VMware Boxer Technical Whitepaper
Table of Contents Introduction... 3 Consumer-Simple Mobile Productivity... 3 Features & Benefits...4 Optimized for Mobile Micro-Moments...6 Enterprise Security... 8 Solution Architecture...9 Secure Email Gateway (SEG)... 10 Email Notification Service (ENS)... 10 Console and Self-Service... 10 Empowering IT with a Future-Proof Platform... 11 Features & Benefits...11 Summary...12 VMware Boxer Technical Whitepaper / 2
Introduction The VMware Workspace ONE apps suite empowers mobile productivity by engaging business apps to solve for mobile micro-moments and drive digital transformation. As part of the Workspace ONE suite of apps, VMware Boxer combines consumer simplicity with enterprise security. The app provides frictionless access to enterprise email, calendar and contacts across both corporate-owned and employee-owned devices. The containerization of business data from personal data enables IT organizations to exceed their enterprise security, compliance, data leakage prevention (DLP) and user privacy requirements. Consumer-Simple Mobile Productivity Millions of users worldwide choose to use Boxer everyday. Covered in the press over 500 times, including Time Magazine, The Wall Street Journal, Fast Company and others, Boxer has been repeatedly touted as the best email client on both ios and Android. Highly praised for its innovative user experience, Boxer has won many business excellence and user experience awards. Boxer has proven its maturity over the course of the last 3 years and won the hearts, minds and swipes of users around the world. With Boxer s fluid, clean-cut interface, email management becomes much easier, turning from a chore into a fast and even enjoyable experience. - Yahoo News [Boxer s] approach is to just keep on innovating - Forbes Boxer manages to combine a lot of the best features of other apps into one single email client - Lifehacker VMware Boxer Technical Whitepaper / 3
Features & Benefits Boxer allows users to personalize the app to meet their needs with features like custom swipe gestures, contact avatars, custom smart folders, and account color preferences. The all-in-one email, calendar and contacts app provides an intuitive user experience following native OS design standards. At the core of an email app, users expect fast email sync and notifications. Boxer delivers reliable sync with real-time email notifications and calendar reminders to stay on top of your inbox. Feature Automatic Sync Description Two-way automatic synchronization of email, calendar and contacts, including sub-folders Inline Editing Efficiently collaborate via email with inline edits during email reply or forward Email Triage Delete, flag or mark emails as read/unread with simple swipe or bulk actions Smart Folders Use the default unread, flagged or to-do smart folders or create custom smart folders from multiple accounts Predictive Move Easily file emails in the right folders with predictive move suggestions based on analytics Conversation Threads Schedule Meetings Efficiently manage Out your of Box email with messages Device organized in conversation Application threads Experience Setting Level Enrollment on Settings > Accounts Enrollment via Initial Power ON Schedule, change or cancel one-time or recurring events and appointments Microsoft App Meeting Reminders Display calendar event reminder notification with user preference for alert time Send Availability Share availability by simply selecting available timeslots on the calendar Modern Calendar Check your availability Workplace at a glance with the busy meter in the modern month view and use simple Enrollment toggle to switch between day view and agenda view Manage Attachments View attachments with a built-in viewer and add attachments by picking files from other document providers VMware Boxer Technical Whitepaper / 4
Feature Personalized Mailbox Description Personalized mailbox experience with contact avatars, custom swipe gestures, and initial view preference Multiple Accounts Support Configure multiple accounts with the ability to customize colors for calendar events in different accounts Quick Reply Tap to respond with personalized reply templates Caller ID Export basic contact information to show caller ID of a contact Native Contacts Show an aggregated contacts view within Boxer and allow users to mark contacts as favorites Native Calendar Allow users to balance work and personal life with a read-only view of the native calendar within Boxer Email Search Filter emails on the device and search on server Contact Lookup Search on the device or lookup contact information in the Global Address List (GAL) Rich Compose Compose emails in rich text, such as bold, italics and underline Secure Browser Simply open intranet websites and web apps links in the secure browser Create Invite From Email Quickly gain consensus by creating an invite from an email Table 1: Boxer high-level feature summary VMware Boxer Technical Whitepaper / 5
Optimized for Mobile Micro-Moments Boxer is designed to empower user productivity during mobile micro-moments. Let s look at a few examples. Users can quickly send pre-configured replies to emails when in a rush: Customize quick actions in settings Reply to an email with a quick action Simply tap to choose reply And send! Figure 1: Quick Reply Mobile Micro-Moment Users can send their calendar availability with a few simple taps without invoking the keyboard or waiting to get back to their desk. Reply on-the-go with quick actions Tap to see available times Choose best times Send availability Figure 2: Send Availability Mobile Micro-Moment VMware Boxer Technical Whitepaper / 6
Based on usability studies, most users triage emails by either filing, piling or purging their emails. Filers aspire for a zero-inbox goal and neatly organize their emails into folders; pilers use unread emails to determine actionable items and purgers delete emails if they are no longer actionable. The Boxer app is built to cater to the user s style by providing a faster way to triage emails on their mobile device than their laptop or desktop. Unread custom box for piler Predictive move to smart folder for filer Swipe gestures for purger Figure 3: Email Triage Mobile Micro-Moment VMware Boxer Technical Whitepaper / 7
Enterprise Security As part of the Workspace ONE productivity apps suite, Boxer ensures end-to-end encryption of data at-rest and in-transit to exceed enterprise security and compliance standards. IT administrators can trigger manual or automatic compliance actions to wipe enterprise data based on password policies, jailbreak/root detection, device compatibility, OS compatibility, and many other policies. IT organizations can protect enterprise data with control points at the identity, data, app, device and/or network level to meet the needs of all corporate-owned and BYOD use cases. With containerized apps, intelligent access and adaptive management, IT can tune the perfect balance between security, usability and privacy to match their security and risk posture. Policy Authentication and Password Policies Details IT can enforce app level password for Boxer with policies to enforce minimum length, complex password, timeout, age, history and failed attempts. Remote Wipe IT can meet compliance objectives by remote wiping business data from the device. For corporate-owned devices, IT can also trigger full device wipe. The wipe action can be triggered manually or IT can configure it to trigger automatically as a result of a compliance violation. Jailbreak and Root Detection IT can maintain peace of mind with compromised device detection that prevents access to business apps from jailbroken or rooted devices. Intelligent Access Attachment Handling Workspace ONE integration provides user and device attestation for intelligent access to corporate data. The user attestation is based on identity and access management integration, while the device attestation is based on approved device model, OS, EAS device type/id, etc. Attachment policies allow IT to ensure that users can be productive with documents on their mobile devices but do not cause data leakage or compliance violations. Depending on the security policies, IT can enable or disable cloud file connectors. Prevent Copy/Paste Copy/paste policies allow IT to ensure that sensitive data stays within the business apps. Open Links In Secure Browser IT can enable or disable opening links in native browser by enforcing shared links to remain within a secure browsing environment. Advanced DLP There are many other DLP controls in the Boxer product, including the ability to allow user to sync contacts to native, block third-party keyboards, block native print, prevent app data to itunes, etc. Table 2: High-level security, compliance & DLP policies VMware Boxer Technical Whitepaper / 8
Solution Architecture The following diagram depicts the high-level architecture of Boxer deployed with the VMware AirWatch Enterprise Mobility Management (EMM) platform. The client app implements Exchange ActiveSync (EAS) and IMAP protocols to connect to various email systems, including Exchange, Outlook, Gmail, Yahoo and icloud Email. Figure 4: High-level architecture for on-premise Boxer deployment across corporate owned and BYO devices VMware Boxer Technical Whitepaper / 9
Secure Email Gateway (SEG) The optional secure email gateway (SEG) Proxy server can provide additional security by only allowing traffic from approved devices to the corporate email server. Also, email attachments and hyperlinks can be encrypted such that they can be only be opened via VMware AirWatch Content Locker and VMware AirWatch Browser respectively, thus protecting sensitive information. Email Notification Service (ENS) With the email notification service (ENS), users receive real time email notification on their ios devices through Apple Push Notification Service (APNS). The service also helps to improve battery performance. IT can configure policies to mask the actual content of the notifications for security and DLP. Console and Self-Service IT administrators can manage their entire mobile deployment from the console. While the diagram depicts the console deployed on-premise, we provide deployment flexibility to host it in the SaaS environment. End users can access the self-service portal to alleviate IT requests. VMware Boxer Technical Whitepaper / 10
Empowering IT with a Future-Proof Platform VMware Workspace ONE is the only platform that is able to seamlessly bring together technologies of identity, apps and mobile to remove the friction of disparate systems. The platform is designed to seamlessly scale as your business grows and your mobile initiatives evolve. Feature Single Pane of Glass Details Manage all end points and support your entire global deployment within a single console with our multitenant architecture. Role-Based Access Easy Onboarding Flexible Deployments Delegate management across your geographies, divisions and departments with role-based access controls. Fast track your deployment to make the initial setup easy to get up and running quickly. Utilize Getting Started wizards, branded onboarding or industry templates to quickly and easily configure device policies and settings. Bulk enroll devices with solutions such as Apple Device Enrollment Program, KNOX Mobile Enrollment, Android NFC, and out-of-box enrollment for Windows 10. The same AirWatch EMM platform is available for deployments on-premise, in the multitenant shared cloud or dedicated cloud, or hybrid instances. We also work with Office 365 environments. Existing Systems AirWatch seamlessly integrates with your existing systems, such as email, content repositories, directory services, and more, to extend those services to mobile devices. Our robust API framework enables plug-and-play with your existing infrastructure investments. SIEM Integration Reporting and IT Automation System administrators can record application, device and console events to capture detailed information for system monitoring, and view logs in the console or export pre-defined reports for integration with other SIEM consoles. Configure compliance rules and automate the remediation process with the compliance engine. Over 80 pre-configured reports and modular dashboards make it easy to view deployment analytics. Self-Service Console Self-service capabilities enable end users with basic management functionality, such as reset a passcode, to alleviate IT ticket requests. Analytics and Insights Advanced analytics with industry templates provide insights for IT to discover the transformational apps by line of business or industry with average baseline policies. Ecosystem Line of business managers have access to a growing ecosystem of ISV apps and can develop custom enterprise apps on the AirWatch platform. AirWatch is a pioneer in build a strong mobile ecosystem as a founding member of Mobile Security Alliance and the AppConfig Community. Global Customers The AirWatch console, productivity app suite and self-service portal is available in 18 languages to support your global workforce, and our global services and support team backs your IT department around the world. Table 3: Features and benefits summary VMware Boxer Technical Whitepaper / 11
Summary With the rich end user feature set combined with the security policies, Boxer is designed to empower mobile productivity. The integrated suite of Workspace ONE productivity apps enables organizations to drive digital transformation. For more information about Boxer, please visit http://www.air-watch.com/solutions/ mobile-email-management/. VMware Boxer Technical Whitepaper / 12
Additional Resources For additional information, visit: www.air-watch.com/solutions/windows. To get started with a free trial of AirWatch, visit www.air-watch.com/free-trial. AirWatch Global Headquarters 1155 Perimeter Center West Suite 100 Atlanta, GA 30338 United States T: +1 404 478 7500 E: sales@air-watch.com About AirWatch AirWatch is the leader in enterprise mobility management, with a platform including industry-leading mobile device, email, application, content and browser management solutions. Acquired by VMware in February 2014, AirWatch is based in Atlanta and can be found online at www.air-watch.com.