# Configuring Email in Windows devices

You can configure the organization **email account** on the Mail app for Windows devices by deploying Windows email account settings. Push the policy to the devices and the users need not set up email on their devices by themselves. This lets the IT admins set up email settings and synchronize the user’s email accounts with the email server on the devices remotely.

 Notes:- This feature works on **Windows 10 and Windows 11 PCs and tablets**.

 

Configure Windows Email settings
--------------------------------

To configure Email settings,

1. Login to your **Hexnode UEM** portal.
2. Navigate to the **Policies** tab.
3. Click on **New Policy** to create a new one or click on any policy to edit an existing one. Enter the *Policy Name* and *Description* in the provided fields.
4. Navigate to **Windows** and select **Email** under *Accounts*.
5. Click on **Configure**.

Email settings

 SettingsDescriptionAccount DescriptionEnter a name/ description to differentiate between multiple email configurations.Account TypeSelect the option **IMAP** (Internet Message Access Protocol) if you want to store all emails on the server and sync them with the device. *By default*, the *Account Type* is set to **POP** (Post Office Protocol) which enables you to store emails (received and sent) on the device.

Email Address (Reply Address)Enter the email address of the user. The field supports the use of [wildcards](https://www.hexnode.com/mobile-device-management/help/how-to-pass-device-and-user-information-using-the-wildcards-supported-by-hexnode-mdm/). The supported wildcard is **%email%**.User Display NameEnter the display name of the user. The field supports the use of [wildcards](https://www.hexnode.com/mobile-device-management/help/how-to-pass-device-and-user-information-using-the-wildcards-supported-by-hexnode-mdm/). The supported wildcards are: - **%name%**
- **%email%**

Incoming Mail ServerEnter the server address or IP address of the incoming email server. An incoming mail server is responsible for handling incoming mails of an email account.DomainEnter the name of the email domain. You may use the following [wildcards](https://www.hexnode.com/mobile-device-management/help/how-to-pass-device-and-user-information-using-the-wildcards-supported-by-hexnode-mdm/): - **%domain%**
- **%netbiosname%**

User NameEnter the username to get authenticated with the email server and retrieve all emails from the server. The field supports the use of [wildcards](https://www.hexnode.com/mobile-device-management/help/how-to-pass-device-and-user-information-using-the-wildcards-supported-by-hexnode-mdm/). The supported wildcards are: - **%username%**
- **%email%**

Authentication SecretEnter the email account password.  Note: 
If multi-factor authentication is enabled for the email account, but not supported by the native mail application, add the app password instead of the account password.

Outgoing Mail ServerEnter the server address or IP address of the outgoing email server. An outgoing mail server is responsible for handling the delivery of mails sent from an email account.Authentication RequiredSelect the option *Authentication Required* if authentication is required for the outgoing email server. *Disabled* by default.

SMTP Alternate EnabledSelect the option *SMTP Alternate Enabled* to enable an alternate SMTP email account. *Disabled* by default.

SMTP Alternate DomainEnter the domain name of the alternate SMTP email account.SMTP Alternate Authentication NameEnter the display name of the alternate SMTP email account.SMTP Alternate PasswordEnter the password required to access the alternate SMTP email account.Linger (Update Frequency)Select the time interval for updating the emails on the device. The available options are Manually (**Manually** update emails), **15 Min**, **30 Min**, **60 Min**, and **120 Min** (*default*).

Download DaysSelect the number of days’ worth of emails you need to download onto the device. The available options are **All emails**, **7 Days**, **14 Days**, and **30 Days** (*default*).

E-mail TypeSelect the option **Visual Voice Mail** to convert the voicemail into text, along with a slider to hear the voicemail from the part you want to hear. *By default*, the *E-mail Type* is set to **Normal Email.**

Incoming Server Use SSLSelect the option *Incoming Server Use SSL* to use SSL for the incoming server. SSL establishes an encrypted connection between the email server and the device for secure communication.

Outgoing Server Use SSLSelect the option *Outgoing Server Use SSL* to use SSL for the outgoing server.

 

 

![Configuring email for Windows devices using mdm](https:2021/02/Configuring-email-settings-in-Windows-devices-using-mdm.png "Configuring email settings in Windows devices using mdm")

Apply Email policy to Devices/Groups
------------------------------------

There are two ways by which you can associate restrictions with the devices in bulk.

If you haven’t saved the policy yet,

1. Navigate to **Policy Targets**.
2. Click on **+ Add Devices**, search and select the required device(s) to which you need to apply the policy > Click **OK**.
3. Click on **Save** to apply the policies to the devices.

To associate the policies with a device group, select **Device Groups** from the left pane under Policy Targets, and follow the above instructions. Similarly, you can associate the policy with **Users**, **User Groups**, or **Domains** from the same pane.

If you’ve already saved the policy and taken to the page which displays the policy list,

1. Select the required policy.
2. Click on **Manage** > select **Associate Targets**.
3. Select **Device**/ **User**/ **Device Group**/ **User Group**/ **Domain**.
4. Search and select the device(s)/ user(s)/ device group(s)/ user group(s)/ domain(s) to which you need to apply the policy > Click **Associate**.

What happens at the device end? 
--------------------------------

Once the *Email* accounts policy is associated with the device, the configured mail account gets synchronized with the *Mail* app.
![email account configured on the Mail app](https:2021/09/email-account-listed-on-the-mail-app.png "email account listed on the mail app")
The given email account will also be listed among other email accounts used by email, calendar and contacts on the device settings under *Email & accounts*.
![Email account appears on Email & accounts of the device settings page](https:2021/09/Email-account-listed-on-the-device-settings.png "Email account listed on the device settings")

Frequently Asked Questions (FAQs)
---------------------------------

#### 1. What is the difference between IMAP and POP?

IMAP (Recommended) syncs folders and changes across all devices. POP downloads emails to the local device and typically removes them from the server, making it harder to access the same mail on other devices.

#### 2. Will the removal of an associated Email policy result in the deletion of a user’s existing emails?

Removing the Email policy or disenrolling the device will remove the account profile and any locally cached data from the Windows Mail application. However, the original emails remain stored on the organization’s email server and are not deleted.

#### 3. Does the “Download Days” configuration in the email policy impact the status of emails on the primary mail server?

No. This setting exclusively dictates the duration of the local cache on the Windows device to optimize storage and data usage. It has no impact on the retention or deletion of messages residing on the email server.

Troubleshooting
---------------

#### 1. Emails are not being sent (Outgoing Mail fails).

**Probable Cause:**

Many servers require separate authentication for SMTP (outgoing) to prevent spam.

**Solution:**

Ensure that the **“Authentication Required”** option is enabled in the Email policy.

#### 2. Policy shows “Success”, but the account is missing.

**Probable Cause:**

Windows privacy settings might be blocking apps from accessing the “Email” or “Calendar” services.

**Solution:**

Go to **Settings > Privacy & security > Email** on the device and ensure **“Let apps access your email”** option is toggled **On**.

Best Practices
--------------

- **Prioritize IMAP over POP:** To ensure your users have a consistent experience across their phones, tablets, and Windows PCs, always use **IMAP** which ensures that statuses and folder structures are synced everywhere.
- **Optimize Local Storage:** To save battery and storage, set **Download Days** to **30 Days** rather than “All Emails.” This prevents the Mail app from consuming excessive storage.