Description of configurations in Ivanti EPMM
4 min
this section provides a more detailed description of the configuration steps referenced in overview of configuration on ivanti epmm docid\ f7a o9 yg5f9vstyn7wp the following configurations are described configuring scep settings docid\ dwfojkbprcy u23gujezxconfiguring an apptunnel service docid\ dwfojkbprcy u23gujezxupdating the appconnect app configuration for ivanti email+ docid\ dwfojkbprcy u23gujezx configuring scep settings create a scep setting if your exchange server and the ews service require certificate authentication you will reference the name of scep setting in the appconnect configuration for email+ to generate the login certificate for email+, so that the exchange server and ews trust the device procedure in the admin portal, go to \<font color="#323232">policies \& configs \> configurations\</font> select add \<font color="#323232">new \> certificate enrollment \> scep\</font> in the new scep setting window, configure the settings based on your scep requirements click save to save the scep setting click ok to dismiss the prompt indicating the successful creation of your scep setting you will reference this scep setting in the appconnect app configuration for email+ using the key email login certificate related topics “configuring scep” in the configuring an apptunnel service you create an apptunnel service in standalone sentry as part of an apptunnel setup before you begin ensure that you have a standalone sentry that is set up for apptunnel and the necessary device authentication is also configured see “configuring standalone sentry for app tunneling” in the procedure in the ivanti epmm admin portal, go to \<font color="#323232">services \> sentry\</font> edit the entry for the standalone sentry that supports apptunnel in the \<font color="#323232">app tunneling configuration\</font> section, under \<font color="#323232">services\</font> , click \<font color="#323232">+\</font> to add a new service use the following guidelines to configure an apptunnel service item description service name select \<any> the service name is used in the appconnect app configuration for email+ server list select the standalone sentry tls enabled na proxy/atc na server spn list na click \<font color="#323232">save\</font> updating the appconnect app configuration for ivanti email+ update the appconnect app configuration for email+ for ios, so that email+ on ios devices is authorized to get real time notifications from cns procedure in the ivanti epmm admin portal, go to \<font color="#323232">policy \& configs \> configurations\</font> select the appconnect app configuration you created for email+ click \<font color="#323232">edit\</font> add an apptunnel rule that points to the standalone sentry on which you configured the apptunnel service for url wildcard, enter the exchange server’s ip address or fqdn for identity certificate, select the certificate enrollment setting you configured for standalone sentry you would have created the certificate enrollment setting as part of the standalone sentry setup for identity certificate with pass through add the necessary key value pairs click \<font color="#323232">save\</font> ensure that the configuration is applied to the labels that contain the devices to which you want to push the configuration the updated appconnect app configuration for email+ for ios will be sent to devices at the next sync interval related topics see key value pairs for real time push notifications docid\ u32jiryq4umyqpdah8upm for a list of key value pairs
