Key-value pairs for customization Ivanti Email+ for iOS
2 min
key value pairs for customization docid\ fidbv5n89hmfjspm6wnml describes the key value pairs available to administrators to customize email+ for ios app behavior these key value pairs define app behavior such as providing detailed notifications to device users and export contacts from email+ key value pairs marked as ivanti epmm only are not applicable to ivanti neurons for mdm for ivanti neurons for mdm deployments, these key value pairs are either provided as fields in ivanti neurons for mdm or are set automatically and do not require action from the administrator see ivanti email+ configuration field description (ivanti neurons for mdm) docid 9d00ahvegsfkg1tqgrzsj for a description of the fields in ivanti neurons for mdm some values can use ivanti epmm variables, such as $email$ ivanti epmm substitutes the device user’s value when sending the app configuration to the device you can configure and customize the following features with key value pairs required key value pairs docid\ fidbv5n89hmfjspm6wnmlbackground email check and user notifications docid\ fidbv5n89hmfjspm6wnmlcertificates docid\ fidbv5n89hmfjspm6wnmls/mime docid\ fidbv5n89hmfjspm6wnmlmanage contacts docid\ fidbv5n89hmfjspm6wnmlsyncing docid\ fidbv5n89hmfjspm6wnmlmaximum size for email docid\ fidbv5n89hmfjspm6wnmlemail attachments docid\ fidbv5n89hmfjspm6wnmlopen links in a browser docid\ fidbv5n89hmfjspm6wnmldefault signature docid\ fidbv5n89hmfjspm6wnmlssl docid\ fidbv5n89hmfjspm6wnmlgal search docid\ fidbv5n89hmfjspm6wnml key value enter/ select one description required key value pairs email address (ivanti epmm only) email address of the device user typically, this field uses the ivanti epmm variable $email$ you can also use combinations of these ivanti epmm variables, depending on your activesync server requirements $userid$, $user custom1$, $user custom2$, $user custom3$, $user custom4$ email device id (ivanti epmm only) $device uuid no dashes$ identifies the device to the activesync server always use the ivanti epmm variable $device uuid no dashes$ email exchange host (ivanti epmm only) fqdn of the activesync server or standalone sentry the fully qualified domain name of the activesync server if you are using a standalone sentry, enter the fully qualified domain name (fqdn) of standalone sentry example \<font color="#000000">mysentry mycompany com\</font> email exchange username (ivanti epmm only) user id for the activesync server the user id for the activesync server typically, you use the ivanti epmm variable $userid$ if your activesync server requires a domain, use \<domain name> \\$userid$ for example mydomain\\$userid$ you can also use combinations of these ivanti epmm variables, depending on your activesync server requirements $email$, $user custom1$, $user custom2$, $user custom3$, $user custom4$ this kvp is case sensitive enter the key in lower case key value pair value behavior updated as part of msal changes the email address kvp value is now is now used for authentication instead of email exchange username microsoft authentication library (msal), which is now used instead of the deprecated microsoft azure active directory authentication library (adal) thus, email address and email exchange username should have same values for upgrade to email+ 5 0 after upgrading to email+ 5 0 0, re authentication is must to obtain a new token due to a limitation in the msal library microsoft authenticator will be used for email+ authentication if it is installed background email check and user notifications allow detailed notifications (ivanti epmm only) true false true device user sees detailed notifications the details can include sensitive information such as email subject, or event titles and times false notifications do not include any details default if key value is not configured false should cache tunneling config true false use the key should cache tunnelling config along with the key allow device keychain true the configuration will be cached by appconnect, as a result device user sees detailed push notifications and badge count (number of unread mails) after force closing the app false the configuration is not cached default if key value is not configured false certificates allow certificate revocation check true false true allows crl check default if key value is not configured false allow device keychain true false true email+ stores the decryption key received from the uem client in the device keychain this allows email+ to access its credentials and check email when ios launches it in the background, thus improving background email notifications false the appconnect content decryption key is not stored on the device ivanti recommends that customers set this to true in conjunction with a strong device passcode for more information see background email checks and user notifications docid\ zhwrnoutg8q3gsufmvkyf default if key value is not configured false email login certificate (ivanti epmm only) from the dropdown list the device uses the certificate for authentication see the for your deivce platform for information on configuring certificate enrollment settings if the certificate is password encoded, ivanti epmm automatically also sends another key, email login certificate mi cert pw, with the password as the certificate’s value this key is required if sentry is configured to require certificates default if key value is not configured certificates are not used email trust all certificates (ivanti epmm only) true false true email+ automatically accepts untrusted certificates typically, you enter true only when working in a test environment false email+ does not accept untrusted certificates default if key value is not configured false email user certificate self service (ivanti epmm only) from the dropdown list allows the administrator to distribute certificates to device users users can then upload the certificates manually to the ivanti epmm user portal email certificate x where x is 1 through 10 from the dropdown list you can designate up to ten certificate authority (ca) root certificates as trusted email+ imports the certificate into its keychain of trusted certificates, and trusts any certificates derived from the ca root certificate in its keychain designating a ca root certificate as trusted is necessary for the following you have configured device authentication in standalone sentry to require a certificate whose certificate authority is not a trusted ca a common scenario for this case is if you are using a self signed certificate or a certificate that is not derived from a well known certificate authority you specify this certificate to email+ in the key email login certificate it corresponds to the certificate you specified for device authentication in standalone sentry configuration in the ivanti epmm admin portal you have configured certificates for encrypting or signing s/mime emails and these certificates are self signed or not derived from a well known certificate authority you specify these certificates in the keys email encryption certificate and email signing certificate use der format instead of normal pem format for email certificate x certificates s/mime email encryption certificate from the dropdown list specifies the certificate to use for encrypting s/mime emails the uem sends the contents of the certificate as the value email+ imports the key into the keystore and selects the certificate as the encryption certificate if you change the certificate, email+ imports the new certificate into the keychain and selects the new certificate as the encryption certificate it leaves the previous certificate in the keychain if you delete the key value pair, email+ leaves the certificate in the keychain, while changing its settings to specify that no certificate is selected as the encryption certificate for more information about configuring s/mime for email+ for ios, see s/mime support in ivanti email+ for ios docid\ g8jnyhoejf7m mdzdb2ah default if key value is not configured certificate is not configured for s/mime certificates use der format instead of normal pem format email signing certificate from the dropdown list specifies the certificate to use for signing s/mime emails the uem sends the contents of the certificate as the value email+ imports the key into the keychain and selects the certificate as the signing certificate if you change the certificate, email+ imports the new certificate into the keychain and selects the new certificate as the signing certificate it leaves the previous certificate in the keychain if you delete the key value pair, email+ leaves the certificate in the keychain and changes its settings to specify that no certificate is selected as the signing certificate for more information about configuring s/mime for email+ for ios, see s/mime support in ivanti email+ for ios docid\ g8jnyhoejf7m mdzdb2ah default if key value is not configured certificate is not configured for s/mime certificates use der format instead of normal pem format email encryption algorithm aes 256, aes 192, aes 128 configures encryption algorithim the default value is set to sha 256 email signing digest sha 1 sha 256 sha 384 sha 512 configures signature algorithim the default value is set to sha 256 the restriction is empty by default if there is no value or invalid value set, then sha 1 is used s/mime support for retired certs email escrow certificates each dictionary consists of the following two keys email escrow certificates email escrow certificates mi cert pw use this option to use the multiple retired certificate for decrypting older messages this value corresponding to this kvp is an array of dictionaries email escrow certificates is a base64 encoded p12 archive with certificate and private key email escrow certificates mi cert pw is a password string to unpack archives manage contacts allow export contacts (ivanti epmm only) true false true allows email+ users to export email+ contacts to an email+ contacts group on the personal side of the device when device users export the contacts, they can see the caller id of incoming calls from phone numbers in the list of corporate contacts third party apps can also access the corporate contacts false device users cannot export the email+ contacts they see the caller id only for personal contacts default if key value is not configured false contact details are exported, excluding the notes field due to apple limitations limit contact export to (ivanti epmm only) name number all name number limits the exported contact information to each contact’s name, number, phonetic first name, and phonetic last name all exports all contact information for each contact this field is used only if allow export contacts is set to true if you enter a value other than all or name number, email+ for ios uses the value all default if key value is not configured all email safe domains a comma separated list of safe domains ensure that there are no spaces before or after the comma a wildcard in the domain name is supported the only format supported for domain names with a wildcard is domainname com entering only will make all domains safe base domain is not included in the wildcard domain, it needs to be added explicitly if required for example, domainname com, domainname com email addresses not in the safe domain list are displayed in red color in email+ this configuration minimizes the risk that a user will accidentally send internal emails to external email addresses you may want to use this key value pair if your company policy requires this risk mitigation step if your company has multiple domains and you want to identify your company’s domains as opposed to domains that are not your company domains example mycompany com,mycompany net,internal mycompany com default if key value is not configured only the domain of the email account is safe email alert unsafe domains true false true users see an alert if the recipients in an email or calendar invite include addresses that are not in a safe domain for the alert to be displayed, the email safe domains key must also be configured false an alert is not displayed for addresses not in a safe domain default if key value is not configured false syncing email max sync period 0 1 2 3 4 5 controls the maximum number of days for which emails are synced 0 = download all emails 1 = download emails received over the last day 2 = download emails received over the last 3 days 3 = download emails received over the last week 4 = download emails received over the last 2 weeks 5 = download emails received over the past month default if key value is not configured 0 device users can change the interval to a value less than the default maximum this feature is useful for regulatory purposes, if an organization requires device users to have no more than n days of emails on their devices if the maximum email synchronization (email max sync period) period is less than the default email synchronization period, then the maximum value is used email default sync period 0 1 2 3 4 5 controls the default time interval for which emails are downloaded 0 = download all emails 1 = download emails received over the last day 2 = download emails received over the last 3 days 3 = download emails received over the last week 4 = download emails received over the last 2 weeks 5 = download emails received over the past month default if key value is not configured 2 ivanti does not recommend setting the value as 0, as downloading all emails could take a very long time, and take up too much space on the device maximum size for email email max body size a number specifies the maximum size in megabytes permitted for each email that is received this feature allows administrators to manage bandwidth and memory consumption on devices by restricting the maximum size of individual emails if the size of the email is greater than the default or configured size, users are presented with the following message and the email cannot be downloaded email+ maximum message size exceeded default if key value is not configured 4 mb email attachments email max attachment a number specifies the maximum size in megabytes permitted for downloading each email or event attachment if you set the maximum value to 10mb, a device user who receives an email that includes attachments of 3mb, 9mb, and 10mb will be able to download each attachment if, however, a device user receives an email with an 11mb attachment, the following alert is displayed and users cannot download the attached file failed to retrieve attachment email+ maximum attachment size exceeded this limitation for outgoing emails is not controlled by this kvp , the following alert is presented warning the message size exceeds 10 mb please confirm you would like to continue users have the option to either cancel or proceed if users tap proceed, the email is successfully sent this feature allows administrators to manage bandwidth and memory consumption on devices by restricting the maximum size of individual email attachments default if key value is not configured 10 mb calendar attachments true false enabled viewing of files attached to calendar meeting invites this feature requires exchange web services to be configured email+ fetches calendar attachments via an ews api if email+ is configured through sentry, then additional key value pair email ews host is needed with server address the email exchange host is used automatically, but it is configured through sentry email ews host default if key value is not configured false mi shared group id a unique, sufficiently complex alphanumeric string required to enable attaching of files from docs\@work ensure that the key value pair is configured in the docs\@work configuration as well and that the value is identical (including case) in both email+ and docs\@work configurations the key is case sensitive enter the key in upper case configure mi enable doc sharing with value true in the docs\@work configuration mi ac access control id a unique, sufficiently complex alphanumeric string required to enable attaching of files from docs\@work ensure that the key value pair is configured in the docs\@work configuration as well and that the value is identical (including case) in both email+ and docs\@work configurations the key is case sensitive enter the key in upper case configure mi enable doc sharing with value true in the docs\@work configuration open links in a browser links in email+ are opened by default in web\@work if web\@work is not installed on the device, email+ for ios displays an error however, administrators can specify the default browser to use when device users click links in email+ administrators can configure the default browser to be used for both http and https links, using customized url schemes this allows finer control over the browser used to open http and https links, respectively additionally, this key can be used to configure a customized browser as the one that launches when a device user clicks a link in email+ allow safari browser (ivanti epmm only) true false true allows email+ to open urls (included, for example, in an email) in safari if the allow safari browser key is configured, the values of email url scheme http and email url scheme https are ignored default if key value is not configured false email url scheme http mibrowser googlechrome firefox microsoft edge http touch http mibrowser opens links in web\@work for ios googlechrome opens links in chrome firefox opens links in firefox microsoft edge http opens links in microsoft edge touch http opens links in opera default if key value is not configured mibrowser email url scheme https mibrowsers googlechromes firefox microsoft edge https touch https mibrowsers opens links in web\@work for ios googlechromes opens links in chrome firefox opens links in firefox microsoft edge https opens links in microsoft edge touch https opens links in opera default if key value is not configured mibrowsers webatwork install link(ivanti epmm only not supported on ivanti neurons for mdm) url for web\@work if web\@work is not installed on the device, device users are prompted to install web\@work when they click on a webpage link in an email in email+ if users accept the prompt, they are redirected to apps\@work for installing web\@work the web\@work url is available in the app catalog in the ivanti epmm admin portal in ivanti epmm, go to apps > app catalog, click on the web\@work app, and then click global in the global settings, for app url, click copy link to clipboard paste the link as the value default signature email default signature (ivanti epmm only) the default email signature the value of this key is the default email signature for all emails however, the device user can define the default email signature at any time, overriding this key’s value after the user defines the default email signature, email+ does not use the value in the key, even if you update it default if key value is not configured sent by email+ for ios managed by mobileiron ssl email ssl required (ivanti epmm only) true false true secures communication using https to the server specified in email exchange host default if key value is not configured true gal search gal search minimum characters (ivanti epmm only) a number the minimum number of characters email+ uses for automatic global address list (gal) lookup in mail and contacts when device users enter the specified number of characters of a name, email+ searches the gal and presents the matches that it finds on your exchange server, set the minimum number of characters for gal search to the same value you set for this key if you do not, gal search will not work properly in email+ default if key value is not configured 4 gal search display name true false true enables display name in email+ settings > contacts by default false disables display name in email+ settings > contacts by default default if key value is not configured true contacts display order first last last first sets the default display order for contact names in search results device users can change the display order in email+ in settings > contacts the values are case sensitive; enter in lower case first last contact names in search results are displayed with first name followed by the last name last first contact names in search results are displayed with last name followed by the first name default if key value is not configured first last classification markers email security classification json is equal to json representation of json configuration is equal to json representation of classification configuration for json sample format see, classification markers docid 3ecev0i3rggtq8pi137vg section allows the admin to configure email classification markers, for secure sharing of mail and calendar events the mail is marked with a marker that defines security of the mail you can add any of the following markers to a mail unofficial official secret protected top secret
