Main configuration steps for Ivanti Email+ for Android AppConnect (Ivanti EPMM)
13 min
following are the main steps for configuring and deploying email+ for android appconnect on ivanti epmm adding ivanti email+ for android appconnect and secure apps manager to ivanti epmm docid\ rm50dab8xfuxngeprdmtj enabling third party appconnect apps in ivanti epmm docid\ rm50dab8xfuxngeprdmtj configuring the appconnect global policy in ivanti epmm docid\ rm50dab8xfuxngeprdmtj configuring the appconnect container policy in ivanti epmm docid\ rm50dab8xfuxngeprdmtj configuring an appconnect app configuration for ivanti email+ in ivanti epmm docid\ rm50dab8xfuxngeprdmtj configuring email attachment control with standalone sentry in ivanti epmm docid\ rm50dab8xfuxngeprdmtj (for standalone sentry deployments only) adding ivanti email+ for android appconnect and secure apps manager to ivanti epmm you add email+ and secure apps manager (sam), in the same manner you would add any other android in house app after adding the apps to ivanti epmm, you can distribute the apps to devices by applying the apps to labels that contain the devices you want to distribute the apps procedure in the ivanti epmm admin portal, go to \<font color="#323232">apps \> app catalog \> add+ \> in house\</font> (prior to ivanti epmm 8 0 go to \<font color="#323232">apps \> app distribution library\</font> , and select \<font color="#323232">add app)\</font> add the apps just as you would any in house app add sam if you have not already uploaded it to support other secure apps after adding the apps, apply the apps to appropriate labels so that they are available to the required devices next steps continue on to enabling third party appconnect apps in ivanti epmm docid\ rm50dab8xfuxngeprdmtj related topics for information on adding in house apps for android, see “working with apps for android devices” in the enabling third party appconnect apps in ivanti epmm email+ requires that you enable the licensing option for third party and in house appconnect apps procedure in the ivanti epmm admin portal, go to \<font color="#323232">settings \> system settings\</font> click additional products > licensed products select \<font color="#323232">appconnect for third party and in house apps\</font> if your organization has purchased it click \<font color="#323232">save\</font> next steps continue to configuring the appconnect global policy in ivanti epmm docid\ rm50dab8xfuxngeprdmtj configuring the appconnect global policy in ivanti epmm because email+ for android is an appconnect app, you need to configure an appconnect global policy (if one has not already been configured) this policy specifies settings that apply to all appconnect apps on a device for example, you configure the appconnect passcode requirements make sure only one appconnect global policy applies to each device on the appconnect global policy, you can authorize device users to use email+ even if no appconnect container policy is applied to the device procedure in the ivanti epmm admin portal, go to \<font color="#323232">policies \& configs \> policies\</font> select \<font color="#323232">add new \> appconnect\</font> you can also use an existing appconnect global policy select it, and click \<font color="#323232">edit\</font> complete the form most fields default to suitable values, but make sure that you select \<font color="#323232">appconnect \</font> \<font color="#323232">enabled\</font> to enable appconnect on the device click \<font color="#323232">save\</font> select the policy select \<font color="#323232">actions \> apply to label\</font> select the labels to which you want to apply this policy click \<font color="#323232">apply\</font> next steps continue to configuring the appconnect container policy in ivanti epmm docid\ rm50dab8xfuxngeprdmtj related topics for general details on the appconnect global policy, see “configuring the appconnect global policy” in the and ivanti tunnel for android guide configuring the appconnect container policy in ivanti epmm this task is only required if you did not select authorize for apps without an appconnect container policy, in the appconnect global policy if you want to apply different data loss prevention policies to different devices when you upload email+ to ivanti epmm, ivanti epmm automatically creates an appconnect container policy for the app create an appconnect container policy, if you want to apply different settings to different devices make sure only one appconnect container policy for email+ is applied to each device ivanti epmm keeps in sync the labels that you apply to the app and the labels that you apply to the appconnect container policy that ivanti epmm automatically created when you apply email+ to a label, ivanti epmm automatically adds the same label to the automatically created appconnect container policy be sure to remove that label from the automatically created appconnect container policy if you are using that label on a manually created appconnect container policy procedure in the ivanti epmm admin portal, go to \<font color="#323232">policies \& configs \> configurations\</font> click \<font color="#323232">add new \> appconnect \> container policy\</font> alternatively, edit the automatically created appconnect container policy for email+ enter a name for the policy enter a description for the policy in the \<font color="#323232">application\</font> field, choose the email+ select \<font color="#323232">allow screen capture\</font> if you want to override the default restriction on screen capture the remaining settings do not apply to android also, the ability to open a document is always restricted to the secure container on android devices click \<font color="#323232">save\</font> next steps if you created a new container policy, continue to applying the container policy to labels in ivanti epmm docid\ rm50dab8xfuxngeprdmtj if you edited the automatically created appconnect container policy, continue to configuring an appconnect app configuration for ivanti email+ in ivanti epmm docid\ rm50dab8xfuxngeprdmtj applying the container policy to labels in ivanti epmm do these steps if you created a new appconnect container policy procedure select the container policy select \<font color="#323232">actions \> apply to label\</font> select the labels to which you want to apply this policy click \<font color="#323232">apply\</font> next steps continue to removing labels from the automatically created appconnect container policy in ivanti epmm docid\ rm50dab8xfuxngeprdmtj removing labels from the automatically created appconnect container policy in ivanti epmm do these steps if you are not using the automatically created appconnect container policy procedure select the automatically created appconnect container policy select \<font color="#323232">actions \> remove from label\</font> select any labels that you applied to the appconnect container policy that you just created click \<font color="#323232">remove\</font> next steps continue to configuring an appconnect app configuration for ivanti email+ in ivanti epmm docid\ rm50dab8xfuxngeprdmtj configuring an appconnect app configuration for ivanti email+ in ivanti epmm when you add email+ for android appconnect, an appconnect app configuration is automatically created for email+ you can create a new appconnect app configuration if you want to apply different settings to different devices otherwise, edit the automatically created appconnect app configuration to configure the activesync server information and other settings that you want to customize the appconnect app configuration for email+ for android appconnect contains information such as the fully qualified domain name and user id for the activesync server certificate information key value pairs that determine the app’s settings and behavior the default configuration contains the bundle id for the app and a set of default key value pairs that can be edited or deleted you can also configure additional key value pairs make sure only one appconnect app configuration for email+ is applied to each device always set the value of the email device id key to $device uuid no dashes$ standalone sentry uses this key value pair for activesync correlation procedure in the ivanti epmm admin portal, go to \<font color="#323232">policy \& configs \> configurations\</font> select the automatically created appconnect app configuration for email+ for android, and click edit edit the configuration as needed click save the automatically created app configuration has the same labels you applied to the app you do not need to apply the automatically created app configuration to a label related topics for a description of the fields see appconnect app configuration field descriptions docid\ rm50dab8xfuxngeprdmtj for descriptions and list of supported key value pairs, see key value pairs for ivanti email+ (android appconnect) docid\ fqckqtshskvvfvl0nwfe3 creating a new appconnect app configuration for ivanti email+ for android create a new appconnect app configuration by saving the automatically created appconnect app configuration for email+ if you want to apply different settings to different devices procedure in the admin portal, go to \<font color="#323232">policy \& configs \> configurations\</font> select the automatically created appconnect app configuration for email+ click actions > save as and save it as a new configuration enter a new name and description for the configuration edit the configuration as needed click \<font color="#323232">save\</font> select the new appconnect app configuration select \<font color="#323232">actions \> apply to label\</font> select the labels to which you want to apply this appconnect app configuration click \<font color="#323232">apply\</font> the automatically created app configuration is automatically applied to the same labels you applied to the app however, only one app configuration should be applied to any one device therefore, remove the labels from the automatically created app configuration select the automatically created appconnect app configuration select \<font color="#323232">actions \> remove from label \</font> select any labels that you applied to the appconnect app configuration that you just created click \<font color="#323232">remove\</font> related topics for a description of the fields, see appconnect app configuration field descriptions docid\ rm50dab8xfuxngeprdmtj for descriptions and list of supported key value pairs, see key value pairs for ivanti email+ (android appconnect) docid\ fqckqtshskvvfvl0nwfe3 appconnect app configuration field descriptions the following table provides description of the fields in an appconnect app configuration for email+ for android item description name edit the default name if necessary the name is not the same as the name that appears in the name column in \<font color="#323232">policy \& configs \> configurations\</font> description if necessary, edit the text to clarify the purpose of this appconnect app configuration application email+ is selected apptunnel rules to configure apptunnel for android appconnect, see configuring email+ with apptunnel for android appconnect docid\ edesgpawu9zcithbhbn n email+ app might use apptunnel as vpn if the email exhcnage host kvp is set as the activesync server and if this server is not accessible from public network apptunnel is not used if standalone sentry used in the email exchange host kvp if you are using a standalone sentry, all communication with the activesync server is through a secure connection to the standalone sentry app specific configurations add key value pairs to configure app behavior the automatically created app configuration for email+ contains a set of default key value pairs each key value pair is configured as a separate row do the following for the value of the email exchange host key, enter the fully qualified domain name (fqdn) of the activesync server, or the standalone sentry server if you are using a standalone sentry edit the default key value pairs as necessary to add a key value pair, click \<font color="#323232">add+\</font> to delete a key value pair, click \<font color="#323232">x\</font> the following key value pairs are required email address email device id email exchange host email exchange username configuring email attachment control with standalone sentry in ivanti epmm this is only required if attachment control is enabled in standalone sentry procedure in the ivanti epmm admin portal, go to \<font color="#323232">services \> sentry\</font> select the standalone sentry that handles email for the devices click the edit icon in the attachment control configuration section, for \<font color="#323232">ios and android using secure email apps\</font> , select \<font color="#323232">open with secure email app\</font> click \<font color="#323232">save\</font> related topics see “email attachment control with standalone sentry” in the
