Secure email is essential for protecting sensitive business communications. S/MIME (Secure/Multipurpose Internet Mail Extensions) enables users to digitally sign messages to verify sender identity and encrypt email to prevent unauthorized access.
Organizations using Microsoft Exchange Online and Microsoft Outlook for iOS or Android can deploy SSL.com S/MIME certificates to provide end-to-end email security across mobile devices. Depending on your environment, certificates can be distributed manually or automatically using Microsoft Intune.
This guide explains the prerequisites, deployment options, and configuration steps required to use SSL.com S/MIME certificates with Microsoft Outlook for iOS and Android.
あなたが始める前に
導入前に S/MIME certificates to mobile devices, ensure the following requirements are met:
- SSL.com S/MIME certificate has been issued for each user.
- Microsoft Exchange Online has been configured to support S/MIME.
- Exchange Online is configured with a virtual certificate collection.
- Certificate Revocation Lists (CRLs) are publicly accessible.
- Trusted root and intermediate CA certificates are available in Exchange Online’s virtual certificate collection.
- Mobile devices are enrolled in Microsoft Intune if using automated deployment.
For Exchange Online configuration requirements, refer to Microsoftのドキュメント 設定用 S/MIME in Exchange Online.
How Outlook Validates S/MIME 証明書
Before Outlook enables signing or encryption, Exchange Online validates the certificate chain by:
- Verifying each certificate in the chain
- Confirming the presence of a trusted root certificate
- Checking the certificate’s revocation status
Additionally, Outlook for iOS and Android compares the user’s primary SMTP email address with the email address contained in the certificate’s Subject or Subject Alternative Name (SAN).
If these values do not match exactly, Outlook will not make the certificate available for signing or encrypting email.
Choose a Certificate Distribution Method
Microsoft Outlook supports two methods for deploying S/MIME 証明書。
証明書の手動配布
Manual installation is appropriate for small organizations or individual users.
The user exports their personal certificate as a password-protected PFX file and sends it to themselves using Outlook. Opening the attachment from Outlook on iOS or Android automatically begins certificate installation.
For instructions on exporting a certificate, see this Microsoft ガイド.
Although simple, manual distribution requires each user to install and manage their own certificate.
Automated Certificate Distribution with Microsoft Intune
For larger organizations, Microsoft recommends automated certificate deployment through Microsoft Intune.
Automated deployment simplifies certificate lifecycle management, reduces administrative overhead, and ensures users always receive the correct signing and encryption certificates.
iOS Architecture Considerations
On iOS, certificates used by Outlook must reside in Microsoft’s publisher keychain rather than the system keychain.
Because Apple restricts third-party applications from accessing certificates stored in the system keychain, Outlook for iOS can only use certificates delivered through Microsoft-managed applications such as Company Portal.
Android アーキテクチャ
Outlook for Android supports automated certificate delivery through Microsoft Intune across multiple enrollment models, including:
- Android エンタープライズ ワークプロファイル
- Fully Managed Android Enterprise
- Device Administrator (where supported)
Prerequisites for Automated Deployment
Before deploying certificates through Intune, complete the following tasks.
Deploy Trusted Root Certificates
Deploy all required trusted root and intermediate certificates. For more details, refer to this guide: Trusted root certificate profiles for Microsoft Intune
This allows Outlook to establish a complete chain of trust when validating user certificates.
Import User Encryption Certificates
Import users’ encryption certificates into Microsoft Intune using PKCS imported certificates. For more details, refer to this guide: インポートされた PKCS 証明書を Intune で構成して使用する
These certificates will be distributed automatically to enrolled devices.
Install the Microsoft Intune PFX Certificate Connector
Install and configure the Microsoft Intune PFX Certificate Connector. For more details, refer to this guide: Microsoft Intune 用の PFX Certificate Connector をダウンロード、インストール、構成する
The connector securely delivers user certificates from your PKI environment to managed devices.
Enroll User Devices
Ensure all target iOS and Android devices are enrolled in Microsoft Intune before assigning certificate profiles or Outlook configuration policies.
Configure Outlook for Android
To configure Outlook on Android:
- Sign in to Microsoft Intune Admin Center.
- Create and assign either a SCEP or PKCS certificate profile.
- MFAデバイスに移動する Apps > App configuration policies.
- 選択 追加 > 管理対象デバイス.
- 選択してください。
- プラットフォーム: Androidエンタープライズ
- プロファイルタイプ: すべてのプロファイル タイプ
- 選択 Microsoft Outlookの as the targeted application.
- 構成設定、選択する 構成デザイナーを使用する.
- 拡大する S/MIME のセクションから無料でダウンロードできます。
- 設定:
- 有効にする S/MIME
- Encrypt all email
- Sign all email
- User modification permissions
- Assign the policy to the appropriate Microsoft Entra ID user groups.
After policy deployment, Intune automatically provisions certificates to enrolled Android devices.
Configure Outlook for iOS
Follow these steps to configure Outlook for iOS to use SSL.com S/MIME 証明書。
- Sign in to Microsoft Intune Admin Center.
- MFAデバイスに移動する Apps > App configuration policies.
- 選択 追加 > 管理対象デバイス.
- Enter a policy name and optional description.
- 選択 iOS / iPadOS プラットフォームとして。
- 選択する Microsoft Outlookの as the targeted application.
- 店は開いています 構成設定.
- 拡大する S/MIME のセクションから無料でダウンロードできます。
Configure the following options as appropriate:
- 有効にする S/MIME
- Encrypt all email
- Sign all email
- Allow or prevent users from changing these settings
- Configure an LDAP URL if recipient certificate lookup is required
- 有効にする 配備します S/MIME Intune からの証明書
Configure Signing Certificates
Choose one of the following certificate profile types:
SCEP
Creates a unique certificate for each user and device. For more details, refer to this guide: Create and assign SCEP certificate profiles in Intune
PKCS インポートされた証明書
Uses administrator-imported user certificates that can be distributed across multiple enrolled devices. For more details, refer to this guide: Configure and use PKCS certificates with Intune
派生資格情報
Uses an existing credential retrieved through Intune’s derived credential workflow.
Configure Encryption Certificates
次のオプションのいずれかを選択します。
PKCS インポートされた証明書
Distributes imported encryption certificates automatically to enrolled devices.
派生資格情報
Uses an existing device certificate obtained through the Intune derived credential workflow.
Configure User Notifications
When certificates become available, Intune can notify users using one of two methods.
ポータルサイト
Users receive a push notification directing them to the Company Portal application, where certificate retrieval begins.
メールアドレス
Users receive an email instructing them to open the Company Portal and retrieve their S/MIME 証明書。
On iOS, users must complete certificate retrieval through the Company Portal before Outlook can use the certificate for signing or encryption.
有効にする S/MIME Outlookで
After certificates have been installed, users must manually enable S/MIME within the Outlook mobile application.
有効にする S/MIME:
- MicrosoftOutlookを開きます。
- 店は開いています 設定.
- Select the appropriate email account.
- MFAデバイスに移動する セキュリティ.
- オンにする S/MIME.
Once enabled, users can digitally sign or encrypt email messages directly from Outlook.
Optional: Configure LDAP for Certificate Lookup
Organizations may configure LDAP (Lightweight Directory Access Protocol) to simplify certificate discovery.
LDAP enables Outlook and other applications to locate recipient certificates automatically, allowing users to encrypt email without manually importing recipient certificates.
Benefits of LDAP integration include:
- 証明書の一元管理
- Simplified recipient certificate discovery
- Improved certificate validation
- Easier enterprise-wide S/MIME 展開
For instructions, see the SSL.com guide:
LDAP Integration with SSL.com S/MIME 証明書
結論
Deploying SSL.com S/MIME certificates with Microsoft Outlook on iOS and Android helps organizations protect sensitive communications through digital signatures and end-to-end email encryption.
Whether certificates are distributed manually for small deployments or automatically through Microsoft Intune for enterprise environments, proper configuration ensures users can securely send authenticated and encrypted email while maintaining compliance with organizational security policies. Automated deployment also reduces administrative effort, simplifies certificate lifecycle management, and provides a consistent user experience across managed mobile devices.