Introduction to Ivanti Email+ Notification Services
12 min
when a mail is received on an ios mobile device, a notification appears if real time notification is enabled for each mail there are two notifications received apple apns notification shows up immediately on the lock screen (depending on the email+ notification settings in your device settings) this notification has the text “you have new messages” email+ notification the email+app fetches the email summary for the new unread email, removes the original device notification, and replaces it with a new notification the second notification shows either the unread email count or summary of the new emails, depending on your email+ settings voip notifications for email+ are not supported starting email+ 3 13 0 and later, due to the changes in apple policy with regards to notifications this impacts the vip notifications outside of work hours , other notifications such as work hours notifications and the weekend notifications work as before email+ notification services (ens) is the recommended solution to fix this issue there are two different notification deliverable mechanism for real time notification cloud based service which only supports work hour notification, see about real time push notifications for email+ for ios docid 1uzjcwty12er7nk7p7jrm section ens based service which supports vip email only notifications the following sections describes about ens and how to configure it on your device about ivanti email+ notification services email+ notification service leverages a standalone server that is based on existing sentry and hosted inside the organizations firewall this server is configurable on uem servers and leverages a service account on microsoft exchange to retrieve email metadata information (such as sender, subject, and body snippet) required to support vip mails notifications outside of office hours and direct detail notifications the following diagram describes how the ens solution works figure 1 email+ notification services architecture email+ app the email+ app registers callback url with microsoft exchange server to send out work hours, list of vip contacts, key value pairs settings, and vip notifications outside work hours microsoft exchange when a new mail is received in the folder that you are subscribed to, microsoft exchange sends a notification to email+ notification proxy (enp) which consists of message id and folder id for the new received mail email+ notification proxy enp logs in to the exchange server using a service account and pulls the following information about the mail senders email address subject line snippet of the mail enp applies and verifies the rules once the verifications is complete, it creates a payload and sends it to real time push notification server on the ivanti neurons for mdm real time push notifications the mobileiron cns relays the information to apple push notification service (apns) apple push notification service (apns) notifies the ios device notification workflow on email+ this feature requires users to be subscribed to cns for real time notifications ios displays a notification to the user indicating that there are new messages mailbox active sync a notification is triggered to email+, to open the correct mailbox a sync up is performed to co relate the notification and the mail enable email+ settings on your device to receive notifications in email+ app, go to settings > notifications and enable work hours only option first to enable weekend alerts or vip allowed after work hours option the vip related options are not be enabled if ens is not configured, as there is no service account to check if the sender is a vip contact (ensure that the contacts are marked as vip) when notification settings is changed, a note similar to the following is displayed changes to alert times will come into effect after 'x' hours the default interval is 1440 minutes if you are using cns only for real time notifications all the settings related to vip are not visible on the email+ app and cannot process notifications outside work hours other than delivering notifications over weekend the following section describes how to configure ens limitation the ens solution is not supported on microsoft exchange office 365 before you begin supported on ivanti epmm 10 7 0 0 or later, ivanti neurons for mdm r70 and later, and sentry 9 8 5 ensure that you have configured a service account on microsoft exchange server (service account on exchange impersonates other mailboxes when accessing exchange over various supported protocols for the purpose of exchange notification proxy (enp), microsoft’s exchange web services (ews) protocol is used to access mailbox messages ) ensure that you have the jwt token of cns production server for more information, see about real time push notifications for email+ for ios docid 1uzjcwty12er7nk7p7jrm section the term jwt token is also referred as authorization token , token , and notification server authorization in ivanti products standalone sentry must be configured activesync with a publicly trusted certificate ensure that the exchange servers are configured with the service account the servers must have identity certificate to authenticate the service account if exchange server version support is earlier than tls v1 2, then the supported protocols should be configured in incoming protocols on mics the following table describes the ens port rules for firewall table 1 ens port network rules requiredirectionment destination port direction standalone sentry cns mobileiron com tcp443 outbound initialized, bi direction connection exchange server standalone sentry tcp443 outbound standalone sentry exchange server tcp443 inbound ivanti epmm management ip standalone sentry tcp443, 9090 bi direction connection it admin pc ip standalone sentry tcp8443, 22 inbound initialized, bi direction connection standalone sentry ntp server ntp outbound standalone sentry dns server dns outbound standalone sentry smtp server smtp outbound configuring service account service account on microsoft exchange impersonates other mailboxes when accessing exchange over various supported protocols following are the main steps for configuring service account setting up service accounts on exchange server configuring a service account on exchange server setting up service accounts on exchange server for the purpose of exchange notification proxy (enp), microsoft’s exchange web services (ews) protocol is used to access mailbox messages for example service account is assigned to the following role applicationimpersonation the ews sends requests with the credentials of a single service account which includes an xml key \<soap\ header> \<t\ requestserverversion version="exchange2013" /> \<! the following causes the request to run as alfred\@contoso com > \<t\ exchangeimpersonation> \<t\ connectingsid> \<t\ smtpaddress>alfred\@contoso com\</t\ smtpaddress> \</t\ connectingsid> \</t\ exchangeimpersonation> \</soap\ header> this allows a single account to access the mailbox of other accounts configuring a service account on microsoft exchange server to configure service account on ews follow these steps in the microsoft exchange management console, open a browser and type in url for example https //\<hostname>/ecp log in as an admin, go to mail > options > manage my organization > roles & auditing> mailboxes and create a new role group add the applicationimpersonation role to the group add members to the group click save to finish for more information on configuring service account on microsoft exchange server, see microsoft documentation https //docs microsoft com/en us/windows/security/identity protection/access control/service accounts setting up standalone sentry as an ivanti email+ notification service you can set up a dedicated standalone sentry as an email+ notification service this capability allows you to configure multiple exchange servers to provide notifications for vip accounts in email+ this feature requires uem servers, cloud notification service (cns), standalone sentry, and email+ applicable to ios only, the email+ notification service cannot be combined with activesync or apptunnel email+ notification service requires sentry 9 8 5 and email+ 3 13 0 through the latest supported versions (content notification system is automatically upgraded) for more information, see “ standalone sentry email notifications ” section in the configuring ivanti email+ using kvps on ivanti epmm for notification services after standalone sentry is set up, you must configure email+ on ivanti epmm procedure in the ivanti epmm admin portal, go to policy & configs > configurations click add new > appconnect > app configuration to create a new appconnect configuration in the name field, enter brief text that identifies this appconnect app configuration for example email+ for ios in the description field, enter additional text that clarifies the purpose of this appconnect app configuration in the application field, enter the bundle id for the app in the app specific configurations section enter the required key value pairs for more information on how to configure the key value pair on cloud notification service, see real time push notifications docid\ rjgjwabjua0pm4w6qi029 section com mobileiron ios emailplus click save go to policies & configs > policies , select an appconnect policy and click edit guidelines to edit appconnect global policy fields option name default appconnect global policy appconnect select enabled option security policies > apps without an appconnect container policy check the authorize option click save go to apps > app catalog > add + >in house click browse to upload email+ inhouse app registering your ios device using ivanti epmm you should register your ios device with an ldap user or local user in the ivanti epmm admin portal, go to device & users > users click on add and select add local user or ldap user fill in the details in the add new user window click save register device with the local or ldap user result email+ is pushed to device as a part of mdm configuration configuring ivanti email+ using kvps on ivanti neurons for mdmfor notification services set up a standalone sentry before configuring email+ on ivanti neurons for mdm, see the standalone sentry email+ notification services section in the procedure in the ivanti neurons for mdm admin portal, go to apps > app catalog > email+ go to app configuration > email+ configuration , click + to create a new email+ configuration in the configuration setup section enter the following in the name field, enter the name of the configuration in the description field, enter additional text that clarifies the purpose of the configuration in the email+ settings section, enter the following email address exchange host exchange username in the appconnect custom configuration section enter the required key value pairs, to configure ens choose a distribution option for the configuration and click done the configuration is distributed to the subset of the devices to which the app is distributed the sentry server host key value pair should point to ens sentry hostname registering your ios device using ivanti neurons for mdm to register your ios device with email+, see the device registration (ios, macos, and android) section in the procedure in the ivanti neurons for mdm admin portal, go admin >user click on +add to add a user, select the user type click done new user is added in the go client, log in with the user details after registering on go client the device is listed under the devices tab in ivanti neurons for mdm
