Docs / Obsidian Mail Server / Apps and devices
Phones and tablets
Phones and tablets with an Exchange account sync through Exchange ActiveSync. Each one shows up under Phones & tablets after its first sync, and on its owner's page, with the model, the last sync time and its status.
Security rules for phones
Under Phones & tablets, Security rules for phones sets what every phone of the organization must do before it may sync. The phone asks its owner to accept the rules when the account is added, and again whenever they change.
| Rule | What it does |
|---|---|
| Require a passcode | The phone must have a screen lock |
| Allow simple passcodes | Allows passcodes like 1111 or 1234 |
| Require letters and numbers | The passcode must mix letters and digits |
| Minimum passcode length | For example 6 |
| Erase after failed attempts | The phone erases itself after this many wrong passcodes (for example 10) |
| Lock after idle | Seconds without use before the screen locks (for example 300) |
| Passcode expires after | Days until the passcode must be changed; empty = never |
| Require encryption | The phone's storage must be encrypted (all current iPhones and Android phones are) |
| Allow camera | Some phones honour this and disable the camera |
| Allow attachments | Whether attachments can be downloaded to the phone |
| Allow HTML email | Whether mail shows formatted, or as plain text only |
With no rules saved, phones sync without restrictions. Rules apply to phones and tablets only; IMAP apps and webmail are not affected.
A lost or stolen phone
On Phones & tablets, or on the owner's page:
- Block stops the phone from syncing at once. Nothing on the phone is erased, but it receives nothing new. Allow undoes it. Also reset the person's password.
- Erase tells the phone to erase itself the next time it connects.
Erase resets the whole phone to factory settings, including the person's own photos and apps, not just the mail account. Use it for company phones, or with the owner's agreement. While it has not happened yet (the phone has not connected since), Cancel erase takes it back.
- Remove deletes the phone from the list, for example an old phone that is no longer used. If the phone connects again, it reappears.
From the command line
sudo oms device list [email protected]
sudo oms device block [email protected] <device-id>
sudo oms mobilepolicy show <organization>
sudo oms mobilepolicy set <organization> DevicePasswordEnabled=1 MinDevicePasswordLength=6
mobilepolicy set also accepts the rules that have no switch in the admin center, using their Exchange names, for example MaxEmailAgeFilter, AllowBluetooth or RequireManualSyncWhenRoaming.