Apps
Apple devices
Add your mailboxes to Mail, Calendar and Contacts on iPhone, iPad and Mac as an Exchange account.
Your mailboxes can be added to the built-in apps on iPhone, iPad and Mac as an Exchange account. iPhone and iPad connect with Exchange ActiveSync, Mac with Exchange Web Services, both at sync.dev.gov.vin.
Mail, Calendar and Contacts work on iPhone, iPad and Mac (see Calendar and Contacts on Mac). Reminders and Notes aren't synced on any device, so turn them off for the account.
Set up with a profile
On the device, open your account page at id.dev.gov.vin and go to Apple devices:
- Choose the mailbox.
- Keep Sign in with your account selected.
- Select Add to iPhone or iPad or Add to Mac, then install the downloaded profile: on iPhone and iPad in Settings → Profile Downloaded, on Mac in System Settings → General → Device Management (or Profiles).
- The device opens a sign-in sheet. Sign in with a passkey or your password (or approve from another device), then Allow access to the mailbox.
Mail, Calendar and Contacts then sign in with tokens from your account; the profile contains no password, so it's safe to keep or share. The device appears under Apple devices → Signed-in devices.
Profiles are signed when the platform has a signing certificate set up, so the device shows them as verified; otherwise they install as unverified. Installing a profile for the same mailbox again replaces the earlier one. Removing the profile removes the account.
With an app password instead
If the sign-in sheet doesn't work on a device, choose Use an app password instead. Keep Include a new app password selected to put a new password, named after the profile, inside it; without it, the device asks for an app password when you install. These profiles contain the password, so treat them like one.
Approve from another device
Sign-in sheets on some devices can't use passkeys. Select Approve from a signed-in device in the sheet: it shows a code. On any device where you're signed in (or in Safari on the same iPhone or iPad, with Open in Safari), open id.dev.gov.vin/approve, enter the code, check the device and time, and approve with a passkey or your password. The sheet continues on its own.
Codes work once and expire after 5 minutes. When the sheet was opened for one of your mailboxes, your account page shows that a sign-in is waiting, without the code: only approve a code you can see on your own device.
Signed-in devices
Apple devices → Signed-in devices lists each device that signed in with a profile, with its mailbox, when it signed in and when it was last used. Sign out stops it within a minute. Devices stay signed in while they keep syncing; one unused for 90 days must sign in again. Leaving a mailbox or its organization signs its devices out of it.
App passwords
App passwords are for devices set up by hand or with an app password profile, never your account password. Create one per device under Apple devices → App passwords:
- Name it after the device.
- Choose a mailbox, or All my mailboxes (including ones you're added to later).
- Optionally set an expiry in days. Empty or
0means it never expires.
The password is shown once, as four groups of four letters. Case, spaces and dashes don't matter when you type it. The list shows when each password was last used. Revoke signs every device using it out within a minute.
An app password opens a mailbox only while you're a member of it. When an admin removes you from a mailbox, or you leave the organization, its devices stop syncing.
Set up by hand
When you add an account by hand, Apple devices offer a sign-in sheet only for Microsoft 365, so use an app password. Add an Exchange account (on Mac: Microsoft Exchange in Internet Accounts) with:
| Field | Value |
|---|---|
The mailbox address, e.g. support@example.com | |
| Server | sync.dev.gov.vin |
| User name | The mailbox address |
| Password | An app password |
Devices that find the server on their own (below) only ask for the email address and password.
If a device keeps asking for the account's password, it has the wrong one: enter an app password, not your account password.
Automatic discovery
Devices look up a domain's Exchange server with Autodiscover. For your mail domains, Mail lists an optional DNS record under Settings → Domains → DNS records:
| Type | Name | Value |
|---|---|---|
SRV | _autodiscover._tcp | 0 0 443 sync.dev.gov.vin |
With it, entering the address and app password is enough. Without it, use a profile or enter the server by hand. Copy all and Download zone file include it.
Mail on iPhone and iPad
Mail shows the mailbox's folders: Inbox, Drafts, Sent Items, Deleted Items, Junk Email and Archive. You can read messages and attachments, send, reply and forward from the mailbox address or its aliases, flag, mark read or unread, move between folders, delete, search the mailbox, and look up your organization's mailboxes when addressing a message.
- Deleting moves a message to Deleted Items; deleting it there removes it for good, as does emptying Deleted Items.
- Moving or deleting a message moves its whole conversation, as in Mail on the web. Sent messages stay in Sent Items when their conversation moves.
- Labels are categories on the device. Folders can't be created, renamed or removed from the device.
- Mail Days to Sync in the account's settings sets how far back the device keeps mail.
- The account asks for no device passcode or encryption. Automatic replies can't be set from the device.
Calendars and contacts on iPhone and iPad
The mailbox's calendars and address books (the same ones as Calendar and Contacts in Mail) appear in the Calendar and Contacts apps. Changes on the device and on the web reach each other at the next fetch.
- Events: create, change and delete events, repeating ones included, with their own changes to single occurrences. Times keep their time zone, so a 9:00 meeting stays at 9:00 across daylight saving.
- Invitations: invitations sent to the mailbox appear in Calendar; accepting, tentatively accepting or declining answers the organizer. Inviting people to an event you create on the device emails them from the mailbox, under your organization's mail limits.
- Calendar Days to Sync in the account's settings sets how far back events sync; upcoming events always do.
- Contacts: names, company, emails, phone numbers, addresses, birthdays, notes and photos. ActiveSync has room for three emails, two work and two home numbers and one address of each kind per contact; anything beyond that stays on the server and isn't lost when you edit the contact on the device.
Mail on Mac
Mail on Mac uses everything in your mailbox:
- Mailboxes: Inbox, Drafts, Sent Items, Deleted Items, Junk Email and Archive. Labels show as categories, not mailboxes. New mailboxes can't be created from Mail.
- Reading: messages with their attachments, read state and flags, kept in step with the web app and your other devices.
- Sending: new messages, replies and forwards are sent by your organization's mail service and filed in Sent Items, under the same rules and limits as the web app. You can send as the mailbox address or one of its aliases.
- Drafts: saved to Drafts with their recipients, subject and text. Attachments on a draft stay on the Mac until you send it.
- Organizing: mark read or unread, flag, move between mailboxes, mark as junk, delete, and erase Deleted Items or Junk Email.
- Search: searching in Mail also searches the server (subject, people and text).
- Addresses: typing a name finds the mailboxes and aliases in your organization.
Moving or deleting a message moves its whole conversation, as in the web app. Copying messages within the account, and adding messages from another account into it, isn't available. Automatic replies (out of office) aren't available.
The newest 5,000 messages of each mailbox sync to the Mac.
Calendar and Contacts on Mac
Calendar and Contacts on Mac use the mailbox's calendars and address books, in step with the web app:
- Calendars: every calendar of the mailbox, with events, repeating events (and occurrences you changed or deleted), all-day events, time zones, alerts, locations and notes. Create, change, move between calendars and delete events on the Mac.
- Invitations: adding invitees to an event emails them invitations from the mailbox address; changing or deleting a meeting you organize emails them the update or cancellation, unless you choose not to send it. Answering an invitation (Accept, Maybe, Decline) emails the organizer, as in the web app.
- Availability: when you add invitees, Calendar shows when you and people in your organization are busy. Other people's events show as busy times only, never their titles.
- Contacts: every address book of the mailbox, with names, company and job title, up to three email addresses, phone numbers, home, work and other addresses, a web page, birthday, anniversary, notes and photo.
Calendars and address books themselves are created, renamed and removed in the web app, not on the Mac. Exchange gives each contact fixed slots: three email addresses, one address of each kind, and named phone numbers (one mobile, two work, two home, …). Numbers past those slots are kept and still show in the web app, but not on the Mac.
Fetching
Push is off: devices fetch new mail, events and contacts on their own schedule. On Mac, set how often in Mail → Settings → General → Check for new messages and Calendar → Settings → Accounts → Refresh Calendars. On iPhone and iPad, set it in Settings → Mail → Accounts → Fetch New Data (every 15 minutes is the shortest). Opening Mail fetches right away.
Devices
Apple devices → Devices lists the devices that synced, with their mailboxes and last sync.
- Remove account (iPhone and iPad): the next time the device syncs, it deletes this account's mail, calendars and contacts. Nothing else on the device is touched. The device shows Removing account until it confirms, then Account removed; until then you can Cancel removal. Devices too old to remove only an account (before iOS supports ActiveSync 16.1) stop syncing instead; they're never erased.
- Forget clears a device and its sync state, so its next sync starts over. To keep a device out, sign it out or revoke its app password.
Signing devices in and out, approvals from another device, creating and revoking app passwords, their first use, removing accounts from devices and forgetting devices are recorded in the audit log.
Limits
- 50 signed-in devices and 50 app passwords per person.
- 10 wrong passwords for an address from one network in 15 minutes, or 50 from anywhere, pause sign-ins for that address until the 15 minutes end.
- Messages follow your organization's mail limits.