Skip to main content

August 18, 2026

Application Configurations for Omnissa Workspace ONE Boxer

Configure Workspace ONE Boxer with application configuration values.

You can configure settings for your Workspace ONE Boxer deployment using the Configuration Key and Configuration Value pairs provided by Workspace ONE UEM.

Note: If you are using console 2004 or higher, you do not need to manually add all the configuration key-value pairs. You can configure most of the application configuration values using the settings available in the Email Settings and App Policies assignment pages. Some new features will require key-value pairs. If you input a key-value pair that has already been migrated to the new UI, a message is shown stating that a duplicate key is found. The settings for that feature can be found elsewhere in the UI depending if it is an account or app specific policy.

To configure these settings, enter the configuration key and the corresponding value into the Application Configuration setting during the app assignment.

Important: If Workspace ONE Boxer is already installed on end-user device, it might take few minutes for Workspace ONE Boxer to download the new profile settings.

(iOS only) FastSync - Key Sync Escrow

Add the following key value pairs to improve the background syncing and speed of subsequent syncs.

Configuration KeyValue TypeConfiguration ValueDescription
ENSEnableKeyEscrowInteger0 - deactivated (default)
1 - activated
Set to enable FastSync.
ENSKeyEscrowExpiryInteger48 hours (default)Set the expiration time in hours when Workspace ONE Boxer no longer receives this key.

S/MIME

Use these key value pairs to configure S/MIME support.

Configuration KeyValue TypeConfiguration ValueDescription
PolicySMIMEInteger0 - deactivated (default)
1 - allowed
2 - required
Changes the status of S/MIME support.
PolicySMIMEEnableRevocationCheckInteger0 - deactivated (default)
1 - enabled
Activate or Deactivate Online Certificate Status Protocol (OCSP).
PolicySMIMERevocationCheckUrlStringSupported format: http://ocsp.acme.us/
ocsp:88
Configure the Revocation check URL.
PolicySMIMERevocationCheckTypeInteger0 - check entire chain(default)
1 - check only user certificate
Configure the revocation check type.
PolicySMIMERevocationUseAIAInteger0 - deactivated (don't use URL configured inside certificate for revocation status, use PolicySMIMERevocationCheckUrl only) (default)
1 - enabled (use URL configured inside certificate for revocation status check, fall back to PolicySMIMERevocationCheckUrl if it is unavailable)
2 - required (only use URL configured inside certificate to check for revocation status, ignore PolicySMIMERevocationCheckUrl)
Define the revocation usage policy.
PolicySMIMERevocationEnforceNonceInteger0 - deactivated (enforce nonce) (default)
1 - enabled (do not use nonce)
Define the nonce usage policy.
PolicySMIMERevocationTTLInteger7 - Default valueDefine the amount of time to retain the revocation data.
PolicySMIMETrustStoreInteger0 - Device Trust Store (default)
1 - Workspace ONE Boxer Trust Store
Define the Trust Store.

Default S/MIME Signing and Encryption Algorithms

Add the following key value pairs to configure the default encryption algorithms for signing and encrypting S/MIME emails. When a default S/MIME algorithm is configured, Workspace ONE Boxer sends the outgoing emails with the default configured algorithm. Workspace ONE Boxer also checks the algorithms for the incoming emails. If the incoming emails are not configured with the default algorithm, a warning message is displayed in the conversation view.

Configuration KeyValue TypeConfiguration ValueDescription
PolicySMIMEDefaultEncryptionAlgorithmStringAllowed Values:
3DES
AES128
AES192
AES256
For example, PolicySMIMEDefaultEncryptionAlgorithm - [“3DES”]
Specify an encryption algorithm to use for incoming and outgoing emails. If a valid algorithm is not provided, the lowest supported algorithm is used (3DES).
PolicySMIMEDefaultSigningAlgorithmStringAllowed values:
SHA1
SHA256
SHA384
SHA512
For example, PolicySMIMEDefaultSigningAlgorithm - [“SHA1”]
Specify a default S/MIME signing algorithm to use for incoming and outgoing emails. If a valid algorithm is not provided, the lowest supported algorithm is used (SHA-1).

Enable ENS Notification Encryption

Message payload between Workspace ONE Boxer and the Email Notification Service (ENS) server can be encrypted using the end-to-end notification encryption feature.

Configuration KeyValue TypeConfiguration ValueDescription
EnableEnsNotificationEncryptionBooleanTrue - enabled
False - deactivated (default)
When the value of the KVP is true, message payload between Workspace ONE Boxer and the ENS server is encrypted using the end-to-end notification encryption feature. By default, the value is false and the feature is turned off.

Enable S/MIME Signing by default

Add the following key to enable the S/MIME digital signing for all outgoing email messages by default. To enable this option, you must also ensure that the S/MIME is enabled and configured on the Exchange account.

Configuration KeyValue TypeConfiguration ValueDescription
AccountSMIMESignByDefaultBooleanTrue - enabled (default)
False - deactivated
Use this key to digitally sign all outgoing emails by default. When the key value is set to true, the S/SMIME signing is always enabled in the Boxer Settings and the users are not allowed to change this setting.

If the admin has not configured the AccountSMIMESignByDefault key, users can also set the S/MIME signing as a default option when S/MIME is enabled for that Exchange account. To do so, user must navigate to Boxer Settings > Account > S/MIME > On > Sign > On and enable the Sign email by default option.

Note:

  • Even if the SMIME signing is enabled by default, users can always opt to deactivate signing when composing any specific email.
  • The user can use S/MIME only for encryption. This allows the user to reply to signed emails even when the user does not have a signing certificate.

Send S/MIME protected emails to Distribution Lists

Add the following key value pairs to control the maximum number of members of a distribution list allowed to receive S/MIME protected emails.

As prerequisites, ensure that the S/MIME signing and encryption is enabled on the managed account on Exchange server on-premises or office 365.

The sender can send encrypted emails only to those members who have S/MIME enabled. If the sender sends an encrypted email to members without the S/MIME certificates, the sender sees a notification message. The sender has the option to send an unencrypted email to all the members.

Configuration KeyValue TypeConfiguration ValueDescription
PolicySMIMEtoDLMaxSizeInteger50 (default)Use this key to set the maximum number of members in a distribution list who can receive S/MIME protected mails.

(Android Only) S/MIME Algorithms Compliance

Add the following key value pairs to configure the list of algorithms that Workspace ONE Boxer checks for compliance when receiving a signed or encrypted S/MIME email. When set, only the configured algorithms are recognized by Workspace ONE Boxer. Workspace ONE Boxer displays non-compliance warning when accessing emails that are encrypted using any other algorithm, both strong or weak, than that are listed using the key value pairs.

Configuration KeyValue TypeConfiguration ValueDescription
PolicySMIMEConformingEncryptionAlgorithmsStringSupported Values:
3DES
AES128
AES192
AES256
For example, PolicySMIMEConformingEncryptionAlgorithms = ["AES-128", "AES-256"]
Set the algorithms that are recognized by Workspace ONE Boxer for encrypting S/MIME emails.
PolicySMIMEConformingSigningAlgorithmsStringSupported Values:
SHA1
SHA256
SHA384
SHA512
For example, PolicySMIMEConformingSigningAlgorithms = ["SHA-256", "SHA-512"]
Set the algorithms that are recognized by Workspace ONE Boxer for signing S/MIME emails.

ENSv2 Notification Policy

Add the following key value pair to configure the ENS Notification Policy for Workspace ONE Boxer. When configured, Workspace ONE Boxer immediately re-subscribes to ENSv2 and notification policy is updated as per the set key value.
For more information about configuring ENS2 for Workspace ONE Boxer, see Email Notification Service v2.0 Installation and Configuration Guide available at Omnissa Product Documentation.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyLimitNotificationTextInteger0 - sets notification to sender, subject and preview
1 - sets notification to sender and subject(default)
2 - sets notification to sender
3 - sets notification to generic message (new message)
4 - sets notification to none (only the badge is updated)
Configure the notification policy used by Workspace ONE Boxer.

Plain Text Mode

Add the following key value pair to configure Workspace ONE Boxer plain text mode.

Configuration KeyValue TypeConfiguration ValueDescription
AppPlainTextModeBooleanFalse - Deactivated (default)
True - Activated
Set to True to enable Workspace ONE Boxer plain text mode.
When set, Workspace ONE Boxer retrieves only plain text from HTML mails when syncing. Workspace ONE Boxer sends only plain text regardless of the email message format. The formatting controls in compose view is deactivated and only text can be copied and pasted from rich or HTML content.

Policy Allow Metrics

Add this key to define the policy for allowing collection of anonymous usage data to improve user's Workspace ONE Boxer experience. When enabled, a Data Sharing notice is displayed to user when Workspace ONE Boxer is launched. The device user can activate or deactivate data sharing by navigating to Settings > Privacy > Data Sharing.

The behavior of this KVP depends on the value of the PolicyAllowFeatureAnalytics KVP. For more information about this KVP, see the Entering Privacy Policy Key Values for Data Collection section in the Manage Apps and SDK Settings documentation at Omnissa Product Documentation.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyAllowMetricsBooleanFalse - Deactivated (default)
True - Activated
If PolicyAllowFeatureAnalytics is set to True, then the behavior of PolicyAllowMetrics depends on the KVP value.
- When PolicyAllowMetrics is set to True, data collection for Workspace ONE Boxer experience improvement is enabled.
- When PolicyAllowMetrics is set to False, data collection for Workspace ONE Boxer experience improvement is deactivated.

If PolicyAllowFeatureAnalytics is set to False, then regardless of the value of PolicyAllowMetrics, data collection remains deactivated.

Policy Allow Crash Reporting

Add this key to define the policy for reporting crashes to the Workspace ONE Boxer team.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyAllowCrashReportingBooleanTrue - Activated (default)
False - Deactivated
Set to True to report crashes to the Workspace ONE Boxer team.
The value of PolicyAllowCrashReporting, when set from Custom SDK settings takes precedence over the value that is set from App Configuration Settings.

(iOS only) Allow Print

Configuration KeyValue TypeConfiguration ValueDescription
PolicyAllowPrintBooleanTrue - Activated (default)
False - Deactivated
Set to False to deactivate printing of emails from Workspace ONE Boxer.

Note: You can only print the email from a Boxer preview and not the attachments. To print attachments, open it to some third-party apps, and then print it from there.

(iOS only) Enforce HTTPS

From Workspace ONE Boxer v4.13 for iOS, adding this key value pair blocks email content from unsecured connections in Workspace ONE Boxer.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyEnforceHTTPSBooleanFalse = Deactivated (default)
True = Activated
When set to True, email content from unsecured HTTP connections are not loaded. Outgoing links (hrefs) are not affected since the outgoing links can be controlled using Browser policy.

Limit Notification

Configuration KeyValue TypeConfiguration ValueDescription
PolicyLimitNotificationTextInteger0 - Displays Sender, Subject, and Body Preview
1 - Displays Sender and Subject (Default)
2 - Displays Sender
3 - Generic notification (You've got a new email)
4 - No notification
Set configuration value to limit what is displayed in Workspace ONE Boxer notification.

Mark External Addresses

Add the following keys to configure Workspace ONE Boxer to warn the user when adding external recipients to emails.

Configuration KeyValue TypeConfiguration ValueDescription
AppDomainsInternalStringProvide the list of internal domains. For example, [omnissa.com].Define the domains that are internal or permitted. The user can deactivate the warning using the 'Confirm before sending' setting in Workspace ONE Boxer when the internal domains are defined and AppDomainsWarning key is not set.
AppDomainsWarningBooleanFalse - Deactivated (default)
True - Activated
Set to True to enable warning when the user enters recipients from external domains. If the domains are configured and the AppDomainsWarning value is set to True, the 'Confirm before sending' setting is unavailable to the users. When the warning is displayed, the user can either Accept and return to the Compose email menu or Ignore and continue sending the email to external recipients.

If the AppDomainsInternal key is activated and the AppDomainsWarning key is deactivated, then the ‘Confirm before sending emails’ setting is deactivated and the device user can toggle the setting in the Workspace ONE Boxer app as per requirement. If the 'AppDomainsInternal' key and 'AppDomainsWarning' key are deactivated, then the 'Confirm before sending emails' setting is deactivated and the device user can activate the setting in the Workspace ONE Boxer app as per requirement. If both the AppDomainsInternal and AppDomainsWarning is set to true, then the ‘Confirm before sending emails’ setting is activated and is unavailable to the device user.

Allow Local Calendars

Add this key to define the policy for local calendars in Workspace ONE Boxer.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyAllowLocalCalendarsBooleanTrue - Activated (default)
False - Deactivated
When the KVP is set to True,
- In Workspace ONE Boxer for iOS, a Local calendars toggle is available for end users. By default, the toggle is turned off. When end users turn on this toggle, local calendars are added to Workspace ONE Boxer and they appear as separate calendars.

- In Workspace ONE Boxer for Android, a Enable device calendars toggle is available for end users. By default, this toggle is turned on. As a result, events from personal and local calendars are visible in Workspace ONE Boxer and events can be created in any of these calendars from within Workspace ONE Boxer.

When the KVP is set to False, the toggle is not available for end users and remains grayed out.

Default Swipe Actions

Add this key to define the default swipe actions in Workspace ONE Boxer.

Configuration KeyValue TypeConfiguration ValueDescription
AppSwipesLeftShortDefault

AppSwipesLeftLongDefault

AppSwipesRightShortDefault

AppSwipesRightLongDefault
Integer1 - actions grid
2 - archive
3 - delete
4 - move
5 - flag
6 - quick reply
7 - read or unread
8 - spam
Define the default swipe actions. User can customize swipe actions using the options provided in the Workspace ONE Boxer app.

Default Conversation View

Add this key to define the default policy for conversation view in Workspace ONE Boxer.

Configuration KeyValue TypeConfiguration ValueDescription
AppConversationViewDefaultBooleanTrue - Activated (default)
False - Deactivated
Set to True to enable conversation threading by default. When set to False, the conversation threading option is deactivated for the users.

Default Avatar Policy

Add this key to define the default policy for avatars in Workspace ONE Boxer.

Configuration KeyValue TypeConfiguration ValueDescription
AppAvatarsDefaultBooleanTrue - Activated (default)
False - Deactivated
Set to True to enable avatars for initial configuration. User can change the Avatar setting using the options provided in the Workspace ONE Boxer app. The KVP and setting affect only the avatars in the email list. If the KVP value is set to false, the avatars in the email list are hidden.

(iOS only) Allow Custom Keyboards

Add this key to define the policy for allowing third-party keyboards with Workspace ONE Boxer.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyAllowCustomKeyboardsBooleanTrue - activate (default value for unmanaged device)
False - deactivate (default value for managed device)
Set to True to permit users to activate third-party keyboards within Workspace ONE Boxer.

Export Contacts by Default

Add this key to activate or deactivate exporting of contacts by default.

Configuration KeyValue TypeConfiguration ValueDescription
AppDefaultCallerIDBooleanTrue - Activated (default)
False - Deactivated
Set to true to enable the exporting of contacts by default. This setting requires the Caller ID option in the Workspace ONE UEM console to be set as Unrestricted.

Allow Caller ID (Contact Export for iOS)

Add this key to activate or deactivate Export Contact option in Workspace ONE Boxer for end users.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyAllowCallerIDBooleanTrue - Activated (default)
False - Deactivated
Set to true to activate the exporting of contacts by the end users. This setting requires the AppDefaultCallerID configuration value set to 'enabled'. If deactivated, the Export Contacts option in Workspace ONE Boxer is unavailable for the end users.

Note: Boxer contacts exported to iOS devices are not deleted upon an enterprise wipe and are retained in the device's native contact list. To trigger the deletion of the contacts from the iOS devices, the end user has to relaunch Boxer after the enterprise wipe.

Allow Archive

Add this key to activate or deactivate Archive action in Workspace ONE Boxer for end users.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyAllowActionArchiveBooleanTrue - Activated(default)
False - Deactivated
Set to true to enable archive action by the end users. If deactivated, the Archive option in Workspace ONE Boxer is unavailable for the end users.

Phishing Reporting

Add this key to enable phishing reporting action in Workspace ONE Boxer for end users.

Configuration KeyValue TypeConfiguration ValueDescription
AppPhishEmailAddressstringAny email address that is in valid format.The reported email is sent to the email address specified by the configuration value.

Restricting Third-Party Attachments

Add these keys to restrict the device user from attaching files to emails from multiple third-party sources.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyAllowDocProvidersBooleanTrue - activate (default)
False - deactivate
Activates or deactivates attachments from external providers (iCloud, Dropbox, Google Drive, etc.) within Workspace ONE Boxer.
PolicyAllowOpenInInteger1 - allowed (default)
0 - not allowed
Activates or deactivates attaching of files from other apps using open-in or share into Workspace ONE Boxer. When open-in or sharing of attachments are deactivated, the message 'Your administrator has restricted attachments from external applications' is displayed.
(iOS Only)
PolicyAllowPhotoAttachment
BooleanTrue - activate (default)
False - deactivate
Activates or deactivates attaching of images and media files from photo gallery and camera.

Add this key to restrict the sharing of UNC/HTTP links in an email with long tap menu.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyAllowSharingLinksBooleanTrue - activate (default)
False - deactivate
Activates or deactivates the sharing of UNC/HTTP links in an email. If set to False UNC/HTTP links cannot be shared.

To configure the refetch policy for non-standard URL schemes, add the following key value pair:

Configuration KeyValue TypeConfiguration ValueDescription
AppRefetchEmptyLinksUsingMimeBooleanTrue - Activated
False - Deactivated
Note: The default value on iOS is True, whereas the default value on Android is False.
For emails (fetched using HTML) that contain non-standard URL schemes, pointing to non-server domains, Exchange replaces the URL with two empty spaces. You can enable the PolicyRefetchEmptyLinksUsingMime key to detect this occurrence and redownload the affected body using MIME, which is not subject to the URL replacement error.

Modern Authentication

To enable modern authentication for Office 365 accounts, add the following key value pair:

Configuration KeyValue TypeConfiguration ValueDescription
AccountUseOauthBooleanFalse - deactivate (default)
True - deactivate
Activates or deactivates modern authentication for Office 365 accounts. When enabled, during enrollment, users are redirected to the login page for entering email password.

Workspace ONE Boxer also supports Certificate-Based Authentication with Modern Authentication (CBA with Modern Authentication).

Note:

  • Modern authentication is enabled by default for personal (non-managed) Exchange accounts.

You must set the following authentication types in addition to the AccountUseOauth key to support the modern authentication:

  • Set the authentication type to Basic and add the key for Modern Authentication with password.

  • Set the authentication type to Certificate and add the modern authentication key with only authentication certificates or set the authentication type to Both and add the modern authentication key with both authentication certificate and password.

    Note: These types of authentication only work when MDM is deployed on iOS Boxer. Boxer for Android supports both MDM and MAM.

Certificate-Based Authentication with Modern Authentication

With Certificate-Based Authentication (CBA), users authenticate with the Exchange Server with the configured certificates eliminating the need to enter a password or a security token.

Note: Certificate-Based Authentication with Modern authentication is not supported for personal (non-managed) Exchange accounts. Standalone Boxer configurations are supported.

To achieve certificate-based authentication, you must configure either of the following:

  • Device Profile

    You must configure the authentication certificates and the other certificates for installation on the device when the end user enrolls the device using Workspace ONE Intelligent Hub. When the device profile installs during enrollment, the certificates installs in the iOS device certificate store. When Boxer launches Modern authentication, the installed certificates authenticate the users.

    Note: The device profile cannot be installed on the device during Boxer Standalone enrollment and hence is not supported.

  • Boxer Profile

    You must configure the authentication certificates for Boxer on the assignment page under Email Settings > Authentication. Boxer fetches the configured certificates and saves them in the database, and uses them for authentication. Here, there is no dependency on the iOS device certificate store for authentication certificates. Thus, all enrollment types, including Boxer Standalone enrollment, are supported.

    Note: You must add the configuration key AccountUseWebviewForOauth and set it to True. This key allows Boxer to use the configured authentication certificate and allow authentication flows using WKWebView instead of SFSafariViewController. If using PIV-D for certificates, you must configure PIV-D before launching Boxer.

Configuration KeyValue TypeConfiguration ValueDescription
AccountUseOauthBooleanTrue - Activated
False - Deactivated (default)
Activates or deactivates modern authentication for Exchange server on-premises or Office 365 accounts.
AccountUseWebviewForOauthBooleanTrue - Activated
False - Deactivated (default)
When set to True, the oauth flow is presented using a WKWebView instead of SFSafariViewController.
Note: The AccountUseWebviewForOauth key can be applied for managed accounts on Exchange server On-Premise or Office 365.
AuthenticationTypeStringCertificateWhen the authentication type is set to certificate and if the authentication certificate is configured for Exchange Server, certificate-based authentication is automatically enabled and authenticates the user.

OnlineMeetingsCBAEnabled is an account-based KVP used for modern authentication from Workspace ONE Boxer for Android to Microsoft Teams and Zoom Meetings.

Note: Workspace ONE Boxer for iOS does not require the OnlineMeetingsCBAEnabled KVP when authenticating to Microsoft Teams and Zoom meetings.

Configuration KeyValue TypeConfiguration ValueDescription
OnlineMeetingsCBAEnabledBooleanTrue - Activated
False - Deactivated
When activated, certificate-based authentication is used for end-user authentication instead of username and password when the end user is redirected to Microsoft Teams and Zoom Meetings.

To use CBA (Certificate-Based Authentication) instead of username and password for Microsoft OneDrive authentication, EnterpriseContentCBAEnabled KVP is used.

Note: Workspace ONE Boxer for iOS does not require the EnterpriseContentCBAEnabled KVP when authenticating to Microsoft OneDrive.

Configuration KeyValue TypeConfiguration ValueDescription
EnterpriseContentCBAEnabledBooleanFalse - Deactivated
True - Activated (default)
When the feature is activated, Workspace ONE Boxer uses Certificate-Based Authentication for the end user instead of username and password when authenticating to Microsoft OneDrive.

Allow User Agent based Authentication Policy for Boxer Android

In scenarios that involve a third-party identity provider (IdP), Boxer authentication on Android devices can fail if the IdP does not identify the specific user agent for Boxer. The user during authentication gets redirected to the sign-in page where the OAuth flow is presented using the native browser's webview. The user agent shown to the IdP is of the browser instead of Boxer. As a result, the IdP blocks the authentication.

Add the following key to allow Boxer to use the Boxer-specific WebView UserAgent instead of the browser user agent.

Configuration KeyValue TypeConfiguration ValueDescription
AppBoxerUserAgentInOauthWebViewBooleanFalse - Deactivated
True - Activated
Set the value to true for the Boxer app to set and use the Boxer-specific WebView UserAgent during OAuth.

Note: The AppBoxerUserAgentInOauthWebView key can be applied for managed accounts on Exchange server On-Premise or Office 365.

Enable Umlaut Characters in Login Password on Android Devices

By default, Workspace ONE Boxer uses UTF-8 decoding while authenticating users. Boxer's authentication fails if your Exchange password contains umlaut characters (ä, Ë, ë, Ï, ï) as UTF-8 does not support these characters.

To support umlaut characters, add the following key to change Boxer's encoding from UTF-8 to ISO-8859-1.

Configuration KeyValue TypeConfiguration ValueDescription
EnableNewAuthEncodingBooleanFalse - Deactivated (default)
True - Activated
Set the value to true to change the Boxer encoding to ISO-8859-1 that supports umlaut characters.

Downloading Attachments

Add this key value pair to activate or deactivate downloading of attachments.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyAllowAttachmentsDownloadBooleanTrue - activate (default)
False - deactivate
Activates or deactivates downloading of attachments.

Managing Attachments

Add this key value pair to activate or deactivate attachments for sending mails..

Configuration KeyValue TypeConfiguration ValueDescription
PolicyAllowAttachmentsBooleanTrue - activate (default)
False - deactivate
Activates or deactivates attachments for sending mails.

Spam Reporting

Add the following configuration keys to forward a spam marked email to the configured address and then delete the email from the user’s account once it has been forwarded to the configured address.

Configuration KeyValue TypeConfiguration ValueDescription
AppSpamForwardAddressStringValid email address spam@email.com.Set the email address where spam emails are sent.
PolicyDeleteOnSpamForwardBooleanFalse - deactivate (default)
True - activate
Set to delete the spam email from the user’s device after forwarding.
PolicyAllowActionSpamBooleanTrue - Activated (default)
False - Deactivated
Set to true to enable spam action by the end users. If deactivated, the Spam option in Workspace ONE Boxer is unavailable for the end users.

(Android Only) Activate SSO

If SSO is enabled in Security Policies, enable Application uses AirWatch SDK and assign the following application configuration key to add SSO functionality for Workspace ONE Boxer. For using SSO functionality in Workspace ONE Boxer Android, you must have Workspace ONE console version 9.0.5 or above.

Configuration KeyValue TypeConfiguration ValueDescription
AppForceActivateSSOBooleanTrue - activate
False - deactivate
Activates or deactivates SSO for Workspace ONE Boxer. Enterprise Content requires this value to be set to true.

Note:

  • You can enable the AppForceActivateSSO key and configure SSO in the Workspace ONE UEM console. For more information about SSO, see Configuring Security Policies in the Manage Apps with SDK Settings documentation at Omnissa Product Documentation.
  • To run the mobile SSO authentication smoothly on your Android device, make sure you use the latest version of Chrome.

Health Check - Boxer Version update for iOS devices

Add the following console key to alter the app opened when the user taps to update Boxer.

Configuration KeyValue TypeConfiguration ValueDescription
AppUpdateSourceInteger0 (default) - App Store
1 - Intelligent Hub
Set the value to 1 to change the default app opened when the user taps to update Boxer from the Health Check screen.

QuickJoin - Vanity URL Support

To configure Boxer to detect meeting links with vanity URLs, add the following key in the Boxer's application configuration.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyCustomOnlineMeetingUrlsStringA JSON formatted string containing a map of the meeting types and corresponding set of wildcard URLs.Set these URLs in the console corresponding to the meeting types to permit Boxer to detect meeting links with vanity URLs.
Validate the format externally before entering into the UEM Console.

Example of a configuration value:

{   "skype":[ 
      "https://lync.company.com/*",
      "https://sample.us/j/*"
   ],
   "zoom":[ 
      "https://meetings.company.com/*",
      "https://sample.us/j/*",
      "https://mtg.company.com/*"
   ],
   "webex":[ 
      "https://webex.company.com/*"
   ]
}

Browser Exception List

You can use the AppDefaultBrowserExceptions key to create exception lists for hyperlinks when hyperlinks are Restricted or Unrestricted in the Workspace ONE UEM console.

You can configure the key value pairs to support the following functionalities:

  • If hyperlinks are restricted in the Workspace ONE UEM console, all links open in Workspace ONE Web.
  • If hyperlinks are restricted, but has an exception list, all available browsers are displayed but only links in the exception list opens in the default browser.
  • If hyperlinks are unrestricted in the Workspace ONE UEM console, all available browsers are displayed and all links open in the default browser.
  • If hyperlinks are unrestricted in the Workspace ONE UEM console, but has an exception list, all available browsers are displayed and the links in the exception list only opens in Workspace ONE Web.
Configuration KeyValue TypeConfiguration ValueDescription
AppDefaultBrowserExceptionsStringAppDefaultBrowserExceptions = [".acme.com", "acme.acme1.com", "source.acme.com", "acme.com"]Creates an exception list to restrict and unrestrict specific links from opening in the default browser.

Note: If the browser exception regex value is set to *google.com and the user receives a link in Boxer such as https://www.gooogle.com, then this link opens in Workspace ONE Web application as it matches the wildcard for browser exception. However, if the link is like https://www.abc.com/?url=https://www.google.com/, then the regex fails to match and the link can be open in any of the browser.

Enterprise Content

To configure Enterprise Content in Boxer, add the following key to Boxer's application configuration.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyAllowEnterpriseContentBooleanTrue - activate
False - deactivate
Set the value to true to configure Enterprise Content in Boxer.

Note: Enterprise Content requires setting the key AppForceActivateSSO to true. AppForceActivateSSO is supported in Workspace ONE Boxer for Android only. For more information about configuring SSO, see Configuring Security Policies in the Manage Apps with SDK Settings documentation at Omnissa Product Documentation.

Watermark Support

You can add a customized watermark text that covers sensitive areas in Boxer.

To configure the watermark, add the following keys to Boxer’s application configuration.

Configuration KeyValue TypeExample Configuration ValueDescription
PolicyWatermarkTextStringCustomWatermarkTextDefines the watermark text.
PolicyWatermarkOpacityInteger20 (default)(Optional) Defines the opacity of the text.You can set any number from 0 through 100.
PolicyWatermarkColorString#0079B8 (default)(Optional) Defines the color of the text in the hexadecimal format.Blue is the default color.

Note: Ensure that the watermark text has appropriate visibility in Dark Mode or Dark Theme when you set the color and opacity value different from the default value.

Security Classifications

Enable Email Classification Marking to assign security classifications to the emails sent from Workspace ONE Boxer. Assign the following application configuration keys and values to enable Email Classification Marking feature:

Note: Email classification is a supported feature in Delegated and Shared Accounts.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyClassMarkingsEnabledInteger0 - deactivate (default)
1 - activate
Activates or deactivates classification markings.
PolicyClassMarkingsXHeaderStringx-header-name(Optional) Enables and defines x-header for classification.
Note: Boxer sends the x-headers on email replies or email forwards but not with SmartForward or SmartReply commands.
PolicyClassVersionString1.0Version number for classification feature.
PolicyClassMarkingsRankEnabledInteger0 - deactivate (default)
1 - activate
(Optional) Enables hierarchical classification ranking.
PolicyClassMarkingsDefaultClassStringConfidential, Restricted, Protected, or Secret(Optional) Set the default classification for emails. The value must match a display name from an entry in the PolicyClassMarkings configuration value.
PolicyClassMarkingsStringPolicyClassMarkings Configuration ValueDefines the hierarchical list of classifications.

Optional: Customize the appearance of classifications within Workspace ONE Boxer using the Color property. The property value must be in hex (for example: #FFFFFF)

PolicyClassMarkings Configuration Value

[{
			"Rank": 4,
			"DisplayName": "Secret",
			"Color": "#FFFF00",
			"Description": "This is secret...",
			"Subject": "(Secret)",
			"TopBody": "Classification: Secret",
			"BottomBody": "Classification: Secret",
			"XHeader": "Secret"
			}, {
			"Rank": 3,
			"DisplayName": "Restricted",
			"Color": "#FF0000"
			"Description": "This is restricted...",
			"Subject": "(Restricted)",
			"TopBody": "Classification: Restricted",
			"BottomBody": "",
			"XHeader": "Restricted"
			}, {
			"Rank": 2,
			"DisplayName": "Protected",
			"Description": "This is protected...",
			"Subject": "[Sec=Protected]",
			"TopBody": "",
			"BottomBody": "Classification: Protected",
			"XHeader": "Protected"
			}, {
			"Rank": 1,
			"DisplayName": "Confidential",
			"Description": "This is confidential...",
			"Subject": "(Confidential)",
			"TopBody": "Classification: Confidential",
			"BottomBody": "Classification: Confidential",
			"XHeader": "Confidential"
		}]

Deactivate Classifications on Forwarded Calendar Events

Information goes missing in forwarded calendar events due to x-header classification. To prevent this missing information, classifications must be turned off when forwarding a calendar event.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyClassDisableForEventsInteger0 - False

1 - True
To turn off the classifications on forwarded Calendar events, set the value of this KVP to 1. By default, the value of the KVP is 0 which means that the x-header classifications are present in forwarded Calendar events.

Enforce Users to Classify Emails

After you enable the email classification marking feature, you can further add a key to force your users to set an appropriate classification to the emails they compose.

When the user attempts to send a message without a classification, Boxer prompts the user to select one, only after which the user is allowed to send the email.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyClassMarkingsRequiredInteger0 (default) - Deactivated

1 - Activated
Set the value to 0 to allow the user to send emails without selecting a classification.

Set the value to 1 to force the user to select a classification before they can send the email.

Enforce Users to Classify Emails for External Recipients

You can force your users to set an appropriate classification to the emails they want to send to email recipients outside of the organization. As a prerequisite, ensure the email classification is enabled and configured in the UEM console.

When the user attempts to send a message to an external recipient without a classification, Boxer prompts the user to select one, after which the user is allowed to send the email.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyClassMarkingsRequiredInteger2 - ActivatedSet the value to 2 to send emails to external recipients with classifications.

Restrict Screenshots in Boxer on Android Devices

Add the following key to restrict Android device users from taking screenshots in Boxer:

Configuration KeyValue TypeConfiguration ValueDescription
PolicyRestrictScreenshotsBooleanFalse - screenshots allowed (default)
True - screenshots restricted
Set the value to true to restrict taking of screenshots in Boxer.

Skipping the In-App Tutorial (Block FTUE screen)

First Time User Experience (FTUE) screens and prompts can be deactivated using the AppShowFirstTimeTutorials KVP.

Configuration KeyValue TypeConfiguration ValueDescription
AppShowFirstTimeTutorialsBooleanTrue - Activated (default)
False - Deactivated
Set the value to false to deactivate the in-app tutorials.

Skipping the Battery Optimization Screen in Android Boxer

Add the following key to Boxer's application configuration:

Configuration KeyValue TypeConfiguration ValueDescription
AppShowOptOutBatteryOptimizationScreenBooleanTrue - Activated (default)
False - Deactivated
Set the value to false to skip the Battery Optimization screen.

(iOS only) Enhance Modern Authentication Enrollment

To streamline the enrollment process, administrators can use the AccountAllowSplashScreenAutomaticSignIn KVP to control automation of the Workspace ONE Boxer's authentication screen. When the KVP is configured to true, the enrollment process is automated by activating an automatic sign in on the OAuth splash screen. As a result, an end user need not explicitly tap the Sign in button on the screen.

Configuration KeyValue TypeConfiguration ValueDescription
AccountAllowSplashScreenAutomaticSignInBooleanFalse - Deactivated (default)
True - Activated
Set to true, Workspace ONE Boxer displays an automatic sign in on the OAuth splash screen and the end user need not explicitly tap the Sign in button.

Deactivate Plain Text in Emails on Android Boxer

The inline style elements in an email are displayed as plain text when the email is protected with S/MIME. Add the following configuration key to display the inline elements in rich text format. This key when added overrides the plain text setting.

Configuration KeyValue TypeConfiguration ValueDescription
AppEnableSMIMEStylingBooleanTrue - Activated
False - Deactivated (default)
Set the value to true to deactivate plain text format and enable rich text format.

Enable Autofill in Boxer for an Office 365 Account

To automatically prefill the user's credentials (user name or email address) in a pop-up authentication window of Office 365, add the following key:

Configuration KeyValue TypeConfiguration ValueDescription
PolicyPrefillCredentialsPopUpInteger0 - None
1 - Email (default)
2 - User name
By default, the key value is 1.
Based on your preferences, set the value to 1 to prefill the user's email address or 2 to prefill the user name.
Users can edit the prefilled email or user name.

Block External Images in Email

Use PolicyBlockExternalImages an application-level, boolean, KVP to block loading external images in the email. Administrators can use this KVP to enhance end user's privacy.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyBlockExternalImagesBooleanTrue - Activated
External images are not loaded. However, internal inline images are not affected.

False (default) - Deactivated
Both internal and external images are loaded.
End users can also control the loading of external inline images using a toggle present in Workspace ONE Boxer settings. The value of the KVP determines the availability of this toggle to end users.

Note: The PolicyBlockExternalImages key can be applied for managed accounts on Exchange server On-Premise or Office 365.

In Workspace ONE Boxer for Android, when the KVP is false, the Block external images toggle is available for end users to turn on or turn off. This toggle is present in Settings > More Mail settings. When the toggle is turned on, external images are not loaded. By default, the toggle is turned off. When the KVP value is set to true, the toggle is always turned on. The toggle is greyed out and cannot be turned off by the end users. As a result, end users have no control on this setting.

In Workspace ONE Boxer for iOS, when the KVP is false users can block the external images from Settings > Mail > More > Block external images. The images are not displayed but the users can still view the images by tapping the Show images button in the email bar. When the KVP is set to true, the user's setting is not available.

External links in emails can sometimes lead to phishing attacks and expose users to malicious websites. To provide a safe browsing experience to Boxer users, as an admin, you can add multiple domains or IP addresses as an allowlist. Subdomains and directories are part of the main domain.

When the user taps on a link in the Boxer email that is not in the allowlist, the user sees a warning message. If the user consents, the user navigates to the link. If the user disapproves, the warning disappears, and the user stays on the email.

Note: The ExternalLinksAllowlist key can be applied for managed accounts on Exchange server On-Premise or Office 365.

Use the following key and add the URLs that must be considered as an allowlist.

Configuration KeyValue TypeConfiguration ValueDescription
ExternalLinksAllowlistStringProvide the list of URLs. For example, ["acme.com", "abc.com", "xyz.com"]The string accepts URLs and serves the role of an allowlist.

Enable AIP Sensitivity Labels in Workspace ONE Boxer

Add the following key to the Boxer's application configuration.

Configuration KeyValue TypeConfiguration ValueDescription
PolicySensitivityLabelsEmailClassificationBooleanFalse - Deactivated (default)
True - Activated
Set the key value to true to enable the AIP Sensitivity labels in Workspace ONE Boxer.

Item Operations Sync for IRM Templates

Add the following key value pair for Item Operation sync for IRM templates. This KVP is set on an account level.

NOTE:

  • You must have a managed account on Exchange server On-Premises.
  • You must have enabled IRM.
Configuration KeyValue TypeConfiguration ValueDescription
PolicyRefetchRMSTemplateUsingItemOperationsBooleanFalse - Deactivated (default)
True - Activated
When activated, Workspace ONE Boxer stores the IRM template in the Item Operations request.

Derived Credentials

Add these keys to enable derived credentials authentication policies for Workspace ONE Boxer. If PIV-D is selected as a certificate provider, the device users must install PIV-D Manager application for enrolling into Workspace ONE Boxer.

Note: To enable S/MIME, you must configure the PolicySMIME key.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyDerivedCredentialsInteger0 - Deactivated

1- PIV-D

2 - Purebred (Android only)
The default value of this key is 0.

To enable derived credentials, set the value to 1.

(Android Only)To configure Purebred as a certificate source for Certificate-based authentication (CBA), set the value to 2.
PolicyDerivedCredentialsSMIMEInteger0 - Deactivated

1- PIV-D

2 - Purebred (Android only)
By default, the value of this key is 0 and the certificate source is the Workspace ONE UEM Console.

To configure PIV-D as the certificate source for S/MIME certificates (signing and encrypting), set the value to 1.

(Android Only)To configure Purebred as a certificate source for S/MIME certificates, set the value to 2.

Configure Android Boxer to Verify Purebred

Security is at risk if a malicious app pretends to be the Purebred app. Boxer uses the public signing key from the Purebred app to verify app communication to mitigate such security concerns.

Since Purebred is not a Play Store app, if Purebred changes the signing key, the admins can override the signing key using the AppPurebredPublicKey configuration key. Boxer uses an additional configuration key to verify the package name of the trusted Purebred app.

Configuration KeyValue TypeConfiguration ValueDescription
AppPurebredPublicKeyStringA new Purebred public signing key.Use this key to override the Purebred public signing key to verify the Purebred Registration application.
AppPurebredPackageNameStringThe package name of the trusted Purebred appSets the trusted Purebred package name to verify the app.

Note:You must configure both the keys for Boxer to perform trust check on the Purebred app available on the device.

Excluding Sender's Email Signature from the Conference Dialer

Add the following key to exclude the phone numbers displayed in the sender's email signature when viewing the OneTap dialing section of a calendar invite.

Configuration KeyValue TypeConfiguration ValueDescription
AppExcludeSignatureFromEventParsingBooleanFalse - Deactivated (default)
True - Activated
When the key value is set to True, the phone numbers in the sender's email signature is removed from the OneTap dialing section of a calendar invite.

Enable Microsoft Teams Meetings

Add the key value pair to show the Team Meetings toggle button in the New Event screen when creating a new calendar event. When enabled, you can see the toggle button to add the Teams Meeting to your calendar invites.

Configuration KeyValue TypeConfiguration ValueDescription
EnableTeamsOnlineMeetingsBooleanTrue - Activated
False - Deactivated (Default)
Set to True to show the Team Meetings toggle button.
Set to false to hide the Teams Meetings toggle button.

Note: You must use Modern Authentication, EWS, and Exchange Online (Office 365) to show the Teams Meetings toggle. In Azure, administrators must allow access to the Teams app and provide consent on behalf of users in the tenant. If you do not do so, each user must manually consent for the first time when a creating a Teams meeting. This is only for regular meetings that include audio, video and screen sharing for up to 250 people. We do not currently support Teams live events.

Create Online Meetings for Zoom

As a prerequisite, ensure that cloud ENS (Email Notification Service) is enabled.

Add the key value pair to show the Zoom meeting toggle button in the New Event or Edit Event screens. With the toggle button turned on, when a user creates or edits a meeting event, a Zoom link is automatically created along with the other meeting details.

Note: When the user tries to create a meeting for the first time, user is prompted to authenticate in Zoom with their credentials.

Configuration KeyValue TypeConfiguration ValueDescription
EnableZoomOnlineMeetingsBooleanTrue - Activated
False - Deactivated (Default)
Set to True to show the Zoom meeting toggle button.

(iOS only) Native Share Sheet

This feature allows Workspace ONE Boxer users to send images, videos, links, files, and text directly from any native iOS application to Workspace ONE Boxer. By default, this feature is deactivated.

To activate the feature, set the following key value to true:

Configuration KeyValue TypeConfiguration ValueDescription
PolicyAllowNativeShareBooleanTrue - Activated
False - Deactivated
Set to True to allow users to send images, videos, links, files, and text directly from native iOS application to Workspace ONE Boxer.
By default, the value is False.

(iOS only) Calendar Widget

This feature displays upcoming events of a user in a widget.

To activate the feature for managed devices, set the following key value to true:

Configuration KeyValue TypeConfiguration ValueDescription
PolicyAllowCalendarWidgetBooleanTrue - Activated
False - Deactivated
Set to True for users to view their events in a Workspace ONE Boxer Calendar Widget when the users have added the calendar widget to their home screens.
By default, the value is False.

(Android only) Debug Logs

When having issues with Workspace ONE Boxer, this feature allows users to send logs directly to their IT administrators or support teams without the necessity of being aware of their email address. Administrator can configure the KVP value with the desired email address that must receive the debug logs.

Configuration KeyValue TypeConfiguration ValueDescription
SupportEmailAddressStringEmail addressDebug logs are directly sent to the email address configured as the KVP value.

Resource URL for ENS (Email Notification Service)

PolicyENSResourceURL is an account-based KVP, used only for hybrid modern authentication with Resource URL and not the O365 URL. When the KVP is enabled, administrators can configure a specific Resource URL. To fetch the oAuth access token, Workspace ONE Boxer and ENS must use the configured Resource URL. Hence, Workspace ONE Boxer must share the Resource URL with ENS as part of the register request payload.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyENSResourceURLStringURLUsed by Workspace ONE Boxer and ENS to fetch the OAuth access token for hybrid modern authentication with Resource URL, which is different from the O365 URL. For now, this KVP supports only cloud ENS.

Resource URL for Authentication

AccountOauthResourceURL is an account-based KVP which can be used with hybrid modern authentication when a specific Resource URL is required. During end-user authentication, when this KVP is configured, the value of this KVP is used with more priority even if auto discover presents a valid Resource URL.

Configuration KeyValue TypeConfiguration ValueDescription
AccountOauthResourceURLStringURLA valid URL for authentication

Configuration for Microsoft 365 Enterprise Application Authentication

When Workspace ONE Boxer is added to the Microsoft 365 Enterprise Application, the following Custom Account Configuration KVPs - Office365OAuthClientID and Office365OAuthTenantID - must be added in the Workspace ONE UEM console.

To add the KVPs, navigate to the Boxer- Assignment -> Email Settings screen in the Workspace ONE UEM console.

Configuration KeyValue TypeConfiguration ValueDescription
Office365OAuthClientIDStringIDPredetermined, client ID for Workspace ONE Boxer
Configuration KeyValue TypeConfiguration ValueDescription
Office365OAuthTenantIDStringIDTenant ID in the Microsoft 365 Enterprise application

Add Shared Mailbox with Hybrid Modern Authentication Support

When using hybrid modern authentication, end users can add shared mailboxes in Workspace ONE Boxer. This is an account-level KVP.

Configuration KeyValue TypeConfiguration ValueDescription
PolicyEnableHybridModernAuthEWSBooleanFalse - Deactivated (default)
True - Activated
Set to true, end users can add shared mailboxes with hybrid modern authentication.

For information, see this KB article: How to enable hybrid modern authentication in Workspace ONE Boxer.

(Android only) Conditional Access Policies

When this KVP is enabled, administrators can set Azure Conditional Access Policies and apply these policies through Workspace ONE Boxer. This is an account-level KVP.

NOTE: In addition to enabling the KVP, you must configure Microsoft Azure and Workspace ONE UEM console with few other settings so that both components get integrated. This integration results in adding the support for Azure Conditional Access Policies in Workspace ONE Boxer. For information about configuring Azure and Workspace ONE UEM console, see Configure Support for Azure Conditional Access Policies in Workspace ONE Boxer section in Workspace ONE Boxer Deployment Workspace ONE Boxer Deployment.

Configuration KeyValue TypeConfiguration ValueDescription
ConditionalAccessEnabledBooleanFalse - Deactivated (default)
True - Activated
When the feature is activated, administrators can set the Conditional Access Policies in Microsoft Azure. With these policies, administrators can restrict end user access to their organisation's Office 365 Exchange Online Server only through Workspace ONE Boxer.

(iOS only) Low Network Detection

When a slow network is detected for 10 milliseconds, Workspace ONE Boxer notifies the end user about such low network conditions with a banner on the Inbox screen. This banner can be turned off by using the AppEnableLowNetworkDetection KVP.

Configuration KeyValue TypeConfiguration ValueDescription
AppEnableLowNetworkDetectionBooleanFalse - Deactivated
True - Activated (default)
When the feature is activated, Workspace ONE Boxer notifies the end user about low network conditions by displaying a banner on the Inbox screen. When the KVP is set to false, the end user stops receiving the notification.

(iOS only) Configure Email Search Mode

Administrators can control the search mode configuration using the AccountEmailSearchMode KVP. This is an account-based KVP.

Prerequisite: This feature requires EAS (Exchange ActiveSync) 16.1 or later.

Configuration KeyValue TypeConfiguration ValueDescription
AccountEmailSearchModeInteger0 (default) - Extensive Search

1 - Quick Search
To allow an extensive search, set the value to 0. This search mode shows more details such as attachments and events of each email listed in the search result. These emails are shown in threads.

To allow a quick search, set the value to 1. This search mode returns a list of results in just a few seconds, hence this mode is faster than the extensive search mode.

Note: In the earlier versions of EAS, the default search mode is applied.

End users can choose the desired search mode from the Settings menu in the Workspace ONE Boxer application for each user account.

Deactivate Cached Contact Suggestion

Administrators can use this KVP to turn off contact suggestions when composing emails. As a result, the KVP helps in improving security and reducing the risk of sending emails to wrong recipients. However, access to mailbox contacts and GAL (Global Access List) is maintained.

By default, the value of this KVP is False, which means that the contact suggestions are activated when composing emails.

Configuration KeyValue TypeConfiguration ValueDescription
DisableCachedContactSuggestionsBooleanFalse - Activated (default)
True - Deactivated
If set to True, contact cache is deactivated. However, users can still search for contacts in the mailbox and GAL.

(Android only) Allow Logging Control

The following KVPs IsVerboseLoggingEnabled and AccAllowLogsObfuscationDeactivation can be used to control log collection and enable plain text logging which helps in diagnosing and resolving issues.

Enable Verbose Debug Logging

By default, the value of IsVerboseLoggingEnabled is false and verbose logging is turned off for the end user. When verbose logging is turned off, the end user is presented with a check box, Enable verbose debug logging, in Advanced settings. This check box allows the end user to control verbose logging. When the check box is selected, users are asked for their consent and verbose logging is enabled. When the check box is cleared, verbose logging is deactivated.

Administrators can set the value of this KVP to true and enable verbose logging all the time. When the KVP is set to true, this check box is not presented to the end user.

IsVerboseLoggingEnabled is an application level KVP.

Configuration KeyValue TypeConfiguration ValueDescription
IsVerboseLoggingEnabledBooleanFalse - Verbose logging is turned off (default)

True - Verbose logging is enabled
When the KVP is set to false, verbose logging can be controlled by the end user using a check box in Advanced settings.

When the KVP is set to true, verbose logging is always enabled for the end user and no longer under user control.

Enable Plain Text Logging

By default, the value of AccAllowLogsObfuscationDeactivation is false. This means that plain text logging is turned off and sensitive data is always masked.

If the value of this KVP is set to true and IsVerboseLoggingEnabled is also set to true, a check box Activating Plain Text Logging is presented to the end user in the Advanced setting. This check box provides end user control in allowing plain text logging.

When the check box is selected, plain text logging is activated and sensitive data is not masked when logs are collected. When the check box is cleared or Workspace ONE Boxer application restarts, plain text logging is deactivated and sensitive data is masked in the logs.

AccAllowLogsObfuscationDeactivation is an account level KVP.

Configuration KeyValue TypeConfiguration ValueDescription
AccAllowLogsObfuscationDeactivationBooleanFalse - plain text logging is turned off (default)

True - plain text logging is enabled
When the KVP is set to false, plain logging is turned off and sensitive data is masked during log collection.

When the KVP is set to true and if IsVerboseLoggingEnabled is also set to true, end user can control plain text logging using a check box in Advanced settings.

(iOS only) App Intents

Administrators can use this application-level KVP to provide end users the ability to use App Intents for Workspace ONE Boxer capabilities such as Check next event, Open Mailbox, Search Mail, and so on.

Configuration KeyValue TypeConfiguration ValueDescription
DeactivateAppIntentsBooleanFalse - All capabilities can be used with App Intents (default).

True - App Intents are not allowed.
When App Intents are not allowed, an alert message is displayed to the end users informing them that App Intents are not available due to administrator restrictions.

For more information about these capabilities, see the App Intents section in Supported Capabilities for Omnissa Workspace ONE Boxer.

(iOS only) Administrator Control for Writing Tools

Administrators can use this application-level, boolean KVP to control the availability of Writing Tools, an Apple intelligence functionality. By default, the value of the KVP is false and this functionality is available for end users.

Configuration KeyValue TypeConfiguration ValueDescription
DeactivateWritingToolsBooleanFalse - By default, this Apple Intelligence functionality is activated.

True - Writing Tools functionality is deactivated in the Compose Email and Create and Edit event screens.

Control the Display of Health Check Indicators

Administrators can use HealthCheckIndicators, an application-level, boolean KVP to control the display of health check indicators in the Workspace ONE Boxer interface. This option can be used when health check indicators are not required in the current context for the end users.

Configuration KeyValue TypeConfiguration ValueDescription
HealthCheckIndicatorsBooleanFalse - All health indicators are hidden.

True - All health check indicators are displayed. End users can monitor system health and performance effectively.
By default, the value is true.

Set Microsoft Edge as the Default Browser

Administrators can set Microsoft Edge as the default browser for hyperlinks opened from the Workspace ONE Boxer application.

Configuration KeyValue TypeConfiguration ValueDescription
AppRequireEdgeBrowserBooleanFalse - Hyperlinks open from the default browser as configured in the end user devices except when hyperlinks restrictions are configured by the administrator. For more information about these restrictions, see the Brower Exception List KVP.

True - Microsoft Edge is automatically set as the default browser for end users if the Microsoft Edge application is installed in the end user devices. Hyperlinks from Workspace ONE Boxer application open in Microsoft Edge by default.
By default, the value of this KVP is false.

When the KVP value is true, note the following behavior:

- In iOS devices, end users have the option to change their default browser to something else even if the KVP value is true.

- In Android devices, external hyperlinks open in Microsoft Edge even if the system default browser is different.

Configure XML-based Autodiscover

JSON (v2) Autodiscover can detect incorrect endpoints, resulting in authentication failures. To resolve this problem, administrators can force Workspace ONE Boxer to use the XML (v1) Autodiscover protocol. This protocol bypasses JSON lookups.

For Workspace ONE Boxer to use this protocol, the AccountUseAutodiscoverV1 KVP must be set to true.

Configuration KeyValue TypeConfiguration ValueDescription
AccountUseAutodiscoverV1BooleanFalse - JSON (v2) Autodiscover is used as the option to detect endpoints.

True - XML (v1) Autodiscover protocol is used.
By default, the value of this KVP is false. If users have authentication errors when JSON (v2) is used as an auto discover option, set the KVP to true.

AI email summarization

This functionality delivers instant summaries of complex emails and lengthy threads using on-device AI models. It is deactivated by default and requires activation by both the administrator and the end-user.

Prerequisites

  • Android devices must be compatible with the Gemini Nano AI model, and the model must be enabled.

  • iOS devices must be compatible with Apple Intelligence, and the feature must be enabled.

Configuration KeyValue TypeConfiguration ValueDescription
EnableAIEmailSummarizationBooleanFalse (default) - The Activate AI email summarization setting is not available in Workspace ONE Boxer settings for the end user. As a result, the AI email summarization feature cannot be used.

True - The Activate AI email summarization setting is available for the end user. By default, the check box is not selected.
When the setting is available and the end user selects the setting, a Summarize button is displayed in the email screen. When the end user clicks this button, the email is summarized.

For more information about AI email summarization, see Supported Capabilities for Omnissa Workspace ONE Boxer.

AI Nutrition Label

TitleApple Intelligence Integration for WS1 Boxer iOS
ProductsWorkspace ONE Boxer
Feature NameAI Email Summarization
DescriptionEnables end users to leverage AI for accurate, real-time summaries of individual emails and email threads.
Model TypeGen AI
Model ProviderExternal
Input DataEmail content from the end user
Input Data AuditNot applicable
Data SovereigntyYes
Trained on Customer DataNo
GuardrailsNot applicable
Update FrequencyDepends on Apple Intelligence
Data Retention DurationNone
OptionalityOptional feature. Must be enabled by the administrator in UEM and by the end user in Boxer settings.
TitleGemini Nano Integration for WS1 Boxer Android
ProductsWorkspace ONE Boxer
Feature NameAI Email Summarization
DescriptionEnables end users to leverage AI for accurate, real-time summaries of individual emails and email threads.
Model TypeGen AI
Model ProviderExternal
Input DataEmail content from the end user
Input Data AuditNot applicable
Data SovereigntyYes
Trained on Customer DataNo
GuardrailsNot applicable
Update FrequencyDepends on Google ML Kit
Data Retention DurationNone
OptionalityOptional feature. Must be enabled by the administrator in UEM and by the end user in Boxer settings.

Configure Read Receipt Management

For more information about read receipt management, see Supported Capabilities for Omnissa Workspace ONE Boxer.

For end users to manage sending read receipts, AppEnableSuppressReadReceipts, an application-level KVP must be set to True in Workspace ONE UEM. When the KVP is enabled, end users can configure their preference for managing read receipts in Workspace ONE Boxer using a Send read receipts setting.

Configuration KeyValue TypeConfiguration ValueDescription
AppEnableSuppressReadReceiptsBooleanFalse - Read receipts are always sent and there is no Workspace ONE Boxer setting available for end users.

True - A Send read receipts setting is available in Workspace ONE Boxer settings. End users can use this setting and configure their preference for managing read receipts.
By default, the value of this KVP is false.

Enable OAuth Email Mismatch Check

EnableOAuthEmailMismatchCheck is an application-level KVP. When enabled, Workspace ONE Boxer compares the identity returned by OAuth token claims against the expected email account or username. If the token claims do not match with the expected values, sign-in is blocked with an authentication mismatch error message.

Configuration KeyValue TypeConfiguration ValueDescription
EnableOAuthEmailMismatchCheckBooleanTrue - Workspace ONE Boxer compares the identity returned by OAuth token claims against the expected email account or username.

False - The mismatch check is skipped.
By default, the value of this KVP is true.

Important Notes

If a user has changed any settings on the Boxer application, as an administrator you cannot modify the following console keys:

  • AccountDefaultSignature
  • AccountName
  • AccountUserDisplayName
  • AccountSyncEmail
  • AccountSyncCalendar
  • AccountSyncContacts
  • AccountNotifyEmail
  • AccountNotifyCalendar
  • AccountNotifyPush

Boxer maintains a flag indicating whether the setting has been changed. Even if the user changes the local setting identical to default, Boxer still treats it as a user change. If a local change is not made by the user, the updated console configuration is used.

Note: Any configuration changes for Boxer made on the console takes around 15 minutes to reflect the change on the device.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…