TECHNICAL WHITE PAPER JUNE 2017
Table of Contents Introduction 3 Consumer-Simple Mobile Productivity 3 A More Personal Email Experience for the User.... 4 Application Capabilities and Features.... 5 Optimized for Mobile Micro-Moments.... 6 Enterprise Security and User Privacy 7 Enterprise Security and DLP Features.... 8 Solution Architecture.... 9 Secure Email Gateway (SEG).... 9 Email Notification Service (ENS).... 9 Privacy Protection on BYO Devices.... 9 Console and Self-Service.... 9 Empowering IT with a Future-Proof Platform 9 Features & Benefits.... 10 Summary.... 11 TECHNICAL WHITE PAPER 2
Introduction The VMware Workspace ONE apps suite, including VMware Boxer, empowers mobile productivity by engaging business apps to solve for mobile micro-moments and drive digital transformation. Available on both ios and Android, Boxer combines consumer simplicity with enterprise security. The app provides frictionless access to enterprise email, calendar and contacts across both corporate-owned and employee-owned devices. The containerization of business data from personal data enables IT organizations to exceed their enterprise security, compliance, data leakage prevention (DLP), and user privacy requirements. Boxer seamlessly integrates with Exchange, Office 365, Outlook, Gmail, Yahoo and icloud email systems. From an IT management perspective, Boxer gives you the ability to manage Exchange and Office 365 via the console. Personal email, calendar and contact services through Gmail, Yahoo and icloud are also available for the user. Consumer-Simple Mobile Productivity Millions of users worldwide choose to use Boxer every day. Covered in the press more than 500 times, including Time Magazine, The Wall Street Journal, Fast Company and others, Boxer has been repeatedly touted as the best email client on both ios and Android. Highly praised for its innovative user experience, Boxer has won many business excellence and user experience awards. Boxer has proven its maturity over the course of the last 4 years and won the hearts, minds and swipes of users around the world. With Boxer s fluid, clean-cut interface, email management becomes much easier, turning from a chore into a fast and even enjoyable experience. Yahoo News Boxer manages to combine a lot of the best features of other apps into one single email client. Lifehacker [Boxer s] approach is to just keep on innovating. Forbes TECHNICAL WHITE PAPER 3
A More Personal Email Experience for the User Boxer enables users to personalize the app to meet their needs and unique email style. With features like pre-determined email replies, custom swipe gestures, contact avatars, custom smart folders, account color preferences and more, Boxer makes managing email more personal and efficient than ever before. Custom quick templates Custom swipe gestures Based on usability studies, most users triage emails by either filing, piling or purging their emails. Filers aspire for a zero-inbox goal and neatly organize their emails into folders; pilers use unread emails to determine actionable items, and purgers delete emails if they are no longer actionable. The Boxer app is built to cater to the user s style by providing a faster way to triage emails on their mobile device than their laptop or desktop. Unread custom box for piler Predictive move to smart folder for filer Swipe gestures for purger The all-in-one email, calendar and contacts app provides an intuitive user experience following native OS design standards. At the core of the email app, users can expect fast email sync and notifications. Boxer delivers reliable sync with real-time email notifications and calendar reminders to stay on top of your inbox. TECHNICAL WHITE PAPER 4
Application Capabilities and Features Feature Details Automatic Sync Two-way automatic synchronization of email, calendar and contacts, including sub-folders Inline Editing Efficiently collaborate via email with inline edits during email reply or forward Email Triage Delete, ag or mark emails as read/unread with simple swipe or bulk actions Smart Folders Use the default unread, flagged or to-do smart folders or create custom smart folders from multiple accounts Predictive Move Easily file emails in the right folders with predictive move suggestions based on analytics Conversation Threads Efficiently manage your email with messages organized in conversation threads x Device Application Personalized Mailbox Personalized mailbox experience with contact avatars, custom swipe gestures, and initial view preference Multiple Accounts Support Configure multiple accounts with the ability to customize colors for calendar events in different accounts Quick Reply Tap to respond with personalized reply templates Caller ID Export basic contact information to show caller ID of a contact Native Contacts Show an aggregated contact view within Boxer Native Calendar Allow users to balance work and personal life with a read and write access to the native calendar within Boxer Email Search Filter emails on the device and search on server Adaptive Management Unlock native apps integration using workspace services profile and adaptive management in VMware Workspace ONE Two-way Automatic Contact Sync Automatically sync Outlook contacts with ability to view contacts in native Contact Lookup Search on the device or lookup contact information in the Global Address List (GAL) TECHNICAL WHITE PAPER 5
Feature Details Favorite Contacts Mark contacts as your favorite External File Repositories Access files from corporate repositories such as SharePoint, One Drive for Business, Box, WebDAV, CMIs, and more Local Files Repository Save email attachments and files in a local in-app file repository Note and Attachment Workflows Integrate with third-party business apps like Box, Evernote and Google Drive to simplify attachment and note workflows Rich Compose Compose emails in rich text, such as bold, italics and underline Secure Browser Open intranet websites and web apps links in the secure browser Create Invite from Email Quickly gain consensus by creating an invite from an email Optimized for Mobile Micro-Moments Boxer is designed to empower user productivity during mobile micro-moments. Let s look at a few examples. Users can quickly send pre-configured replies to emails when in a rush: Customize quick actions in settings Reply to an email with a quick action Simply tap to choose reply And send! TECHNICAL WHITE PAPER 6
Users can send their calendar availability with a few simple taps without invoking the keyboard or waiting to get back to their desk. Reply on-the-go with quick actions Tap to see availible times Choose best times Send availibility Integrated Workflows across Apps Boxer seamlessly integrates with other VMware productivity apps to enhance mobile workflows. By reducing the need to exit the app and open another, Boxer aims to increase user productivity by decreasing time required to complete a task. Browser Content Locker Locate and attach files stored in Content Locker directly in your email Access intranet sites seamlessly and securely Enterprise Security and User Privacy As part of the Workspace ONE productivity apps suite, Boxer ensures end-to-end encryption of data at-rest and in-transit to exceed enterprise security and compliance standards. IT administrators can trigger manual or automatic compliance actions to wipe or block enterprise data based on password policies, jailbreak/ root detection, device compatibility, OS compatibility, and many other policies. IT organizations can protect enterprise data with control points at the identity, data, app, device and/or network level to meet the needs of all corporate-owned and BYOD use cases. With containerized apps, intelligent access and adaptive management, IT can tune the perfect balance between security, usability and privacy to match their security and risk posture. TECHNICAL WHITE PAPER 7
Enterprise Security and DLP Features Feature Details Authentication and Password Policies Enforce app level password for Boxer with policies to enforce minimum length, complex password, timeout, age, history and failed attempts Remote Wipe Remotely wipe business data from the device or full device wipe for corporate-owned devices; wipe action can be triggered manually or configured to trigger automatically when a compliance violation is detected Jailbreak and Root Detection Compromised device detection prevents access to business apps from jailbroken or rooted devices Intelligent Access Workspace ONE integration provides user and device attestation for intelligent access to corporate data; user attestation is based on identity and access management integration while device attestation is based on approved device model, OS, EAS device type/id, etc. App Passcode Enables IT to enforce application passcode settings within the console Attachment Handling Enables users to handle documents on their mobile device without causing data leakage or compliance violations Prevent Copy/Paste Copy/paste policies allow IT to ensure that sensitive data stays within the business apps Open Links in Secure Browser Enable or disable opening links in native browser by enforcing shared links to remain within a secure browsing environment Open Files Securely in Content Locker Access and share documents through our secure content management application Advanced DLP Advanced DLP controls include the ability to allow user to sync contacts to native, block third-party keyboards, block native print and prevent app data to itunes Integrated Identity Management Integrated solution for identity management, conditional access and multi-factor authentication S/MIME Support Send or receive signed and/or encrypted email Email Classification Enable setting classifications in the console and the compose user interface; support for built-in Exchange transport rules as well as Titus, Boldon James, and JanusNET TECHNICAL WHITE PAPER 8
Solution Architecture The following diagram depicts the high-level architecture of Boxer deployed with the VMware AirWatch Enterprise Mobility Management (EMM) platform. The client app implements Exchange ActiveSync (EAS) and IMAP protocols to connect to various email systems, including Exchange, Outlook, Gmail, Yahoo and icloud Email. Cloud Notification Service! Email Notification Service AW Console Exchange Secure Email Gateway Secure Email Gateway (SEG) The optional secure email gateway (SEG) Proxy server can provide additional security by only allowing traffic from approved devices to the corporate email server. Email attachments can also be encrypted and hyperlinks can be redirected to open in VMware Browser, thus protecting sensitive information. Email Notification Service (ENS) With the email notification service (ENS), users receive real time email notification on their ios devices through Apple Push Notification Service (APNS). The service also helps to improve battery performance. IT can configure policies to mask the actual content of the notifications for security and DLP. Privacy Protection for BYO Devices Boxer is a containerized application available on both corporate owned and employee owned or BYO devices. If employee owned, IT has the ability to enable employees to access the Boxer app without an MDM profile on the device. Containerization of the application keeps enterprise data at-rest and in-transit to exist separately, protecting the user s personal data while maintaining security of corporate information. Console and Self-Service IT administrators can manage their entire mobile deployment from the console. While the diagram depicts the console deployed on premise, we provide deployment flexibility to host it in the SaaS environment. End users can access the self-service portal to alleviate IT requests. Empowering IT with a Future-Proof Platform VMware Workspace ONE is the only platform that can seamlessly bring together technologies of identity, apps and mobile to remove the friction of disparate systems. The platform seamlessly scales as your business grows and your mobile initiatives evolve. TECHNICAL WHITE PAPER 9
Feature Feature Single Pane of Glass Manage all end points and support your entire global deployment within a single console with our multitenant architecture Role-Based Access Delegate management across your geographies, divisions and departments with role-based access controls Easy Onboarding Fast track your deployment to make the initial setup easy to get up and running quickly. Utilize Getting Started wizards, branded onboarding or industry templates to quickly and easily configure device policies and settings. Bulk enroll devices with solutions such as Apple Device Enrollment Program, KNOX Mobile Enrollment, Android NFC, and out-of-box enrollment for Windows 10. Flexible Deployments The same AirWatch Enterprise Mobility Management platform is available for deployments on-premise, in the multitenant shared cloud or dedicated cloud, or hybrid instances. We also work with Office 365 environments. IT can also set multiple email configurations set though Smart Groups. Existing Systems AirWatch seamlessly integrates with your existing systems, such as email, content repositories, directory services, and more, to extend those services to mobile devices. Our robust API framework enables plug-and-play with your existing infrastructure investments. SIEM Integration System administrators can record application, device and console events to capture detailed information for system monitoring, and view logs in the console or export pre-defined reports for integration with other SIEM consoles Reporting and IT Automation Configure compliance rules and automate the remediation process with the compliance engine. Over 80 pre-configured reports and modular dashboards make it easy to view deployment analytics. Self-Service Console Self-service capabilities enable end users with basic management functionality, such as reset a passcode, to alleviate IT ticket requests Analytics and Insights Advanced analytics with industry templates provide insights for IT to discover the transformational apps by line of business or industry with average baseline policies Ecosystem Line of business managers have access to a growing ecosystem of ISV apps and can develop custom enterprise apps on the AirWatch platform. AirWatch is a pioneer in build a strong mobile ecosystem as a founding member of Mobile Security Alliance and the AppConfig Community. Global Customers The AirWatch console, productivity app suite and self-service portal is available in 18 languages to support your global workforce, and our global services and support team backs your IT department around the world TECHNICAL WHITE PAPER 10
Summary With a rich end user feature set combined with security policies, Boxer is designed to empower mobile productivity. Boxer and the entire, integrated suite of Workspace ONE productivity apps enable organizations to drive digital transformation. For more information about Boxer, please visit http://www.air-watch.com/solutions/mobile-email-management TECHNICAL WHITE PAPER 11
VMware, Inc. 3401 Hillview Avenue Palo Alto CA 94304 USA Tel 877-486-9273 Fax 650-427-5001 www.vmware.com Copyright 2017 VMware, Inc. All rights reserved. This product is protected by U.S. and international copyright and intellectual property laws. VMware products are covered by one or more patents listed at http://www.vmware.com/go/patents. VMware is a registered trademark or trademark of VMware, Inc. and its subsidiaries in the United States and other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies. Item No: 39342-VM-WPP-BoxerWhitepaper 6/17