Configuring an Exchange Profile for Mobile Devices

Jamf School Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
Requirements

If you plan on using certificate-based authentication, you must add and configure a Certificates payload to the profile before adding and configuring the Exchange payload.

  1. In Jamf School, navigate to Profiles > Overview in the sidebar.
  2. Click + Create Profile.
  3. Select the iOS operating system.
  4. Select the type of enrollment you want to make the profile for.
  5. Enter a name in the Profile name field and configure the additional settings as needed, including the time filter.
  6. Click Finish.
  7. In the list of payloads on the left side of the pane, locate the iOS payload category and click the Exchange payload.
  8. Click Configure.
  9. In the Account Name field, enter the display name for the account.
  10. In the Exchange Server field, enter the Exchange server host name.
    Example:

    outlook.office.365.com

  11. (Optional) To use SSL when communicating with the Exchange server, select the Use SSL checkbox.
  12. From the Past days to sync pop-up menu, choose the number of past days of email to synchronize. To synchronize all available email, choose "Unlimited".
  13. (Optional) To configure the account automatically using credentials configured in the Authentication settings in Jamf School, select the Use Stored Credentials checkbox.
    Note:

    If you select the Use Stored Credentials checkbox, you cannot configure the following settings: E-mail address, Username, Open Authorization, and Password.

  14. (Optional) In the E-mail address field, enter the email address for the account. To prompt the user to enter their email address during the profile installation, leave this field blank.
  15. In the Username field, enter the account username with the optional domain.
  16. (Optional) To use OAuth for authentication, do the following:
    1. Select the Use OAuth for authentication checkbox.
    2. Complete both the OAuth Sign in URL and OAuth Token Requests URL fields.
    Note:

    Keep the following in mind when using OAuth for authentication:

    • You will not be required to enter the password mentioned in step 17.

    • The format for the OAuth Sign in URL is https://login.microsoftonline.com/tenant_ID/oauth2/v2.0/authorize.

    • The format for the OAuth Token Requests URL is https://login.microsoftonline.com/tenant_ID/oauth2/v2.0/token.

    • You will need your Microsoft Entra tenant ID in order to accurately complete these fields. To find your tenant ID, navigate to portal.azure.com > Microsoft Entra ID > Properties.

  17. (Optional) In the Password field, enter the account password. If you leave this field blank, the user must enter their password after the profile is installed.
  18. (Optional) (iOS 14 or later only) To replace the user's current password with the one entered in the Password field, select the Override Current Password checkbox.
  19. In the Restrictions section, configure the account settings.
    Note:

    You must enable at least one of the following services for the account: Calendars, Contacts, Mail, Notes, or Reminders.

  20. (Optional) In the S/MIME section, configure the S/MIME encryption settings.
    Note:

    If using certificate-based authentication, eligible certificates will display in the Signing Certificate pop-up menu. The Certificates payload must be configured in the profile before adding and configuring the Exchange payload.

  21. (Optional) From the pop-up menu in the Communication Service Rules section, choose the default app to use when making audio calls to the account's contacts.
  22. To configure another Exchange account, click Configure a new Exchange account and then repeat steps 9 through 21.
  23. In the list of payloads on the left side of the pane, locate the General category and click the Scope payload.
  24. Configure the scope of the profile by clicking the + icon and adding device groups to the profile scope using the pop-up menu.
  25. Click the Settings icon on the right side of the page, and do one of the following:
    • To install the profile on devices automatically, click Change to automatic installation for all groups.

    • To allow users to install the profile themselves, click Change to on-demand installation for all groups. The profile will be available for users to install in the Jamf Teacher or Jamf School Student apps.

  26. Click Save.