Sophos Mobile: Prepare an Outlook account as a managed app
Sophos Mobile describes account settings for managed Outlook on Android and iPhone/iPad, for both Exchange Online and Exchange Server. This is not yet an approved configuration for your own tenant. For Exchange Online delivered to iOS through a third-party UEM in the Managed devices channel, Microsoft also specifies IntuneMAMUPN. This key is missing from both Sophos iOS examples; that does not, however, establish a requirement for the separate on-premises Exchange Server example. Whether the requirement applies there, and which confirmed UPN value Sophos should deliver for the key in the specific scenario, remains unresolved. The values below are therefore only for comparing the vendor examples, not a ready-to-copy four-way recipe. The authentication method for Exchange Server also needs to be clarified first.
Check the environment and identity first
Prerequisites are a Sophos Mobile license with device-management capabilities (Sophos Mobile Device Management or Sophos Mobile), suitable Android Enterprise management or an actually managed iPhone/iPad app, and an assignment authorized for the pilot. A Mobile Threat Defense-only license does not establish that this MDM route is available. Check supported device/enrollment modes, app/OS versions, and permissions separately in the specific tenant; this is neither a route for an arbitrary personal Outlook installation nor an Intune app protection guide.
Distinguish device enrollment from the delivery channel: Microsoft requires enrolled devices and the MDM OS channel for Account setup configuration and Organization allowed accounts mode; in Intune, this is called Managed devices. The APP channel (Intune App Protection Policy), called Managed apps there, is not a substitute for this account setup on unenrolled devices. Certain general app settings, by contrast, can also be delivered through APP without device enrollment. A managed Outlook app alone therefore does not establish that the enrollment mode or delivery channel is appropriate for the account settings below.
Preparing an account is not restricting accounts: The example values prepopulate details for a work account; they do not automatically block personal accounts or accounts from other storage providers. Microsoft describes the separate Organization allowed accounts mode for that purpose, with its own platform-specific policy keys. That restriction has neither been configured nor tested here and is not being added to the vendor examples. Account settings or their successful delivery also do not establish that Intune app protection or Conditional Access is in place. If only organizational accounts are to be allowed, clarify that requirement separately with the responsible teams and verify its implementation in the authorized pilot.
Before making changes, confirm with the mail and identity teams: Is the mailbox in Exchange Online or on your own Exchange Server? Which primary SMTP address should Outlook use for sending and receiving, which username/UPN is used to sign in, and are they actually identical? Which Microsoft 365 cloud or externally reachable Exchange ActiveSync host, domain, and authentication method have been approved? The example address outlook.office365.com applies to the worldwide Microsoft 365 cloud, not automatically to other clouds. mail.example.com and mycompany.com are illustrative vendor values only, not operational destinations.
Pause the iOS pilot while the key question remains open: Microsoft distinguishes com.microsoft.outlook.EmailProfile.EmailAddress (SMTP address) from com.microsoft.outlook.EmailProfile.EmailUPN (sign-in identifier). For iOS configuration keys delivered through a third-party UEM in the Managed devices channel, Microsoft also requires the additional string key IntuneMAMUPN with a UPN for Exchange Online; Sophos does not list it in its iOS example or provide a documented Sophos UPN placeholder for it. These sources do not establish whether that Microsoft requirement extends to the separate on-premises Basic Auth case. Do not assume %_EMAILADDRESS_% can stand in for the UPN, or blindly add the key with an invented token or across all variants. Clarify the value and scope with current vendor documentation or vendor support, and verify them on an authorized pilot device. Microsoft key names are case-sensitive.
Android: Compare documented fields only after approval
Sophos requires Outlook as a managed Google Play app. In Sophos Mobile, the documented route is Apps > Android > [approved Outlook] > Use managed configuration > Edit managed configuration; save both the form and then the app entry with Save. The following labels are Android fields in this app form, not iOS com.microsoft.outlook.* keys:
- Exchange Online (Sophos example):
email address=$EMAILADDRESS;description for account=$EMAILADDRESS;exchange server url=outlook.office365.com;username=$EMAILADDRESS;account type=ModernAuth. - Exchange Server (documented Basic Auth example only):
email address=$EMAILADDRESS;description for account=$EMAILADDRESS;exchange server url= the actual authorized, externally reachable Exchange host (Sophos examplemail.example.com);domain of user account= verified account domain (Sophos examplemycompany.com);username=$EMAILADDRESS;server authentication method=Username and Password;account type=BasicAuth.
Under Setup > Google setup > Android Enterprise > Email placeholder, Use the assigned user’s email address determines whether $EMAILADDRESS comes from the email address of the person assigned to the device. If the option is off, Sophos uses the email address used for device enrollment; without an assigned person, a placeholder may be empty. Sophos documents an update to installed apps after the next synchronization when the assigned user changes and the option is enabled—not an automatic new Outlook sign-in. Check how the placeholder actually resolves and whether it matches the SMTP address and sign-in identifier in the pilot. According to Sophos, a change to the Android app configuration is sent to all devices with the app installed and may take several minutes: Do not use a global Save as if it were an isolated pilot test. If a managed configuration was edited before August 13, 2022, Sophos says it must be manually re-entered when editing it again or installing an app update with a changed configuration.
iPhone/iPad: Documented keys, not yet complete delivery instructions
Outlook must be installed as a managed app. Check its status under Show device > Installed apps > Managed. The documented Sophos path is Apps > iOS & iPadOS > [Outlook] > Settings and VPN: Show > Managed configuration: Add parameter > Apply > Save. On devices with Apple User Enrollment, an existing unmanaged app cannot simply be converted to a managed app. Do not assume that reinstalling, signing out, or converting the app is a harmless way back.
Sophos lists these Name = value pairs, each of type string; given the unresolved IntuneMAMUPN issue, these lists are for source comparison only, not approval to enter them:
- Exchange Online:
com.microsoft.outlook.EmailProfile.EmailAccountName=%_EMAILADDRESS_%;com.microsoft.outlook.EmailProfile.EmailAddress=%_EMAILADDRESS_%;com.microsoft.outlook.EmailProfile.EmailUPN=%_EMAILADDRESS_%;com.microsoft.outlook.EmailProfile.ServerHostName=outlook.office365.com;com.microsoft.outlook.EmailProfile.AccountType=ModernAuth. - Exchange Server (Sophos Basic Auth example):
com.microsoft.outlook.EmailProfile.EmailAccountName=%_EMAILADDRESS_%;com.microsoft.outlook.EmailProfile.EmailAddress=%_EMAILADDRESS_%;com.microsoft.outlook.EmailProfile.EmailUPN=%_EMAILADDRESS_%;com.microsoft.outlook.EmailProfile.ServerHostName= approved Exchange host (Sophos examplemail.example.com);com.microsoft.outlook.EmailProfile.AccountType=BasicAuth;com.microsoft.outlook.EmailProfile.AccountDomain= verified account domain (Sophos examplemycompany.com);com.microsoft.outlook.EmailProfile.ServerAuthentication=Username and Password.
Sophos describes %_EMAILADDRESS_% as the email address of the person assigned to the device when the app is installed. It is not the Android placeholder $EMAILADDRESS and does not establish that the value matches the authentication UPN. If the SMTP address and UPN differ, first establish a vendor-confirmed way to deliver the correct UPN; do not silently put the same value in both fields.
Authentication and pilot: Delivery is not sign-in
ModernAuth in the Sophos Exchange Online example bypasses neither user sign-in nor MFA or conditional access policies. Microsoft has disabled Basic Authentication for Exchange Online; the on-premises BasicAuth example must not be applied to Exchange Online or used as a reason to weaken tenant security. For on-premises Exchange Server, Microsoft describes Basic Authentication with ActiveSync only for the relevant on-premises accounts without Hybrid Modern Authentication; Hybrid Modern Authentication may offer another route. The responsible operators must confirm whether the version, protocol, TLS, host, account domain, and permissions are appropriate for their Exchange environment. Security boundary: According to Microsoft, on-premises Exchange mailboxes using Basic Authentication in Outlook for iOS/Android support neither Microsoft Entra Conditional Access nor Intune app protection policies. The Sophos BasicAuth example is therefore not an equivalently protected substitute for an approved Modern Auth route; before a pilot, confirm whether it is permitted and check supported Exchange/Outlook versions and Microsoft licenses with the responsible teams.
Existing Basic Auth profiles when switching to HMA: According to Microsoft, after Hybrid Modern Authentication is enabled, users must remove their existing Basic Auth account profile in Outlook and create a new profile using Hybrid Modern Authentication. Changing BasicAuth to ModernAuth in the managed app configuration alone does not demonstrably migrate that profile and is not a documented rollback path. Plan profile removal and recreation only as a separate, authorized migration step with the mail and identity teams: check prerequisites and effects on sign-in and service availability, record the prior state, and verify the new profile, sign-in, and sending and receiving in the correct mailbox. Do not infer a blanket profile removal or tenant-wide authentication change from these example values.
Only after resolving the open questions about keys, identity, and authentication should you plan an authorized, tightly scoped pilot: back up the existing configuration and assignment, document the target device and app management status, and check in advance the actual effect of an app configuration change on other devices with the app installed. On Android, check the delivered configuration and resolved $EMAILADDRESS after synchronization; on iOS, check managed status and the delivered names, values, and types, including any confirmed IntuneMAMUPN requirement. Configuration delivered means only that the values arrived. Separately, observe in Outlook whether the correct account is found, sign-in succeeds with the permitted factors and policies, and sending and receiving work in the correct mailbox. None of these checks has been performed for this draft on a tenant or device.
Safe stop: If the identity, delivery, sign-in, or mailbox does not match, do not broaden the assignment. With the platform and mail owners, restore the previously documented and approved app configuration/assignment, wait for it to be delivered again, and repeat the same observations. According to Sophos, turning off Use managed configuration removes the Android configuration from installed apps; it proves neither that an Outlook account has been safely removed nor anything about the data remaining or a successful rollback. App uninstallation, device unenrollment, and a tenant-wide change to the sign-in method must not be treated as rollback options without verification.