Exchange ActiveSync (com.apple.eas.account)

com.apple.eas.account

The payload that configures Exchange ActiveSync accounts.

iOS(4.0)visionOS(1.1)
Branch: release

Settings (45)

SettingTypeRequiredDefaultManual InstallSupported OS
Email address
EmailAddress
The full email address for the account. If not present in the payload, the device prompts for this string during profile installation.
stringoptional—
✓Yes
iOS (4.0+)visionOS (1.1+)
Exchange ActiveSync host
Host
The Exchange server host name or IP address.
stringoptional—
✓Yes
iOS (4.0+)visionOS (1.1+)
Use SSL
SSL
If `true`, the system enables SSL for authentication.
booleanoptionalfalse
✓Yes
iOS (4.0+)visionOS (1.1+)
Use OAuth
OAuth
If `true`, enables OAuth for authentication. If enabled, don't specify a password. Available only in iOS 12.0 and above.
booleanoptionalfalse
✓Yes
iOS (12.0+)
User
UserName
This user name for this Exchange account. Required for noninteractive installations like MDM in iOS.
stringoptional—
✓Yes
iOS (4.0+)visionOS (1.1+)
Password
Password
The password of the account. Use only with encrypted profiles.
stringoptional—
✓Yes
iOS (4.0+)visionOS (1.1+)
Authentication credential
Certificate
The `.p12` identity certificate in NSData blob format, for accounts that allow authentication via certificate.
dataoptional—
✓Yes
iOS (7.0+)
Authentication credential name
CertificateName
The name or description of the certificate.
stringoptional—
✓Yes
iOS (7.0+)
Authentication credential password
CertificatePassword
The password necessary for the `.p12` identity certificate. Used with mandatory encryption of profiles.
stringoptional—
✓Yes
iOS (4.0+)visionOS (1.1+)
Prevent move
PreventMove
If `true`, the system prevents moving messages from out of this email account into another account. This setting also prevents forwarding or replying from an account other than the recipient of the message.
booleanoptionalfalse
✓Yes
iOS (5.0+)
Prevent app sheet
PreventAppSheet
If `true`, prevents this account from sending mail in any app other than the Apple Mail app.
booleanoptionalfalse
✓Yes
iOS (5.0+)
Payload certificate UUID
PayloadCertificateUUID
The UUID of the certificate payload within the same profile to use for the identity credential. If this field is present, the Certificate field isn't used.
stringoptional—
✓Yes
iOS (4.0+)visionOS (1.1+)
S/MIME enabled
SMIMEEnabled
Deprecated (iOS 10.0)
If `true`, the system enables S/MIME encryption. In iOS 10.0 and later, this key is ignored. Use `SMIMESigningEnabled` instead.
booleanoptionalfalse
✓Yes
iOS (5.0 - 10.0)
S/MIME signing enabled
SMIMESigningEnabled
If `true`, the system enables S/MIME signing for this account.
booleanoptionalfalse
✓Yes
iOS (10.3+)
S/MIME signing certificate
SMIMESigningCertificateUUID
The UUID of the identity certificate used to sign messages sent from this account.
stringoptional—
✓Yes
iOS (5.0+)
S/MIME encryption enabled
SMIMEEncryptionEnabled
Deprecated (iOS 12.0)
If `true`, the system enables S/MIME encryption for this account. This key is deprecated. Use `SMIMEEncryptByDefault` instead.
booleanoptionalfalse
✓Yes
iOS (10.3 - 12.0)
S/MIME encryption certificate
SMIMEEncryptionCertificateUUID
The payload UUID of the identity certificate used to decrypt messages sent to this account. The system attaches the public certificate to outgoing mail to allow the user to receive encrypted mail. When the user sends encrypted mail, the system uses the public certificate to encrypt the copy of the mail in the user's Sent mailbox.
stringoptional—
✓Yes
iOS (5.0+)
S/MIME enable per-message switch
SMIMEEnablePerMessageSwitch
Deprecated (iOS 12.0)
If `true`, the system displays the per-message encryption switch in the Mail Compose UI. This key is deprecated. Use `SMIMEEnableEncryptionPerMessageSwitch` instead.
booleanoptionalfalse
✓Yes
iOS (8.0 - 12.0)
Disable mail recents syncing
disableMailRecentsSyncing
If `true`, the system excludes this account from Recent Addresses syncing.
booleanoptionalfalse
✓Yes
iOS (4.0+)visionOS (1.1+)
Past days of mail to sync
MailNumberOfPastDaysToSync
The number of days in the past to sync mail on the device. For no limit, use the value `0`.
integeroptional7
✓Yes
iOS (4.0+)visionOS (1.1+)
HeaderMagic
HeaderMagic
Deprecated (iOS 7.0)
The value of the `X-Apple-Config-Magic` header in each EAS HTTP request.
stringoptional—
✓Yes
iOS (legacy - 7.0)
Communication service rules
CommunicationServiceRules
The communication service handler rules for this account.
1 subkey
dictionaryoptional—
✓Yes
iOS (10.0+)
└─
Default service handlers
DefaultServiceHandlers
The default handlers to use for contacts from this account.
1 subkey
dictionaryoptional—
✓Yes
iOS (10.0+)
└─ └─
App for audio calls
AudioCall
The bundle identifier of the default application to use for audio calls made to contacts from this account.
stringoptional—
✓Yes
iOS (10.0+)
Allow mail drop
allowMailDrop
If `true`, the system enables this account to use Mail Drop.
booleanoptionalfalse
✓Yes
iOS (9.2+)
SMIMESigningUserOverrideable
SMIMESigningUserOverrideable
If `true`, the user can turn S/MIME signing on or off in Settings.
booleanoptionalfalse
✓Yes
iOS (12.0+)
SMIMESigningCertificateUUIDUserOverrideable
SMIMESigningCertificateUUIDUserOverrideable
If `true`, the user can select the signing identity.
booleanoptionalfalse
✓Yes
iOS (12.0+)
SMIMEEncryptByDefault
SMIMEEncryptByDefault
If `true`, the system enables S/MIME encryption by default. If `SMIMEEnableEncryptionPerMessageSwitch` is `false`, the user can't change this default.
booleanoptionalfalse
✓Yes
iOS (12.0+)
SMIMEEncryptByDefaultUserOverrideable
SMIMEEncryptByDefaultUserOverrideable
If `true`, the system enables encryption by default and the user can't change it.
booleanoptionalfalse
✓Yes
iOS (12.0+)
SMIMEEncryptionCertificateUUIDUserOverrideable
SMIMEEncryptionCertificateUUIDUserOverrideable
If `true`, the user can select the S/MIME encryption identity, and encryption is on.
booleanoptionalfalse
✓Yes
iOS (12.0+)
SMIMEEnableEncryptionPerMessageSwitch
SMIMEEnableEncryptionPerMessageSwitch
If `true`, the system displays the per-message encryption switch in the Mail Compose UI.
booleanoptionalfalse
✓Yes
iOS (12.0+)
EnableMail
EnableMail
If `false`, the system disables the Mail service for this account. The user can reenable Mail service in Settings unless `EnableMailUserOverridable` is `false`. > Note: > At least of the following fields needs to be `true`: `EnableMail`, `EnableContacts`, `EnableCalendars`, `EnableReminders`, and `EnableNotes`.
booleanoptionaltrue
✓Yes
iOS (13.0+)
EnableContacts
EnableContacts
If `false`, the system disables the Contacts service for this account. The user can reenable Contacts service in Settings unless `EnableContactsUserOverridable` is `false`. > Note: > At least of the following fields needs to be `true`: `EnableMail`, `EnableContacts`, `EnableCalendars`, `EnableReminders`, and `EnableNotes`.
booleanoptionaltrue
✓Yes
iOS (13.0+)
EnableCalendars
EnableCalendars
If `false`, the system disables the Calendars service for this account. The user can reenable Calendars service in Settings unless `EnableCalendarsUserOverridable` is `false`. > Note: > At least of the following fields needs to be `true`: `EnableMail`, `EnableContacts`, `EnableCalendars`, `EnableReminders`, and `EnableNotes`.
booleanoptionaltrue
✓Yes
iOS (13.0+)
EnableReminders
EnableReminders
If `false`, the system disables the Reminders service for this account. The user can reenable Reminders service in Settings unless `EnableRemindersUserOverridable` is `false`. > Note: > At least of the following fields needs to be `true`: `EnableMail`, `EnableContacts`, `EnableCalendars`, `EnableReminders`, and `EnableNotes`.
booleanoptionaltrue
✓Yes
iOS (13.0+)
EnableNotes
EnableNotes
If `false`, the system disables the Notes service for this account. The user can reenable Notes service in Settings unless `EnableNotesUserOverridable` is `false`. > Note: > At least of the following fields needs to be `true`: `EnableMail`, `EnableContacts`, `EnableCalendars`, `EnableReminders`, and `EnableNotes`.
booleanoptionaltrue
✓Yes
iOS (13.0+)
EnableMailUserOverridable
EnableMailUserOverridable
If `false`, the system prevents the user from changing the state of the Mail service for this account in Settings.
booleanoptionaltrue
✓Yes
iOS (13.0+)
EnableContactsUserOverridable
EnableContactsUserOverridable
If `false`, the system prevents the user from changing the state of the Contacts service for this account in Settings.
booleanoptionaltrue
✓Yes
iOS (13.0+)
EnableCalendarsUserOverridable
EnableCalendarsUserOverridable
If `false`, the system prevents the user from changing the state of the Calendars service for this account in Settings.
booleanoptionaltrue
✓Yes
iOS (13.0+)
EnableRemindersUserOverridable
EnableRemindersUserOverridable
If `false`, the system prevents the user from changing the state of the Reminders service for this account in Settings.
booleanoptionaltrue
✓Yes
iOS (13.0+)
EnableNotesUserOverridable
EnableNotesUserOverridable
If `false`, prevents the user from changing the state of the Notes service for this account in Settings.
booleanoptionaltrue
✓Yes
iOS (13.0+)
OAuthSignInURL
OAuthSignInURL
The URL that this account should use for signing in through OAuth. Ignored unless `OAuth` is `true`. If you specify this URL, auto-discovery isn't used for this account, so you need to also specify a host.
stringoptional—
✓Yes
iOS (13.0+)
OAuthTokenRequestURL
OAuthTokenRequestURL
The URL that this account should use for token requests through OAuth. Ignored unless `OAuth` is `true`.
stringoptional—
✓Yes
iOS (13.0+)
OverridePreviousPassword
OverridePreviousPassword
If `true`, the system overrides the previous user/EAS password with the new EAS password in the payload.
booleanoptionalfalse
✓Yes
iOS (14.0+)
VPNUUID
VPNUUID
The VPNUUID of the per-app VPN the account uses for network communication.
stringoptional—
✓Yes
iOS (14.0+)

Apple MDM & DDM Policy Explorer

Explore the full catalogue of Apple Mobile Device Management (MDM) and Declarative Device Management (DDM) policies for macOS and iOS. Search, filter, and reference policy keys for use with Microsoft Intune, Jamf, or any standards-compliant MDM solution.

Reference: policy categories & common keys

Policy categories

  • Configuration Profile
  • Declarative Configuration
  • Declarative Activation
  • Declarative Asset
  • Declarative Management

Common policy keys

  • com.apple.wifi.managed – Wi-Fi network configuration
  • com.apple.vpn.managed – VPN configuration
  • com.apple.applicationaccess – App and feature restrictions
  • com.apple.security.pkcs1 – Certificate (PKCS#1) payload
  • com.apple.security.pkcs12 – Identity certificate (PKCS#12) payload
  • com.apple.security.scep – SCEP certificate enrolment
  • com.apple.mail.managed – Mail account configuration
  • com.apple.eas.account – Exchange ActiveSync account
  • com.apple.MCX – Managed Client (macOS) preferences
  • com.apple.MCX.FileVault2 – FileVault 2 disk encryption
  • com.apple.dock – macOS Dock configuration
  • com.apple.screensaver – Screensaver configuration
  • com.apple.loginwindow – macOS login window configuration
  • com.apple.systempolicy.managed – Gatekeeper / system policy
  • com.apple.systempreferences – System Preferences pane restrictions
  • com.apple.SoftwareUpdate – Software update behaviour
  • com.apple.TCC.configuration-profile-policy – Privacy Preferences Policy Control (PPPC)
  • com.apple.notificationsettings – Per-app notification settings
  • com.apple.webcontent-filter – Web content filter
  • com.apple.dnsSettings.managed – DNS settings (DoH / DoT)
  • com.apple.relay.managed – Network relay configuration
  • com.apple.extensiblesso – Extensible Single Sign-On
  • com.apple.configuration.passcode.settings – DDM: passcode policy
  • com.apple.configuration.softwareupdate.enforcement.specific – DDM: enforced software update
  • com.apple.configuration.services.configuration-files – DDM: service configuration files
  • com.apple.configuration.management.status-subscriptions – DDM: status subscriptions
  • com.apple.activation.simple – DDM: simple activation predicate
  • com.apple.management.organization-info – DDM: organization information