Last updated: July 24, 2026

How to secure email attachments in iOS devices?

This guide explains how to secure e-mail attachments on iOS devices (iOS 7.0 or later) using the document viewer built into the Self Service app, which restricts attachments to in-app viewing and storage without cloud syncing. Admins distribute the Self Service app, create an Apple profile with Exchange or E-mail policies, restrict Share Data from Managed Apps to Unmanaged Apps under Security, then publish and distribute the profile to devices or groups.

Description

Corporate Emails often contain confidential organization data as attachments, which must be accessible to the users while preventing any type of unauthorized access. It is also expected that these attachments should not be accessible to other apps. In certain third-party document viewers, the documents are automatically synced with different cloud services, which may cause data breach. 

MDM allows organizations to secure email attachements by using the document viewer, built in the Self Service app (previously ME MDM app). The document viewer is an optimal way for securing documents distributed using MDM and also to secure email attachments. With the document viewer, you can secure email attachments by

  • Viewing the email attachment only through the document viewer.
  • Saving the email attachment only in the Self Service app (previously ME MDM app).
  • Restricting sharing of email attachment content.
  • Not accessing the email attachment using personal apps
  • Not backing up the email attachment on third-party cloud services.

Thus, Self Service app (previously ME MDM app) becomes the endpoint for secure document management, ensuring the data is most secure and can be accessed only by the users. Including the above features, it has also the following advantages.

  • The document viewer has all the e-mail attachments saved, ensuring easy viewing of all the organizational documents in one place.
  • Document Viewer is included as a part of the Self Service app (previously ME MDM app), ensuring no additional app is to be installed for content management.
  • MDM becomes the single point for both device management and content management, ensuring restrictions and profiles can be configured to optimally utilize the document viewer.
  • The document viewer doesn't sync with any Cloud service such as iCloud, ensuring there is no copy of the data except in the document viewer.

This is applicable only for iOS devices running iOS 7.0 or later versions.

NOTE: Know how to secure e-mail attachments using MDM in under 3 minutes, from this video.

Steps

  • Distribute Self Service app (previously ME MDM app) to iOS devices. App distribution can be automated by navigating to Enrollment -> Self Service app (previously ME MDM app)(under Apple) and select the option Automatically distribute Self Service app (previously ME MDM app) to Apple devices. You can also configure MDM app settings to install Self Service app (previously ME MDM app) silently as explained here. This will install the Self Service app (previously ME MDM app) on all managed devices along with the document viewer to secure email attachments.
  • In the MDM console, click on Device Mgmt and select Profiles.
  • Click on Create Profile and select Apple profile.
  • Create the profile with Exchange or E-mail policies to ensure the corporate email account is automatically configured on the devices.
  • To secure email attachments by allowing users to access the email attachments only using the Self Service app (previously ME MDM app), click on Restrictions and select Security.
  • Restrict the option Share data from Managed Apps to Unmanaged apps.
  • Save and publish the profile.
  • Distribute the profile to either specific devices for testing or the required Groups.

NOTE: Ensure no apps used for viewing documents have been distributed through MDM. If distributed, then the attachments can also be viewed through the distributed app as well as Self Service app (previously ME MDM app). 

Frequently asked questions

Why can't email attachments be opened using other apps on managed iOS devices?

MDM restricts the "Share data from Managed Apps to Unmanaged apps" option under Security restrictions, so attachments opened through the document viewer in the Self Service app can't be opened or shared using personal, unmanaged apps.

Does the document viewer back up email attachments to iCloud or other cloud services?

No. The document viewer built into the Self Service app doesn't sync with any cloud service such as iCloud, so there's no copy of an attachment outside the viewer.

Which iOS versions support secured email attachments through MDM?

This feature is applicable only to iOS devices running iOS 7.0 or later versions.

What needs to be configured to enable secure email attachment viewing?

Distribute the Self Service app to iOS devices, create an Apple profile with Exchange or E-mail policies, restrict "Share data from Managed Apps to Unmanaged apps" under Restrictions > Security, then publish and distribute the profile to devices or groups.