Main configuration steps for Ivanti Email+ for Android AppConnect (Ivanti EPMM)
Following are the main steps for configuring and deploying Email+ for Android AppConnect on Ivanti EPMM:
- Adding Ivanti Email+ for Android AppConnect and Secure Apps Manager to Ivanti EPMM.
- Enabling third-party AppConnect apps in Ivanti EPMM.
- Configuring the AppConnect global policy in Ivanti EPMM.
- Configuring the AppConnect container policy in Ivanti EPMM.
- Configuring an AppConnect app configuration for Ivanti Email+ in Ivanti EPMM.
- Configuring email attachment control with Standalone Sentry in Ivanti EPMM. (For Standalone Sentry deployments only)
Adding Ivanti Email+ for Android AppConnect and Secure Apps Manager to Ivanti EPMM
You add Email+ and Secure Apps Manager (SAM), in the same manner you would add any other Android in-house app. After adding the apps to Ivanti EPMM, you can distribute the apps to devices by applying the apps to labels that contain the devices you want to distribute the apps.
Procedure
- In the Ivanti EPMM Admin Portal, go to Apps > App Catalog > Add+ > In-House. (Prior to Ivanti EPMM 8.0 go to Apps > App Distribution Library, and select Add App).
- Add the apps just as you would any in-house app. Add SAM if you have not already uploaded it to support other secure apps.
- After adding the apps, apply the apps to appropriate labels so that they are available to the required devices.
Next steps
Continue on to Enabling third-party AppConnect apps in Ivanti EPMM.
For information on adding in-house apps for Android, see “Working with Apps for Android devices” in the Ivanti EPMM Apps@Work Guide.
Enabling third-party AppConnect apps in Ivanti EPMM
Email+ requires that you enable the licensing option for third-party and in-house AppConnect apps.
Procedure
- In the Ivanti EPMM Admin Portal, go to Settings > System Settings.
- Click Additional Products > Licensed Products.
- Select AppConnect For Third-party And In-house Apps if your organization has purchased it.
- Click Save.
Next steps
Continue to Configuring the AppConnect global policy in Ivanti EPMM.
Configuring the AppConnect global policy in Ivanti EPMM
Because Email+ for Android is an AppConnect app, you need to configure an AppConnect global policy (if one has not already been configured). This policy specifies settings that apply to all AppConnect apps on a device. For example, you configure the AppConnect passcode requirements.
Make sure only one AppConnect global policy applies to each device.
On the AppConnect global policy, you can authorize device users to use Email+ even if no AppConnect container policy is applied to the device.
Procedure
- In the Ivanti EPMM Admin Portal, go to Policies & Configs > Policies.
- Select Add New > AppConnect. You can also use an existing AppConnect global policy. Select it, and click Edit.
- Complete the form. Most fields default to suitable values, but make sure that you select AppConnect: Enabled to enable AppConnect on the device.
- Click Save.
- Select the policy.
- Select Actions > Apply To Label.
- Select the labels to which you want to apply this policy.
- Click Apply.
Next steps
Continue to Configuring the AppConnect container policy in Ivanti EPMM.
For general details on the AppConnect global policy, see “Configuring the AppConnect global policy” in the Ivanti AppConnect for Ivanti EPMM Guide and Ivanti Tunnel for Android Guide.
Configuring the AppConnect container policy in Ivanti EPMM
This task is only required:
- If you did not select Authorize for Apps without an AppConnect container policy, in the AppConnect Global Policy.
- If you want to apply different data loss prevention policies to different devices. When you upload Email+ to Ivanti EPMM, Ivanti EPMM automatically creates an AppConnect container policy for the app. Create an AppConnect container policy, if you want to apply different settings to different devices.
- Make sure only one AppConnect container policy for Email+ is applied to each device.
- Ivanti EPMM keeps in sync the labels that you apply to the app and the labels that you apply to the AppConnect container policy that Ivanti EPMM automatically created.
When you apply Email+ to a label, Ivanti EPMM automatically adds the same label to the automatically-created AppConnect container policy. Be sure to remove that label from the automatically-created AppConnect container policy if you are using that label on a manually created AppConnect container policy.
Procedure
- In the Ivanti EPMM Admin Portal, go to Policies & Configs > Configurations.
- Click Add New > AppConnect > Container Policy.
- Alternatively, edit the automatically-created AppConnect container Policy for Email+.
- Enter a name for the policy.
- Enter a description for the policy.
- In the Application field, choose the Email+.
- Select Allow Screen Capture if you want to override the default restriction on screen capture.
- The remaining settings do not apply to Android. Also, the ability to open a document is always restricted to the secure container on Android devices.
- Click Save.
Next steps
- If you created a new container policy, continue to Applying the container policy to labels in Ivanti EPMM.
- If you edited the automatically-created AppConnect container policy, continue to Configuring an AppConnect app configuration for Ivanti Email+ in Ivanti EPMM.
Applying the container policy to labels in Ivanti EPMM
Do these steps if you created a new AppConnect container policy.
Procedure
- Select the container policy.
- Select Actions > Apply To Label.
- Select the labels to which you want to apply this policy.
- Click Apply.
Next steps
Continue to Removing labels from the automatically-created AppConnect container policy in Ivanti EPMM.
Removing labels from the automatically-created AppConnect container policy in Ivanti EPMM
Do these steps if you are not using the automatically-created AppConnect container policy.
Procedure
- Select the automatically-created AppConnect container policy.
- Select Actions > Remove From Label.
- Select any labels that you applied to the AppConnect container policy that you just created.
- Click Remove.
Next steps
Continue to Configuring an AppConnect app configuration for Ivanti Email+ in Ivanti EPMM.
Configuring an AppConnect app configuration for Ivanti Email+ in Ivanti EPMM
When you add Email+ for Android AppConnect, an AppConnect app configuration is automatically created for Email+. You can create a new AppConnect app configuration if you want to apply different settings to different devices. Otherwise, edit the automatically-created AppConnect app configuration to configure the ActiveSync server information and other settings that you want to customize.
The AppConnect app configuration for Email+ for Android AppConnect contains information such as:
- The fully qualified domain name and user ID for the ActiveSync server.
- Certificate information.
- Key-value pairs that determine the app’s settings and behavior.
The default configuration contains the bundle ID for the app and a set of default key-value pairs that can be edited or deleted. You can also configure additional key-value pairs.
Make sure only one AppConnect app configuration for Email+ is applied to each device.
Always set the value of the email_device_id key to $DEVICE_UUID_NO_DASHES$. Standalone Sentry uses this key-value pair for ActiveSync correlation.
Procedure
- In the Ivanti EPMM Admin Portal, go to Policy & Configs > Configurations.
- Select the automatically-created AppConnect app configuration for Email+ for Android, and click Edit.
- Edit the configuration as needed.
- Click Save. The automatically-created app configuration has the same labels you applied to the app. You do not need to apply the automatically-created app configuration to a label.
- For a description of the fields see AppConnect app configuration field descriptions.
- For descriptions and list of supported key-value pairs, see Key-value pairs for Ivanti Email+ (Android AppConnect).
Creating a new AppConnect app configuration for Ivanti Email+ for Android
Create a new AppConnect app configuration by saving the automatically created AppConnect app configuration for Email+ if you want to apply different settings to different devices.
Procedure
- In the Admin Portal, go to Policy & Configs > Configurations.
- Select the automatically created AppConnect app configuration for Email+.
- Click Actions > Save As and save it as a new configuration.
- Enter a new name and description for the configuration.
- Edit the configuration as needed.
- Click Save.
- Select the new AppConnect app configuration.
- Select Actions > Apply To Label.
- Select the labels to which you want to apply this AppConnect app configuration.
- Click Apply. The automatically-created app configuration is automatically applied to the same labels you applied to the app. However, only one app configuration should be applied to any one device. Therefore, remove the labels from the automatically-created app configuration.
- Select the automatically-created AppConnect app configuration.
- Select Actions > Remove From Label.
- Select any labels that you applied to the AppConnect app configuration that you just created.
- Click Remove.
- For a description of the fields, see AppConnect app configuration field descriptions.
- For descriptions and list of supported key-value pairs, see Key-value pairs for Ivanti Email+ (Android AppConnect).
AppConnect app configuration field descriptions
The following table provides description of the fields in an AppConnect app configuration for Email+ for Android.
Item |
Description |
Name |
Edit the default name if necessary. The name is not the same as the name that appears in the name column in Policy & Configs > Configurations. |
Description |
If necessary, edit the text to clarify the purpose of this AppConnect app configuration. |
Application |
Email+ is selected. |
AppTunnel Rules To configure AppTunnel for Android AppConnect, see Configuring Email+ with AppTunnel for Android AppConnect. Email+ app might use AppTunnel as VPN if the email_exhcnage_host KVP is set as the ActiveSync server and if this server is not accessible from public network. AppTunnel is not used if Standalone Sentry used in the email_exchange_host KVP. If you are using a Standalone Sentry, all communication with the ActiveSync server is through a secure connection to the Standalone Sentry. |
|
App-specific Configurations Add key-value pairs to configure app behavior. The automatically-created app configuration for Email+ contains a set of default key-value pairs. Each key-value pair is configured as a separate row. Do the following:
The following key-value pairs are required:
|
Configuring email attachment control with Standalone Sentry in Ivanti EPMM
This is only required if attachment control is enabled in Standalone Sentry.
Procedure
- In the Ivanti EPMM Admin Portal, go to Services > Sentry.
- Select the Standalone Sentry that handles email for the devices.
- Click the edit icon.
- In the Attachment Control Configuration section, for iOS and Android Using Secure Email Apps, select Open With Secure Email App.
- Click Save.
See “Email Attachment Control with Standalone Sentry” in the Ivanti Sentry Guide for Ivanti EPMM.