<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=1732033&amp;fmt=gif">
Skip to content
All posts

Solution Highlight: ISEC7 Mobile Exchange Delegate (MED)

Editor's note, October 2026: This article was first published in September 2020. ISEC7 Mobile Exchange Delegate (MED) has since been succeeded by ISEC7 MAIL, which carries delegate, shared and functional mailboxes, S/MIME and UEM container support forward and adds options such as S/MIME certificates on a YubiKey and a Graph-based connection to Exchange Online. Several vendor names below have changed since 2020: MobileIron is now part of Ivanti, VMware Workspace ONE is now Omnissa Workspace ONE, and Office 365 is now Microsoft 365.

As we continue to work independently in this COVID-19 paradigm, collaboration is paramount. However, we need to ensure that we can collaborate without compromising privacy or security.

Take a simple example of collaboration like delegated access. It is nothing new and is used in many scenarios, typically by assistants who access their manager's mailbox to send and receive email and calendar invitations on their behalf. Another example is a shared mailbox, used and monitored by a support team to receive notifications and requests.

Even with those common tools in place, collaboration can prove challenging for the people who implement and maintain it in large corporate environments, both technically and practically.

Collaboration is easy and well proven in desktop apps such as Microsoft Office, but things get complicated in the mobile world, because mobile apps behave quite differently when it comes to accessing and sharing data or managing permissions. Even more complications arise when app containerization or a different operating system is added to the equation.

The solution

ISEC7 Mobile Exchange Delegate (MED) is a fully functional email and personal information management (PIM) client that allows delegated and shared access to Exchange email, calendar, contacts, tasks, notes and public folders.

With ISEC7 MED, employees can access the information available to them in Exchange for collaboration. ISEC7 MED uses the interface Microsoft Exchange already provides to mobile devices and requires minimal configuration changes to the existing Exchange installation.

ISEC7 Mobile Exchange Delegate: top 7 features

  1. Delegated access: access a delegated account's inbox, calendar, tasks, notes and public folders without ever having to share a password. Delegated access can be customized by access and read/write privileges.
  2. Email and email classification: ISEC7 MED provides secure mail management that lets users send, receive and enforce encrypted and signed email (S/MIME). Users can delegate access to email accounts, set up functional email accounts and use multiple email domains, while account owners keep control of the mailbox. MED also supports customizable email classifications such as "privileged", "confidential", "secret", "private" or "business-relevant". In more complex cases, classifications may be hierarchical or relevant only to some people in the organization.
  3. Certificate-based authentication: MED supports certificate-based authentication (CBA) through Modern Authentication and Kerberos. With CBA, no additional hardware is needed, because certificates are stored locally on the device.
  4. Calendar: apart from creating, changing and scheduling one-time or recurring appointments, MED lets you delegate and share calendar access. The MED Smart Scheduler adds contextual information such as overlapping and back-to-back meetings.
  5. Contacts: send messages to contacts from your own address book or the MED address book. Share access to contacts, including the right to edit and delete them, and see all activities associated with a contact.
  6. Tasks and notes: create tasks and notes, delegate the right to create tasks for others, and view, edit and delete existing tasks and notes.
  7. Supported environments and container solutions: Microsoft Exchange Server on premises, Microsoft Exchange Online (Office 365, now Microsoft 365), and iOS and Android devices. Supported container solutions were Microsoft Intune, BlackBerry Dynamics, MobileIron AppConnect (now Ivanti AppConnect), VMware Workspace ONE (now Omnissa Workspace ONE) and Citrix Endpoint Management.

What happened next

All of these capabilities live on in ISEC7 MAIL, available for iOS and Android. Classification is now handled by the separately licensed ISEC7 CLASSIFY, and ISEC7 MAIL supports Hypergate as a sign-in method, which we describe in Solution Highlight: Hypergate. Why classification and data loss protection belong together is the topic of Demystifying Security: Data Loss Protection, and the platform question behind it is covered in Cloud Solutions: Microsoft 365 vs. Google Workspace.

Want delegate mailboxes and S/MIME on your users' phones today? Learn more about ISEC7 MAIL and our endpoint productivity services, or contact us with any questions.