Skip to content

Can I deploy BlueMail with MDM?

Yes. BlueMail is built to be rolled out by an IT team rather than configured device by device. It supports managed configuration on both mobile platforms: iOS Managed App Configuration and Android Enterprise managed configurations, so the settings you publish from your existing MDM or EMM console arrive with the app. Your users open BlueMail and it is already set up the way your organization wants it.

Managed configuration is part of BlueMail Enterprise and is switched on for your organization as part of setting you up, so it is worth raising with your BlueMail contact early. It is enabled per customer rather than being on for everyone.

What it saves you

The clearest example is S/MIME. Instead of sending every user a certificate file and its password and walking them through importing it, you publish the identity once and BlueMail installs it for them. It matches each certificate to the right account using the email address inside the certificate, so there is no per-device mapping to maintain, and the import runs once rather than repeating every time the app opens. When a certificate is renewed, publishing the replacement rolls it out on its own.

That turns a support queue into a single console change, and the same applies to the security posture you want on every device, rather than hoping each person sets it themselves.

Which platforms

BlueMail speaks the AppConfig Community standard, so it works with any management platform that can push a managed configuration, including Microsoft Intune, Jamf Pro, Ivanti (MobileIron) and SOTI MobiControl. There is no proprietary agent to install and no second console to learn.

Some of the parameters

These are examples rather than the whole set, grouped by what they are for.

Delivering S/MIME identities

ParameterWhat it does
smimeP12The user's S/MIME identity, as a base64-encoded .p12
smimeP12PasswordThe password protecting that .p12
enableSmimeGrants the S/MIME entitlement, so managed devices need nothing arranged separately

Security posture

ParameterWhat it does
enforcePasscodeRequires a passcode to open BlueMail, independently of the device lock

Data-handling controls

ParameterWhat it does
disableForwardPrevents forwarding messages out of the organization
disablePrintPrevents printing
disableSharePrevents sharing mail into other apps
disableTextCopyPrevents copying text out of a message
disableScreenshotsPrevents screenshots of mail content
disableChatTurns off chat
disableGemAITurns off BlueMail's AI features, including Morning Brief

Boolean parameters accept either real booleans or the strings "true" and "false", so they work with consoles that only send strings. disableGemAI also answers to disableGem.

Pre-configuring accounts

Beyond the policy keys above, a managed configuration can carry the account itself: address, server and authentication settings, delivered so the mailbox is ready at first launch. Variables such as the user principal name resolve per device, so a single payload can provision the whole fleet rather than one configuration per person.

This is usually the biggest saving of all, because it removes the step where each employee types server details, and the step where IT explains them.

Personal devices, and people leaving

Full enrollment is not a prerequisite. BlueMail works inside Android Enterprise work profiles, Apple User Enrollment and pure MAM deployments, so the corporate inbox is governed without IT enrolling, or seeing, the rest of someone's phone.

When an employee leaves, one action in your console revokes access and wipes BlueMail's corporate data. The wipe scope is the app, not the phone, so personal photos, messages and apps are untouched.

MDM and the Admin Console together

The two are complementary rather than alternatives. Your MDM handles deployment and device-side policy; the BlueMail Admin Console adds BlueMail-side fleet visibility, usage insight and email-specific controls.

Getting the full list

More parameters are supported than those above, and the set grows as new controls are added, so rather than work from a snapshot, contact the BlueMail team for the complete and current list. We will send you the parameters for your platform, along with example payloads for your console. Write to sales@bluemail.me, or see BlueMail plans and pricing for what Enterprise includes.

The two platforms differ in timing, which is worth knowing when you plan a rollout: Android broadcasts configuration changes to the app, so BlueMail picks up a new policy as soon as your EMM applies it, while iOS re-reads its managed configuration when BlueMail next comes to the foreground.

It is also worth telling us what you are trying to achieve. Some policies have more than one route, and the team can point you at the one that fits your console and your fleet.