Exchange ActiveSync
com.apple.eas.account
The payload that configures Exchange ActiveSync accounts.
Configuration Keys (43)
| Key | Type | Title |
|---|---|---|
UserNameThis user name for this Exchange account. Required for noninteractive installations like MDM in iOS. | string | User |
EmailAddressThe full email address for the account. If not present in the payload, the device prompts for this string during profile installation. | string | Email address |
PasswordThe password of the account. Use only with encrypted profiles. | string | Password |
OverridePreviousPasswordiOS 14.0+ If 'true', the system overrides the previous user/EAS password with the new EAS password in the payload. Default: false | boolean | Override previous password |
HostrequiredThe Exchange server host name or IP address. | string | Exchange ActiveSync host |
SSLIf 'true', the system enables SSL for authentication. Default: false | boolean | Use SSL |
OAuthiOS 12.0+ If 'true', enables OAuth for authentication. If enabled, don't specify a password. Available only in iOS 12.0 and above. Default: false | boolean | Use OAuth |
CertificateiOS 7.0+ The '.p12' identity certificate in NSData blob format, for accounts that allow authentication via certificate. | data | Authentication credential |
CertificateNameiOS 7.0+ The name or description of the certificate. | string | Authentication credential name |
CertificatePasswordThe password necessary for the '.p12' identity certificate. Used with mandatory encryption of profiles. | string | Authentication credential password |
PreventMoveiOS 5.0+ If 'true', the system prevents moving messages from out of this email account into another account. This setting also prevents forwarding or replying from an account other than the recipient of the message. Default: false | boolean | Prevent move |
PreventAppSheetiOS 5.0+ If 'true', prevents this account from sending mail in any app other than the Apple Mail app. Default: false | boolean | Prevent app sheet |
PayloadCertificateUUIDThe UUID of the certificate payload within the same profile to use for the identity credential. If this field is present, the Certificate field isn't used. | string | Payload certificate UUID |
SMIMEEnableddeprecatediOS 5.0+ · deprecated 10.0 · not on visionOS If 'true', the system enables S/MIME encryption. In iOS 10.0 and later, this key is ignored. Use 'SMIMESigningEnabled' instead. Default: false | boolean | S/MIME enabled |
SMIMESigningEnablediOS 10.3+ If 'true', the system enables S/MIME signing for this account. Default: false | boolean | S/MIME signing enabled |
SMIMESigningCertificateUUIDiOS 5.0+ The UUID of the identity certificate used to sign messages sent from this account. | string | S/MIME signing certificate |
SMIMEEncryptionEnableddeprecatediOS 10.3+ · deprecated 12.0 · not on visionOS If 'true', the system enables S/MIME encryption for this account. This key is deprecated. Use 'SMIMEEncryptByDefault' instead. Default: false | boolean | S/MIME encryption enabled |
SMIMEEncryptionCertificateUUIDiOS 5.0+ The payload UUID of the identity certificate used to decrypt messages sent to this account. The system attaches the public certificate to outgoing mail to allow the user to receive encrypted mail. When the user sends encrypted mail, the system uses the public certificate to encrypt the copy of the mail in the user's Sent mailbox. | string | S/MIME encryption certificate |
SMIMEEnablePerMessageSwitchdeprecatediOS 8.0+ · deprecated 12.0 · not on visionOS If 'true', the system displays the per-message encryption switch in the Mail Compose UI. This key is deprecated. Use 'SMIMEEnableEncryptionPerMessageSwitch' instead. Default: false | boolean | S/MIME enable per-message switch |
SMIMESigningUserOverrideableiOS 12.0+ If 'true', the user can turn S/MIME signing on or off in Settings. Default: false | boolean | Allow user to toggle S/MIME Signing |
SMIMESigningCertificateUUIDUserOverrideableiOS 12.0+ If 'true', the user can select the signing identity. Default: false | boolean | Allow user to select S/MIME Identity |
SMIMEEncryptByDefaultiOS 12.0+ If 'true', the system enables S/MIME encryption by default. If 'SMIMEEnableEncryptionPerMessageSwitch' is 'false', the user can't change this default. Default: false | boolean | Enable S/MIME Encryption |
SMIMEEncryptByDefaultUserOverrideableiOS 12.0+ If 'true', the system enables encryption by default and the user can't change it. Default: false | boolean | Allow user to select S/MIME Encryption |
SMIMEEncryptionCertificateUUIDUserOverrideableiOS 12.0+ If 'true', the user can select the S/MIME encryption identity, and encryption is on. Default: false | boolean | Allow user to select S/MIME Encryption Certificate |
SMIMEEnableEncryptionPerMessageSwitchiOS 12.0+ If 'true', the system displays the per-message encryption switch in the Mail Compose UI. Default: false | boolean | Allow user to select S/MIME Encryption per message |
EnableCalendarsiOS 13.0+ If 'false', the system disables the Calendars service for this account. The user can reenable Calendars service in Settings unless 'EnableCalendarsUserOverridable' is 'false'. Note: At least of the following fields needs to be 'true': 'EnableMail', 'EnableContacts', 'EnableCalendars', 'EnableReminders', and 'EnableNotes'. Default: true | boolean | Enabled Services - Calendars |
EnableContactsiOS 13.0+ If 'false', the system disables the Contacts service for this account. The user can reenable Contacts service in Settings unless 'EnableContactsUserOverridable' is 'false'. Note: At least of the following fields needs to be 'true': 'EnableMail', 'EnableContacts', 'EnableCalendars', 'EnableReminders', and 'EnableNotes'. Default: true | boolean | Enabled Services - Contacts |
EnableMailiOS 13.0+ If 'false', the system disables the Mail service for this account. The user can reenable Mail service in Settings unless 'EnableMailUserOverridable' is 'false'. Note: At least of the following fields needs to be 'true': 'EnableMail', 'EnableContacts', 'EnableCalendars', 'EnableReminders', and 'EnableNotes'. Default: true | boolean | Enabled Services - Mail |
EnableNotesiOS 13.0+ If 'false', the system disables the Notes service for this account. The user can reenable Notes service in Settings unless 'EnableNotesUserOverridable' is 'false'. Note: At least of the following fields needs to be 'true': 'EnableMail', 'EnableContacts', 'EnableCalendars', 'EnableReminders', and 'EnableNotes'. Default: true | boolean | Enabled Services - Notes |
EnableRemindersiOS 13.0+ If 'false', the system disables the Reminders service for this account. The user can reenable Reminders service in Settings unless 'EnableRemindersUserOverridable' is 'false'. Note: At least of the following fields needs to be 'true': 'EnableMail', 'EnableContacts', 'EnableCalendars', 'EnableReminders', and 'EnableNotes'. Default: true | boolean | Enabled Services - Reminders |
EnableCalendarsUserOverridableiOS 13.0+ If 'false', the system prevents the user from changing the state of the Calendars service for this account in Settings. Default: true | boolean | Account Modification - Calendars |
EnableContactsUserOverridableiOS 13.0+ If 'false', the system prevents the user from changing the state of the Contacts service for this account in Settings. Default: true | boolean | Account Modification - Contacts |
EnableMailUserOverridableiOS 13.0+ If 'false', the system prevents the user from changing the state of the Mail service for this account in Settings. Default: true | boolean | Account Modification - Mail |
EnableNotesUserOverridableiOS 13.0+ If 'false', prevents the user from changing the state of the Notes service for this account in Settings. Default: true | boolean | Account Modification - Notes |
EnableRemindersUserOverridableiOS 13.0+ If 'false', the system prevents the user from changing the state of the Reminders service for this account in Settings. Default: true | boolean | Account Modification - Reminders |
disableMailRecentsSyncingIf 'true', the system excludes this account from Recent Addresses syncing. Default: false | boolean | Disable mail recents syncing |
MailNumberOfPastDaysToSyncThe number of days in the past to sync mail on the device. For no limit, use the value '0'. Default: 7 Range: No Limit (0), 1 (1), 3 (3), 7 (7), 14 (14), 31 (31) | integer | Past days of mail to sync |
CommunicationServiceRulesiOS 10.0+ The communication service handler rules for this account. | dict | Communication service rules |
DefaultServiceHandlersiOS 10.0+ The default handlers to use for contacts from this account. | dict | Default service handlers |
AudioCalliOS 10.0+ The bundle identifier of the default application to use for audio calls made to contacts from this account. | string | App for audio calls |
VPNUUIDiOS 14.0+ The VPNUUID of the per-app VPN the account uses for network communication. | string | VPNUUID |
HeaderMagicdeprecatediOS · deprecated 7.0 · not on visionOS The value of the 'X-Apple-Config-Magic' header in each EAS HTTP request. | string | — |
allowMailDropiOS 9.2+ If 'true', the system enables this account to use Mail Drop. Default: false | boolean | Allow mail drop |
OAuthSignInURLiOS 13.0+ The URL that this account should use for signing in through OAuth. Ignored unless 'OAuth' is 'true'. If you specify this URL, auto-discovery isn't used for this account, so you need to also specify a host. | string | — |
OAuthTokenRequestURLiOS 13.0+ The URL that this account should use for token requests through OAuth. Ignored unless 'OAuth' is 'true'. | string | — |