Skip Navigation

iOS
: Email profile settings

iOS
: Email profile setting
Description 
Delivery settings
Allow messages to be moved
This setting specifies whether users can move email messages from this account to another existing email account on an 
iOS
 device.
Allow recent addresses to be synced
This setting specifies whether an 
iOS
 device user can sync recently used addresses across devices.
Use only in Mail
This setting specifies whether apps other than the Mail app on an 
iOS
 device can use this account to send email messages.
Enable S/MIME 
This setting specifies whether an 
iOS
 device user can send S/MIME protected email messages.
Enable digitally signed S/MIME messages
This setting specifies whether a device sends outgoing messages with a digital signature.
This setting applies only to 
iOS
 10.3 and later devices
Signing credentials 
This setting specifies how devices find the certificates required to sign messages. 
This setting is valid only if the "Enable S/MIME" setting is selected.
Possible values:
  • Shared certificate
  • SCEP
  • User credential
After you choose the profile type you want to use, you specify the shared certificate, SCEP, or user credential profile.
Signing shared certificate
This setting specifies the shared certificate profile for a client certificate that an 
iOS
 device uses to sign email messages.
This setting is valid only if the "Enable S/MIME" setting is selected.
Signing SCEP
This setting specifies the SCEP profile that devices can use to retrieve the certificates required to sign email messages using S/MIME.
This setting is valid only if the "Enable S/MIME" setting is selected.
Signing user credential
This setting specifies the user credential profile that devices can use to obtain the client certificates required to sign email messages using S/MIME.
This setting is valid only if the "Enable S/MIME" setting is selected.
User can turn on or turn off S/MIME signing
This setting specifies whether a user is allowed to turn on or turn off S/MIME signing. This setting applies only to  
iOS
  12.0 and later devices.
User can change signing credentials
This setting specifies whether a user can override signing credentials. This setting applies only to  
iOS
  12.0 and later devices.
Enable S/MIME message encryption
This setting specifies whether a device encrypts outgoing email messages with S/MIME encryption.
This setting applies only to 
iOS
 10.3 and later devices
Encryption credentials
This setting specifies how devices find the certificates required to encrypt messages.
Possible values:
  • Shared certificate
  • SCEP
  • User credential
After you select the profile type, you select the shared certificate, SCEP, or user credential profile that you want to use.
This setting is valid only if the "Enable S/MIME" setting is selected.
Encryption shared certificate 
This setting specifies the shared certificate profile for a client certificate that an 
iOS
 device can use to encrypt email messages.
Devices choose the appropriate certificate for the recipient to encrypt messages using S/MIME.
This setting is valid only if the "Enable S/MIME" setting is selected.
Encryption SCEP
This setting specifies the SCEP profile that devices can use to retrieve the certificates required to encrypt email messages using S/MIME.
This setting takes effect only if the "Enable S/MIME" setting is selected.
Encryption user credential
This setting specifies the user credential profile that devices can use to retrieve the client certificates required to encrypt email messages using S/MIME.
This setting takes effect only if the "Enable S/MIME" setting is selected.
User can override S/MIME encryption
This setting specifies whether a user can turn on or turn off the encryption setting. This setting applies only to 
iOS
 12.0 and later devices.
User can override S/MIME encryption credentials
This setting specifies whether a user can override S/MIME encryption credentials. This setting applies only to 
iOS
 12.0 and later devices.
Encrypt messages
This setting specifies whether all email messages must be encrypted when the user sends them (Required), or if the user can choose which messages to encrypt at the time they send them (Allow).
This setting takes effect only if the "Enable S/MIME" setting is selected.
Possible values:
  • Required
  • Allow
The default value is "Required."
The minimum requirement is 
iOS
 version 8.0 and devices must be activated with MDM controls.
Days to synchronize
This setting specifies the number of days in the past to synchronize email messages and organizer data to an 
iOS
 device.
Possible values:
  • 1 day
  • 3 days
  • 7 days
  • 14 days
  • 1 month
  • Forever
The default value is "7 days."
This setting applies only to the default mail and organizer apps on 
iOS
 devices with the 
MDM controls
 activation type.
Authentication
Enable 
BlackBerry Secure Gateway
This setting specifies whether 
iOS
 devices with the 
MDM controls
 activation type use the 
BlackBerry Secure Gateway
 to connect to the mail server. The 
BlackBerry Secure Gateway
 provides a secure connection to your organization's mail server through the 
BlackBerry Infrastructure
 and 
BlackBerry UEM
. Before you enable this service, you must verify that your organization has the appropriate 
BlackBerry UEM
 licenses. For more information, see the Licensing content.
If you configured server groups to direct 
BlackBerry Secure Gateway
 traffic to a specific regional connection to the 
BlackBerry Infrastructure
, you must associate the email profile with the appropriate server group.
Authentication type
This setting specifies the type of authentication an 
iOS
 device uses to connect to the mail server.
This setting is valid only if the "Enable BlackBerry Secure Gateway" setting is not selected.
Possible values:
  • None
  • Shared certificate
  • SCEP
  • User credential
The default value is "None."
Shared certificate profile
This setting specifies the shared certificate profile for the client certificate that an 
iOS
 device uses to connect to the mail server.
This setting is valid only if the "Enable BlackBerry Secure Gateway" setting is not selected and the "Authentication type" setting is set to "Shared certificate."
Associated SCEP profile 
This setting specifies the associated SCEP profile that an 
iOS
 device uses to enroll a client certificate to use for authentication with the mail server.
This setting is valid only if the "Enable BlackBerry Secure Gateway" setting is not selected and the "Authentication type" setting is set to "SCEP."
Associated user credential profile
This setting specifies the associated user credential profile that an 
iOS
 device uses to enroll a client certificate to use for authentication with the mail server.
This setting is valid only if the "Enable BlackBerry Secure Gateway" setting is not selected and the "Authentication type" setting is set to "User credential."
Use credentials and certificate
This setting specifies whether a device uses credentials and a client certificate obtained using the associated SCEP profile to authenticate with the mail server.
This setting is valid only if the "Enable BlackBerry Secure Gateway" setting is not selected and the "Authentication type" setting is set to "SCEP."
Use SSL 
This setting specifies whether a device must use SSL to connect to the mail server.
Accept all SSL certificates
This setting specifies whether all SSL certificates are accepted.
External email domains
External email domain allowed list
This setting specifies the list of domains that a user can send work email or calendar entries to. For example, when a user adds a recipient who has an email address in the allowed domain to an email message or calendar entry, no warning message is displayed. This setting applies to the work space only.
If you list multiple domain names, separate the domain names with a comma (,), semicolon (;), or space. 
External email domain restricted list
This setting specifies the list of domains that users cannot send work email or calendar entries to. For example, if a user tries to add a recipient with an email address from the restricted domain to an email message or calendar invitation, the 
Work Connect
 app prevents the user from completing the task. This setting applies to the work space only. 
If you list multiple domain names, separate the domain names with a comma (,), semicolon (;), or space.
Allow 
Mail Drop
This setting specifies whether users can send files from this account using 
Mail Drop
.
The minimum requirement is 
iOS
 version 9.0 and devices must be activated with MDM controls.