SSL.comの設定方法 S/MIME iOSおよびAndroid版Microsoft Outlook用の証明書

SSL.com を設定 S/MIME Microsoft Intuneを使用してiOSおよびAndroid版Microsoft Outlook用の証明書を作成し、デジタル署名とエンドツーエンド暗号化でモバイルメールを保護します。

Secure email is essential for protecting sensitive business communications. S/MIME (Secure/Multipurpose Internet Mail Extensions) enables users to digitally sign messages to verify sender identity and encrypt email to prevent unauthorized access.

Organizations using Microsoft Exchange Online and Microsoft Outlook for iOS or Android can deploy SSL.com S/MIME certificates to provide end-to-end email security across mobile devices. Depending on your environment, certificates can be distributed manually or automatically using Microsoft Intune.

This guide explains the prerequisites, deployment options, and configuration steps required to use SSL.com S/MIME certificates with Microsoft Outlook for iOS and Android.

あなたが始める前に

導入前に S/MIME certificates to mobile devices, ensure the following requirements are met:

  • SSL.com S/MIME certificate has been issued for each user.
  • Microsoft Exchange Online has been configured to support S/MIME.
  • Exchange Online is configured with a virtual certificate collection.
  • Certificate Revocation Lists (CRLs) are publicly accessible.
  • Trusted root and intermediate CA certificates are available in Exchange Online’s virtual certificate collection.
  • Mobile devices are enrolled in Microsoft Intune if using automated deployment.

For Exchange Online configuration requirements, refer to Microsoftのドキュメント 設定用 S/MIME in Exchange Online.

How Outlook Validates S/MIME 証明書

Before Outlook enables signing or encryption, Exchange Online validates the certificate chain by:

  • Verifying each certificate in the chain
  • Confirming the presence of a trusted root certificate
  • Checking the certificate’s revocation status

Additionally, Outlook for iOS and Android compares the user’s primary SMTP email address with the email address contained in the certificate’s Subject or Subject Alternative Name (SAN).

If these values do not match exactly, Outlook will not make the certificate available for signing or encrypting email.

Choose a Certificate Distribution Method

Microsoft Outlook supports two methods for deploying S/MIME 証明書。

証明書の手動配布

Manual installation is appropriate for small organizations or individual users.

The user exports their personal certificate as a password-protected PFX file and sends it to themselves using Outlook. Opening the attachment from Outlook on iOS or Android automatically begins certificate installation.

For instructions on exporting a certificate, see this Microsoft ガイド

Although simple, manual distribution requires each user to install and manage their own certificate.

Automated Certificate Distribution with Microsoft Intune

For larger organizations, Microsoft recommends automated certificate deployment through Microsoft Intune.

Automated deployment simplifies certificate lifecycle management, reduces administrative overhead, and ensures users always receive the correct signing and encryption certificates.

iOS Architecture Considerations

On iOS, certificates used by Outlook must reside in Microsoft’s publisher keychain rather than the system keychain.

Because Apple restricts third-party applications from accessing certificates stored in the system keychain, Outlook for iOS can only use certificates delivered through Microsoft-managed applications such as Company Portal.

Android アーキテクチャ

Outlook for Android supports automated certificate delivery through Microsoft Intune across multiple enrollment models, including:

  • Android エンタープライズ ワークプロファイル
  • Fully Managed Android Enterprise
  • Device Administrator (where supported)

Prerequisites for Automated Deployment

Before deploying certificates through Intune, complete the following tasks.

Deploy Trusted Root Certificates

Deploy all required trusted root and intermediate certificates. For more details, refer to this guide: Trusted root certificate profiles for Microsoft Intune

This allows Outlook to establish a complete chain of trust when validating user certificates.

Import User Encryption Certificates

Import users’ encryption certificates into Microsoft Intune using PKCS imported certificates. For more details, refer to this guide: インポートされた PKCS 証明書を Intune で構成して使用する

These certificates will be distributed automatically to enrolled devices.

Install the Microsoft Intune PFX Certificate Connector

Install and configure the Microsoft Intune PFX Certificate Connector. For more details, refer to this guide: Microsoft Intune 用の PFX Certificate Connector をダウンロード、インストール、構成する

The connector securely delivers user certificates from your PKI environment to managed devices.

Enroll User Devices

Ensure all target iOS and Android devices are enrolled in Microsoft Intune before assigning certificate profiles or Outlook configuration policies.

Configure Outlook for Android

To configure Outlook on Android:

  1. Sign in to Microsoft Intune Admin Center.
  2. Create and assign either a SCEP or PKCS certificate profile.
  3. MFAデバイスに移動する Apps > App configuration policies.
  4. 選択 追加 > 管理対象デバイス.
  5. 選択してください。
    • プラットフォーム: Androidエンタープライズ
    • プロファイルタイプ: すべてのプロファイル タイプ
  6. 選択 Microsoft Outlookの as the targeted application.
  7. 構成設定、選択する 構成デザイナーを使用する.
  8. 拡大する S/MIME のセクションから無料でダウンロードできます。
  9. 設定:
    • 有効にする S/MIME
    • Encrypt all email
    • Sign all email
    • User modification permissions
  10. Assign the policy to the appropriate Microsoft Entra ID user groups.

After policy deployment, Intune automatically provisions certificates to enrolled Android devices.

Configure Outlook for iOS

Follow these steps to configure Outlook for iOS to use SSL.com S/MIME 証明書。

  1. Sign in to Microsoft Intune Admin Center.
  2. MFAデバイスに移動する Apps > App configuration policies.
  3. 選択 追加 > 管理対象デバイス.
  4. Enter a policy name and optional description.
  5. 選択 iOS / iPadOS プラットフォームとして。
  6. 選択する Microsoft Outlookの as the targeted application.
  7. 店は開いています 構成設定.
  8. 拡大する S/MIME のセクションから無料でダウンロードできます。

Configure the following options as appropriate:

  • 有効にする S/MIME
  • Encrypt all email
  • Sign all email
  • Allow or prevent users from changing these settings
  • Configure an LDAP URL if recipient certificate lookup is required
  • 有効にする 配備します S/MIME Intune からの証明書

Configure Signing Certificates

Choose one of the following certificate profile types:

SCEP

Creates a unique certificate for each user and device. For more details, refer to this guide: Create and assign SCEP certificate profiles in Intune

PKCS インポートされた証明書

Uses administrator-imported user certificates that can be distributed across multiple enrolled devices. For more details, refer to this guide: Configure and use PKCS certificates with Intune

派生資格情報

Uses an existing credential retrieved through Intune’s derived credential workflow.

Configure Encryption Certificates

次のオプションのいずれかを選択します。

PKCS インポートされた証明書

Distributes imported encryption certificates automatically to enrolled devices.

派生資格情報

Uses an existing device certificate obtained through the Intune derived credential workflow.

Configure User Notifications

When certificates become available, Intune can notify users using one of two methods.

ポータルサイト

Users receive a push notification directing them to the Company Portal application, where certificate retrieval begins.

メールアドレス

Users receive an email instructing them to open the Company Portal and retrieve their S/MIME 証明書。

On iOS, users must complete certificate retrieval through the Company Portal before Outlook can use the certificate for signing or encryption.

有効にする S/MIME Outlookで

After certificates have been installed, users must manually enable S/MIME within the Outlook mobile application.

有効にする S/MIME:

  1. MicrosoftOutlookを開きます。
  2. 店は開いています 設定.
  3. Select the appropriate email account.
  4. MFAデバイスに移動する セキュリティ.
  5. オンにする S/MIME.

Once enabled, users can digitally sign or encrypt email messages directly from Outlook.

Optional: Configure LDAP for Certificate Lookup

Organizations may configure LDAP (Lightweight Directory Access Protocol) to simplify certificate discovery.

LDAP enables Outlook and other applications to locate recipient certificates automatically, allowing users to encrypt email without manually importing recipient certificates.

Benefits of LDAP integration include:

  • 証明書の一元管理
  • Simplified recipient certificate discovery
  • Improved certificate validation
  • Easier enterprise-wide S/MIME 展開

For instructions, see the SSL.com guide:

LDAP Integration with SSL.com S/MIME 証明書

結論

Deploying SSL.com S/MIME certificates with Microsoft Outlook on iOS and Android helps organizations protect sensitive communications through digital signatures and end-to-end email encryption.

Whether certificates are distributed manually for small deployments or automatically through Microsoft Intune for enterprise environments, proper configuration ensures users can securely send authenticated and encrypted email while maintaining compliance with organizational security policies. Automated deployment also reduces administrative effort, simplifies certificate lifecycle management, and provides a consistent user experience across managed mobile devices.

Twitter
Facebook
LinkedIn
Reddit
メールアドレス

常に最新情報を入手して安全を確保

SSL.com サイバーセキュリティの世界的リーダーであり、 PKI そしてデジタル証明書。サインアップして、最新の業界ニュース、ヒント、製品のお知らせを受け取ります。 SSL.com.

SSL.com

フィードバックをお待ちしております

アンケートにご協力いただき、最近のご購入についてのご意見をお聞かせください。

プライバシーの概要
SSL.com

このWebサイトではCookieを使用しているため、可能な限り最高のユーザーエクスペリエンスを提供できます。 Cookie情報はブラウザーに保存され、Webサイトに戻ったときにユーザーを認識したり、Webサイトのどのセクションが最も興味深く有用であるかをチームが理解するのに役立ちます。

詳細については、 クッキーとプライバシーステートメント.

サードパーティのCookie

このウェブサイトは Google Analytics 統計カウンター(&S) サイトへの訪問者数や最も人気のあるページなどの匿名情報を収集するため。

これらのCookieを有効にしておくと、ウェブサイトの改善に役立ちます。

詳細を表示