← Back
Intune policy to determine SMIME cert lookup priority
MC1105021 · build prod-20251231-200323
Category
planForChange
Severity
normal
Major change
False
Last modified
2025-06-27 23:25:59
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
Action by (AI)
Services
Microsoft Intune
Tags
New feature, Admin impact
Master tags
Admin, Security
Roadmap IDs

One-line summary

New Intune policy lets admins set SMIME certificate lookup order in Outlook mobile, enhancing control over certificate selection from multiple sources.

Similar updates

More like this
MC1129716 (Updated) Microsoft Outlook Mobile adds support for DLP policy tips and enforcement
(Updated) Microsoft Outlook Mobile adds support for DLP policy tips and enforcement Outlook Mobile's DLP Policy Tips & Override update adds new controls and features for Android/iOS, rollout targeting App Store submission on May 4, with DLP defaulted off via Intune control. Introduction The Outlook Mobile team is updating the release for Data.
MC1147392 Microsoft Outlook: Set up classic Outlook accounts and settings in new Outlook for Windows automatically
...k will auto-configureThis setting can also be managed via: Cloud Policy in the Microsoft 365 Apps admin center Group Policy using the latest ADMX templates Microsoft Intune using administrative templates Learn more:  Control the installation and use of new Outlook | Microsoft 365 Apps | Microsoft Learn Import settings and install add-ins.
MC1193371 How to use Microsoft Intune to update expiring Secure Boot certificates
How to use Microsoft Intune to update expiring Secure Boot certificates Admins can now use Intune to deploy, manage, and monitor Secure Boot certificate updates on Windows clients, with new settings available for streamlined management. You can now deploy, manage, and monitor Secure Boot certificate updates. This method represents an alternative.
MC1179067 Policy-based removal of pre-installed Microsoft Store apps
Policy-based removal of pre-installed Microsoft Store apps Admins can now remove select pre-installed Microsoft Store apps on Windows 11 Enterprise/Education 25H2 using a new policy, configurable via Intune or Group Policy. You’re now more in control of provisioned Microsoft Store apps than ever. Starting this month, you can remove select in-box.
MC1089318 (Updated) Microsoft Outlook for iOS/Android: Copilot shows users important emails in new priority view
(Updated) Microsoft Outlook for iOS/Android: Copilot shows users important emails in new priority view The new Copilot-powered Priority View in Outlook for iOS/Android highlights high-priority emails but requires a Microsoft 365 Copilot license; rollout is from late June to late Dec 2025. Updated February 4, 2026: This feature has been removed.
MC1093912 (Updated) Microsoft Outlook for iOS/Android: Improved Contacts with profile enrichment and duplicate management
(Updated) Microsoft Outlook for iOS/Android: Improved Contacts with profile enrichment and duplicate management Outlook Mobile for iOS/Android will unify and enrich contacts with org profiles and auto-hide duplicates, rolling out mid-July 2025 to May 2026; new features on by default, no admin controls. Updated March 16, 2026: We hav... We’re.

Details

Summary
A new Intune policy allows admins to set the priority order for SMIME certificate lookup in Outlook mobile, enhancing control and security. Rolling out on August 29, 2025, it is off by default. Configuration details and examples are provided. More information is available [here](https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/outlook-for-ios-and-android/outlook-for-ios-and-android-configuration-with-microsoft-intune#smime-settings).

Body (from Message Center)

We're introducing a new Intune policy that allows admins to define the priority order for SMIME certificate lookup in Outlook mobile. This gives organizations more control over how certificates are selected when multiple sources are available, improving flexibility and alignment with internal security practices.

[When this will happen:]

This change will begin rolling out on August 29, 2025.

[How this affects your organization:]

You're receiving this message because our reporting indicates that one or more users in your organization may be using SMIME in Outlook mobile. With this update, administrators can configure a new Intune policy to control the order in which SMIME certificates are retrieved from different sources.

This policy is off by default. If not configured, Outlook mobile will continue using the default lookup order.

[What you can do to prepare

Once the policy becomes available, you can configure it using the following key:

  • Key: com.microsoft.outlook.Mail.SMIMEEnabled.CertificatesLookupOrder
  • Type: String
  • Accepted Values:
    • 0 (Contacts)
    • 1 (GAL)
    • 2 (Device)
    • 3 (LDAP)
    • Format: "X", "X, X", "X, X, X", or "X, X, X, X"
    • Default (if not specified): "0, 1, 2, 3"
    • Example: "3, 2, 0, 1"

To learn more about configuring SMIME settings in Outlook mobile with Intune, visit: Deploying Outlook for iOS and Android app configuration settings in Exchange Online.

Raw JSON (for debugging)

Expand/collapse the full payload below.
Show/hide raw
{
  "snapshot_item": {
    "action_required_by": null,
    "ai_action_required_by": null,
    "ai_actions": [
      "Review SMIME usage in Outlook mobile",
      "Plan certificate lookup order policy",
      "Configure new Intune policy after rollout"
    ],
    "ai_master_tags": [
      "Admin",
      "Security"
    ],
    "ai_model": "gpt-4.1",
    "ai_summary": "New Intune policy lets admins set SMIME certificate lookup order in Outlook mobile, enhancing control over certificate selection from multiple sources.",
    "ai_topics": [
      "Intune",
      "Outlook"
    ],
    "category": "planForChange",
    "details_map": {
      "Summary": "A new Intune policy allows admins to set the priority order for SMIME certificate lookup in Outlook mobile, enhancing control and security. Rolling out on August 29, 2025, it is off by default. Configuration details and examples are provided. More information is available [here](https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/outlook-for-ios-and-android/outlook-for-ios-and-android-configuration-with-microsoft-intune#smime-settings)."
    },
    "id": "MC1105021",
    "importance": 2,
    "is_major_change": false,
    "last_modified": "2025-06-27T23:25:59Z",
    "ms_products": [
      "Intune"
    ],
    "platforms": null,
    "roadmap_ids": [],
    "services": [
      "Microsoft Intune"
    ],
    "severity": "normal",
    "tags": [
      "New feature",
      "Admin impact"
    ],
    "title": "Intune policy to determine SMIME cert lookup priority"
  }
}