You can provision Exchange ActiveSync e-mail accounts on iOS and Android (Samsung Knox compatible only) devices enrolled in a Systems Manager network. Deploying emall configurations can greatly simplify the end device user's experience to receive corporate emails. Additionally, account settings can be configured in order to ensure corporate emails are securely accessed.
To configure an Exchange ActiveSync Profile for an iOS device:
1. Assign device owner
2. Configure Exchange ActiveSync payload
3. Deploy profile to device(s)
Assign Device Owner
Enrolled devices should be assigned to a device user whose email account will be accessed from the device. The device owner can be assigned from two different places:
Option 1 (single device)
- The username field should be the full email account address.
- A domain can be added to the username field (e.g., DOMAIN\user)
- Navigate to Monitor > Clients.
- Select a client to assign a device owner and go to the client's details page.
- Under the 'client details' section, select 'Set an owner.'
- Assign a device owner.
Option 2 (multiple devices)
- Navigate to the Configure > Owners page.
- Select 'Add a new owner' or 'Update from CSV file'
- Configure owner(s) and assign one or more devices.
Configure Exchange ActiveSync Payload
- Account name: Description of the email account that will be displayed on the device.
- Exchange host: Address of the exchange email server.
- Past days to sync mail: Determines the email archive available on the device.
- Use only in Mail: Prohibits sending messages from other applications, such as Safari or Photos. If checked, configured exchange account cannot be selected as default mail account on device.
- Use SSL: Mail is sent to exchange server using an encrypted SSL connection.
- Enable S/MIME: A client certificate is used to sign and encrypt outgoing mail. Certificate must be imported onto device.
- An individual User can also be configured. If specify a user is selected, each device receiving the specified configuration profile will receive the same email account settings.
- Navigate to the ActiveSync tab on the MDM > Settings page.
- Ensure desired configuration profile is selected from 'profile' pull-down (for more information on creating profiles for managed devices, please go here).
- Select 'Create an Exchange account.'
- Configure the Exchange ActiveSync settings.
- Save changes.
Deploy Profile to Device(s)
- After saving changes, devices within the scope of the configured profile will receive the Exchange ActiveSync settings the next time it is able to check-in with the Meraki Cloud.
- Unless a password is inputted from the specify a user option, the device user will be prompted for their email account password before accessing the account's emails.
- For more information on creating profiles for different devices, please consult this Knowledge Base article.
Common Troubleshooting Tips
- Updating a profile with an ActiveSync payload will reset all local email account settings on the devices. Device users will then have to manually re-configure the settings for the email account (e.g., password, default mail account, mail badge notifications).
- It is recommended that an additional profile be created to host only the Exchange ActiveSync payload. This method will ensure that non-related changes to a configuration profile will not impact the Exchange ActiveSync account settings.
- If an Exchange ActiveSync account already exists on the iOS device that is identical to the ActiveSync payload set to deploy via Systems Manager, the entire configuration profile will fail to install. This is because Apple/iOS prohibits multiple identical email accounts on an iOS device. When an identical Exchange ActiveSync is deployed to a device, an 'Error - Profile Installation Failed' error will log in the client's Activity Log at bottom of its details page.
- To resolve the error, either manually remove the existing email account from the device itself, or remove the ActiveSync payload from the configuration profile in Systems Manager.