Skip to main content

August 18, 2026

Frequently Asked Questions for Omnissa Workspace ONE Boxer

This topic covers the most common questions asked by customers and administrators about the features in Workspace ONE Boxer.

FAQs for Mailbox Delegation

Q: What are the supported Exchange versions?

The supported versions are: Exchange SE and Office 365.

Q: Which protocol is used for the delegation feature?

Exchange Web Service protocol is used for the delegation feature. You must enable EWS on your Exchange Server.

Q: Does ActiveSync support the Mailbox Delegation?

This feature is not supported on ActiveSync due to the technical limitations of the ActiveSync protocol.

Q: Does this feature support the Secure Email Gateway (SEG)?

Yes, this feature supports Secure Email Gateway (SEG).

FAQs for Multiple Managed Accounts

Q: Is it required to configure and use all managed accounts?

No, you can skip signing into the multiple accounts. If at least one managed account is signed in, you can use Boxer. You can also select to sign out from a particular account.

Q: How can I sign out from a managed account?

To sign out from a managed account, navigate to Boxer settings > Select the Account > Remove Account.

Q: How can I deactivate notification for a particular email account?

To deactivate notification, navigate to Boxer settings > Select the Account > Notification settings and deselect the email notifications preference.

Q: What happens if the app passcode and SSO are enabled at the same time?

Note: App Passcode is not supported in Workspace ONE Boxer 22.05 and later for standalone enrollments. You can migrate the Workspace ONE Boxer passcode settings to the SDK passcode settings. For more information about configuring the SDK passcode, see the Security Policies Profiles for the SDK section in the SDK and Managing Applications documentation at Omnissa Product Documentation.

Boxer uses the SDK for SSO. If SSO and the Boxer Passcode are enabled, then the SSO settings are used.

General FAQs

Q: If access is restricted to the https://discovery.awmdm.com endpoint, which services are impacted?

If access to the https://discovery.awmdm.com endpoint is restricted, the SSL/TLS inspection service is impacted. Network traffic cannot be SSL/TLS inspected because the network traffic interferes with certificate pinning. Certificate pinning is required for secure communication with the endpoint.

Q: Is Boxer communication impacted by access to https://discovery.awmdm.com endpoint? In this scenario why only Android 9 and Android 10 devices be impacted?

The SSL/TLS network traffic cannot inspect as certificate pinning is impacted. Android 9 or 10 might have added extra security for SSL/TLS. The code that connects to https://discovery.awmdm.com is part of AW SDK.

FAQs for Azure Information Protection (AIP) Sensitivity Labels

This topic covers the most common questions asked by customers and administrators about the AIP feature in Workspace ONE Boxer.

Q: Where can I create and manage labels?

You can create AIP labels in the Microsoft Purview portal.

Q: What versions of Exchange can I use for the AIP feature?

You can only use Office 365 for the AIP feature.

Q: Which authentication method does AIP support?

AIP feature supports only Modern authentication.

Q: What is the minimum supported Boxer version for the AIP feature?

5.19 for iOS and Android Boxer.

Q: Why aren't my labels displayed?

The following are some of the reasons why you are unable to see the labels:

  • Labels are not configured in Azure and the list is empty.
  • You have not authenticated in Azure.
  • You did not provide the consent in the Microsoft account to use the AIP Sensitivity labels application from Omnissa.
  • Your admin has not enabled the PolicySensitivityLabelsEmailClassification key.
    For more information about this key, see the Enable AIP Sensitivity Labels in Workspace ONE Boxer section in Application Configurations for Workspace ONE Boxer.

Q: Why I cannot access emails?

The following are some possible reasons for which you cannot access the emails:

  • You are not part of the allowed user group or organization in the User Permissions settings of the label.

  • You do not have the permission to view the content.

  • Your access time has expired.

    Note: Content access is managed in File Content Expiration settings of the label. Proper error messages and action items can be displayed in Boxer if they are configured in the settings in Azure.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…