to enter the password dialing show dialing confirmation true false true users see a confirmation dialog when they tap on a phone number in an email tapping on the phone number in the dialog, dials the phone number tapping the back arrow cancels the call false users do not see a confirmation dialog when a user taps on a phone number in email+, the number is automatically dialed default if no key value is configured false show pictures show pictures default true false true enables the \<font color="#323232">show pictures\</font> option device users automatically see images when opening an email false disables the \<font color="#323232">show pictures\</font> option device users must tap \<font color="#323232">show pictures\</font> to view images when opening an email device users can override the value you configure by turning the \<font color="#323232">show pictures\</font> option on or off if you change the key’s value, email+ does not change the \<font color="#323232">show pictures\</font> option until email+ does a full synchronization a full synchronization occurs only when you change certain fundamental key value pairs like email address, or when the device user uninstalls and reinstalls email+ default if no key value is configured false default network timeout default network timeout a positive integer the value is represented in seconds the value overwrites the default connection timeout value for all requests you may want to configure the key value pair to manage slow connections with the activesync server or for syncing large folders and emails if the value is 0, negative, or non integer, the default value is used default if no key value is configured 90 seconds troubleshooting disable analytics true false true disables sending email+ analytics false enables sending email+ analytics default if no key value is configured false allow logging true false true email+ logs data in the android logging system this is useful for problem diagnosis typically, you enter true only when working in a test environment otherwise, enter false default if no key value is configured false enabled features export contacts skip empty links show formatting block external gal rms support multiple accounts allow shortcuts eas 16 calendar delegation delegated shared mailbox if the highest activesync version for the server is 16 1 or higher, enable email+ to sync via eas 16 1 version if the highest activesync version for the server is 16 0, enable email+ to sync via eas 16 0 versionif the highest activesync version for the server is lower than 16 0, then it works as per the current settings export contacts if allow export contacts key value pair is set to true and export contacts value is added to the keyvalue pair then email+ contacts will be automatically synced to native contacts app skip empty links some exchange servers block custom links and the hyperlinks are stripped from the email body for example, the url mibrowser // that is used to launch web\@work and may not become click able when sent via email the work around for this problem is, email+ has additional capability to detect such emails and automatically fetch their body as mime ata that is unmodified by exchange we recommend that administrators evaluate this capability in their environment by adding "skip empty links" into the "enabled features" kvp fetching mime data may not work in all configurations show formatting enables the “always show formatting” option if it was not previously changed manually block external gal disables contacts search through email+ contacts for external applications rms support enables fetching, displaying and composing of the protected messages multiple accounts enables secondary email account on the same device allow shortcuts enables the user to create shortcuts for calendar, contacts, tasks, and notes eas 16 enables activesync 16 specific folder synchronization features in email+ when email+ receives "eas 16" the first time, folder resync is expected when "eas 16" protocol is added to enabled features kvp calendar delegation enables the add delegated calendar option delegated shared mailbox enables the delegated mailbox option when this value is removed all added delegated mailbox accounts are removed from email and setting's screen " add a mailbox " button is removed under email screen and setting's screen if only primary account is added then the arrow to expand and collapse to show different mailbox's and add a mailbox label are also removed if secondary account is available then arrow to expand and collapse to show different mailbox's will be available but add a mailbox label is not available disabled features save attachment print show snippet personal events crl signature check save attachment disables the save attachments option when this option is added the “save as” button is not available for email attachments attachments can still be opened and viewed in docs\@work or mail application print disables the ability to print a message show snippet this option removes "text preview" setting and disables message preview displaying if this option is enabled the user can set the number of lines visible for message preview, through email+ app settings on the mobile device by default the number of lines set for preview is set to two personal events \ adding 'personal events' value to 'disabled features' kvp removes "overlay personal events" in settings by admin when 'personal events' value is removed from 'disabled features', the "overlay personal events" appears in settings and has previous state that user had applied crl signature check disables crl check for the email signature certificates microsoft office 365 authority and resource url modern auth authority url https //login microsoftonline com/common this kvp is added to specify microsoft office 365 authority url modern auth resource url https //outlook office365 com this kvp is added to specify microsoft office 365 resource url document classification capabilities email security classification json default value for this key is empty enables the email classification feature if present, it specifies the list of classification values to be used and all the supported permutations see document classification capabilities section for more information report phishing report phishing address email address enabling 'report phishing' option onview screen in the "more" menu phishing email is sent to email address set in value mail organization organize by date true false disables email treading for email messages false "email threading” is turned "on" calendar week view show week number true false displays the week number in the week and month view for calendar you can enable or disable week number view from device settings default if no key value is configured true setup access to exchange server via ews protocol email ews host fqdn of the ews server to support ews authentication when email exchange host kvp does not contain a fully qualified domain name (fdqn) of the ews server, email ews host kvp should be added and have a fdqn as the value for the ews server if not configured, the value of email exchange host kvp is used as the ews server by email+ update the host name in the email ews host key value pair ews min allowed auth mode basic modern auth cert base defines the authentication method for the exchange server through ews protocol supported authentication methods are basic authentication uses username and password modern authentication uses enable modern auth for corresponding protocol enables oauth 2 0 authentication certificate based authentication uses identity certificates for authentication
