Microsoft 365 Mailbox Protection Policy

To protect organizational email data on mobile devices, certain departments have protection policies ensuring WVU mailboxes are only accessible through the Outlook app or Outlook Web Access (OWA). The following departments and colleges are covered by these policies:

  • Information Technology Services (ITS)

  • Student Financial Services

  • Payroll

  • IT staff for other WVU departments and colleges

  • Internal Audit

  • Athletics Compliance

  • Institutional Data Analytics

  • All users who have access to GLBA data in Banner

To access WVU email on your personal phone, you will have to use the Outlook Mobile application on iOS or Android, install an authenticator app, and set up a PIN and/or biometric identifier. You will be prompted to enter the PIN or biometric identifier after 15 minutes of inactivity.

The authenticator app itself is a mobile app management tool and ITS will in no way manage or have any access to data on your device. This only affects Outlook by ensuring that University email and calendar data is kept separate from other personal email/calendar apps and unauthorized access. A broader rollout is planned for all administrative departments that handle Sensitive Data in the near future.  

Note: WVU Microsoft 365 email and calendars cannot be accessed in the native mail/calendar apps after these policies are applied to those in the program. Use the Outlook app or OWA on mobile devices to view email and calendars. This method is the least intrusive option for protecting University data on personal mobile devices. 

Setting up Outlook

View the following articles for instructions on how to set up Outlook and the required authenticator app: 

  

You do not need to uninstall Outlook if it is already installed on your personal phone. If you have any difficulties installing the authenticator or receive an error message, contact the ITS Service Desk.

Policies

Below is a summary of the policy settings ITS is enforcing: 

  • Numeric 4-digit minimum PIN is required to access Outlook

  • Simple PINs (1111, 1234, etc) are blocked

  • Biometrics may be used for access instead of PIN (PIN is backup method and still required to be set)

  • App will prompt for access (PIN or biometrics) after 15 minutes of app inactivity

  • Backing up WVU data to iOS or Android backup services is blocked.

  • WVU data on the phone is encrypted

  • Jailbroken/rooted devices are blocked

  • 5 incorrect PIN attempts will require you to sign into your account again and set a new PIN

  • Access to email/calendar data is blocked after 14 continuous days of being offline: access to data is restored as soon as connection to the Internet is restored

  • WVU email/calendar data is removed from the device after 90 continuous days of being offline.

Troubleshooting

The user experience may vary slightly depending on your Android device. The instructions for Android were developed with the most common experience in mind.

If you have any issues with the authenticator app not working, try uninstalling both the authenticator app and Outlook and begin the process again. Both Android and iOS instructions recommend installing the Outlook app first. 

Users who only use Microsoft Teams on their phones and are enrolled in this program are still required to install the authenticator app. 

If you still need assistance setting this up, contact the ITS Service Desk

 

 

Related content

Microsoft 365 Mobile Data Protection
Microsoft 365 Mobile Data Protection
More like this
Microsoft 365 Protection FAQ
Microsoft 365 Protection FAQ
More like this
Shared User Login FAQ
Shared User Login FAQ
Read with this
Setting Up Outlook on iOS - Microsoft 365 Mailbox Protection
Setting Up Outlook on iOS - Microsoft 365 Mailbox Protection
More like this
Update Your Personal Information
Update Your Personal Information
Read with this
Setting Up Outlook on Android - Microsoft 365 Mailbox Protection
Setting Up Outlook on Android - Microsoft 365 Mailbox Protection
More like this