BlueMail Work · MDM & EMM

Enterprise-managed.
Employee-approved.

BlueMail deploys, configures and governs itself through the device management platform you already run. Push a policy once and it lands on every device, while personal data stays personal.

AppConfig standard Zero-touch deployment BYOD-safe iOS · Android · Desktop Selective wipe
The alphabet, untangled

MDM, EMM, UEM, MAM: what's the difference?

The industry loves its acronyms. Here's what each one actually means, and where BlueMail fits. Spoiler: it works with all of them.

MDM

Mobile Device Management

Manages the device itself: enrollment, OS-level policies, encryption requirements, remote lock and full-device wipe. The foundation every fleet starts with.

EMM

Enterprise Mobility Management

MDM plus the app layer: app distribution, managed configurations, per-app policies and content controls. This is where BlueMail plugs in deepest.

UEM

Unified Endpoint Management

One console for every endpoint: mobile, desktop, rugged. BlueMail runs on iOS, Android, Windows, Mac and Linux, so a single UEM policy covers your whole fleet.

MAM

Mobile Application Management

Controls the app, not the device. Ideal for BYOD: wipe BlueMail's corporate data without enrolling, or ever touching, an employee's personal phone.

Works with your stack

The platforms you already run.

No proprietary agent, no parallel console. BlueMail speaks the AppConfig Community standard, so it behaves like a first-class citizen in every major management platform.

Microsoft Intune

Managed app config, app protection policies and conditional launch, with Microsoft Entra ID signals built in.

Jamf Pro

Managed distribution and configuration for Apple fleets, Mac and iOS side by side.

Ivanti (MobileIron)

AppConnect containers and standards-based managed configurations for regulated industries.

SOTI MobiControl

Rugged, kiosk and single-purpose deployments with locked-down profiles.

Any AppConfig EMM

BlueMail follows the AppConfig Community standard, so any standards-based platform works out of the box.

Managed configuration

Accounts that set themselves up.

Define the configuration once in your MDM and BlueMail reads it on first launch: account, servers, authentication, security posture. Variables like the user's principal name resolve per device, so one payload provisions a thousand inboxes.

Policies are enforced at the app level and re-evaluated continuously. Change a rule in your console and the fleet follows. No reinstall, no re-enrollment.

Managed app configuration · AppConfig
email.address{{userprincipalname}}
email.servermail.acme.com
auth.methodModern OAuth
policy.lock_screenRequired · 5 min
policy.copy_pasteManaged apps only
policy.screenshotsBlocked
policy.remote_wipeApp data only
BYOD, done right

Corporate control. Personal privacy.

Most of your workforce reads corporate email on a personal phone, and they shouldn't have to hand it over to IT to do so. BlueMail supports app-level management (Android Enterprise work profiles, Apple User Enrollment and pure MAM deployments), so your policies govern the corporate inbox and nothing else.

IT can enforce lock-screen rules, block risky attachments and wipe corporate mail the moment someone leaves. What IT can never do is see personal photos, private messages or browsing history. That line is architectural, not a promise.

Personal Invisible to IT
Photos Chat Bank Music
Work profile Managed
BlueMail
✓ Config pushed ✓ Wipe scope: app data
Lifecycle

From first boot to last day.

01

Enroll

Zero-touch deployment through your MDM. BlueMail lands on every managed device silently. No user setup, no IT tickets.

02

Configure

Push accounts, servers and branding as a managed configuration. Employees open the app and their corporate inbox is simply there.

03

Enforce

App-level policies follow the device everywhere: lock-screen rules, copy-paste boundaries, attachment handling, screenshot control.

04

Retire

Offboarding is one action: revoke access and wipe corporate data remotely, while personal photos and chats stay untouched.

Device management questions, answered

The short answers.

Which MDM platforms does BlueMail support?

Any platform that implements the AppConfig Community standard, including Microsoft Intune, Jamf Pro, Ivanti (MobileIron) and SOTI MobiControl. If your EMM can push a managed configuration, it can manage BlueMail.

Do personal (BYOD) devices need full enrollment?

No. BlueMail works inside Android Enterprise work profiles, Apple User Enrollment and pure MAM deployments, so IT governs the corporate inbox without enrolling, or even seeing, the rest of the device.

What happens when an employee leaves?

One action in your console revokes access and wipes BlueMail's corporate data remotely. Personal photos, messages and apps are untouched. The wipe scope is the app, not the phone.

Can accounts be pre-configured before first launch?

Yes. Push account, server and policy settings as a managed configuration; variables like the user principal name resolve per device, so a single payload provisions the entire fleet.

Does MDM replace the BlueMail Admin Console?

They're complementary. Your MDM handles deployment and device-side policy; the Admin Console adds BlueMail-side fleet visibility, usage insights and email-specific controls.

Your MDM. Our app. Zero friction.

Deploy BlueMail to your whole fleet this week.

Talk to sales