Obsidian SuiteDocumentation
Obsidian Mail Server: all chapters

Docs / Obsidian Mail Server / Apps and devices

Phones and tablets

Phones and tablets with an Exchange account sync through Exchange ActiveSync. Each one shows up under Phones & tablets after its first sync, and on its owner's page, with the model, the last sync time and its status.

Security rules for phones

Under Phones & tablets, Security rules for phones sets what every phone of the organization must do before it may sync. The phone asks its owner to accept the rules when the account is added, and again whenever they change.

RuleWhat it does
Require a passcodeThe phone must have a screen lock
Allow simple passcodesAllows passcodes like 1111 or 1234
Require letters and numbersThe passcode must mix letters and digits
Minimum passcode lengthFor example 6
Erase after failed attemptsThe phone erases itself after this many wrong passcodes (for example 10)
Lock after idleSeconds without use before the screen locks (for example 300)
Passcode expires afterDays until the passcode must be changed; empty = never
Require encryptionThe phone's storage must be encrypted (all current iPhones and Android phones are)
Allow cameraSome phones honour this and disable the camera
Allow attachmentsWhether attachments can be downloaded to the phone
Allow HTML emailWhether mail shows formatted, or as plain text only

With no rules saved, phones sync without restrictions. Rules apply to phones and tablets only; IMAP apps and webmail are not affected.

A lost or stolen phone

On Phones & tablets, or on the owner's page:

  • Block stops the phone from syncing at once. Nothing on the phone is erased, but it receives nothing new. Allow undoes it. Also reset the person's password.
  • Erase tells the phone to erase itself the next time it connects.

Erase resets the whole phone to factory settings, including the person's own photos and apps, not just the mail account. Use it for company phones, or with the owner's agreement. While it has not happened yet (the phone has not connected since), Cancel erase takes it back.

  • Remove deletes the phone from the list, for example an old phone that is no longer used. If the phone connects again, it reappears.

From the command line

sudo oms device list [email protected]
sudo oms device block [email protected] <device-id>
sudo oms mobilepolicy show <organization>
sudo oms mobilepolicy set <organization> DevicePasswordEnabled=1 MinDevicePasswordLength=6

mobilepolicy set also accepts the rules that have no switch in the admin center, using their Exchange names, for example MaxEmailAgeFilter, AllowBluetooth or RequireManualSyncWhenRoaming.