What Is AirWatch Secure Email Gateway and How Does It Work?
AirWatch Secure Email Gateway is a security layer that controls how business email moves between mobile devices and an organisation’s mail system. AirWatch is now associated with VMware Workspace ONE, so the product is commonly discussed alongside Workspace ONE UEM, mobile device management, application security and endpoint compliance.
The gateway is designed for workplaces that need email access without exposing Exchange, Microsoft 365 or other corporate messaging services directly to every smartphone and tablet. It checks the device, user and connection against business rules before allowing messages and attachments to pass through.
What the Secure Email Gateway Does
A Secure Email Gateway, often shortened to SEG, acts as a controlled proxy between an email client and the organisation’s back-end mail infrastructure. Instead of a mobile device connecting directly to Exchange or another email server, the device connects to the gateway. The gateway then communicates with the internal mail environment on the user’s behalf.
This arrangement gives IT teams a central enforcement point. Administrators can require an enrolled device, an approved email application, a valid certificate or a compliant security posture before permitting access. If a device is jailbroken, reported lost or removed from management, the gateway can block email without requiring administrators to change every mailbox individually.
The service is especially useful for organisations supporting bring-your-own-device programmes. Employees may use personal iPhones or Android phones, while the business retains control over access to corporate messages, calendars and attachments. This helps separate business information from personal activity and reduces the need to manage an employee’s entire handset.
How Email Traffic Is Checked
The process normally begins when a user opens an approved email client, such as a managed Workspace ONE Boxer deployment or another supported application. The client sends an access request to the SEG, which validates the user’s identity and evaluates the device information supplied by Workspace ONE UEM.
The gateway can check enrolment status, compliance rules, application approval and certificate validity. Policies may also consider whether the device has a passcode, encryption, an up-to-date operating system or a secure connection. If the request meets the required conditions, the SEG forwards it to the organisation’s mail server and returns the authorised email response to the device.
If the device fails a rule, access can be denied or restricted. For example, an employee who removes the management profile may lose mobile email access while their mailbox remains active in Outlook Web Access. This distinction allows a business to contain the risk quickly without immediately disabling the employee’s entire account.
The gateway is generally concerned with access control and traffic mediation rather than replacing the organisation’s email security platform. Spam filtering, malware scanning, data loss prevention and archiving may still be handled by Microsoft Defender, an email security appliance or another specialist service.
Security Controls And Administration
A major benefit of AirWatch email security is the relationship between the gateway and unified endpoint management. Administrators can create compliance policies in Workspace ONE UEM and use the result of those policies to determine whether the SEG should permit access. A single change can therefore affect phones, tablets and other managed endpoints consistently.
Certificate-based authentication is commonly used to strengthen the connection. Rather than relying only on a password that may be reused or stolen, the managed email client can present a device certificate issued through the organisation’s certificate authority. The gateway validates the certificate before allowing the session to continue.
Administrators can also control which email applications are authorised. This reduces the chance that corporate messages will be copied into an unmanaged application with unrestricted sharing, backup or forwarding. Depending on the wider Workspace ONE design, app-level controls, tunnel configuration and content policies can complement the gateway.
Logging supports investigations and operational support. Security teams can review connection attempts, policy decisions and device status, while service desk staff can distinguish an authentication problem from a compliance block. Clear logging is important when employees work across several time zones or when an organisation operates a large distributed fleet.
Deployment In An Australian Business
An organisation can deploy the SEG on premises, in a private environment or through an appropriate hosted model, depending on its Workspace ONE architecture and security requirements. The gateway must be able to communicate securely with the managed email service while remaining reachable by authorised mobile clients. Network design should include firewalls, certificates, DNS, load balancing and high availability.
Australian organisations also need to consider the Privacy Act and the Australian Privacy Principles when deciding how device and email access data is collected, stored and retained. A company based in Melbourne may have staff using personally owned phones, while a Sydney office, a Perth mining operation and remote workers in regional Queensland may all require the same policy with different connectivity conditions.
Data location and operational resilience can be important in the local market. Some businesses prefer services and support arrangements that align with Australian data residency expectations, contractual requirements or regulated-industry policies. Government suppliers and organisations working with Canberra agencies may also map endpoint controls against the Essential Eight, even though the framework is not a complete substitute for an email security architecture.
Sector-specific obligations should be documented before rollout. For example, an aviation company managing crews between Brisbane, Adelaide and international airports may need to align mobile email access with broader operational controls; relevant teams can review aviation compliance guidance when documenting those obligations. The SEG itself does not make an organisation compliant, but it can provide an enforceable access layer within a wider governance programme.
Secure Email Gateway Compared With Other Approaches
A traditional VPN can provide network access, but it may place a mobile device closer to internal services than the business intends. A gateway takes a narrower approach by exposing a defined email path and applying device and user conditions at that point. This can be easier to audit and reduce unnecessary network access.
Direct Microsoft 365 access may be simpler for a small business, particularly when modern authentication, conditional access and mobile application management are already configured. However, organisations with mixed mail systems, legacy infrastructure or tightly controlled managed applications may value a dedicated proxy integrated with endpoint management.
Workspace ONE UEM, Microsoft Intune, Exchange Online and third-party email security products can overlap in functionality. The right design depends on whether the priority is device compliance, application-level protection, mail flow inspection, identity-based conditional access or network segmentation. A SEG is most useful when its role is clearly defined rather than added as an isolated control.
| Approach | Main control point | Typical strength | Important consideration |
|---|---|---|---|
| AirWatch Secure Email Gateway | Managed mobile email connection | Central access enforcement linked to device compliance | Requires careful certificates, networking and policy design |
| Microsoft 365 conditional access | Identity, application and cloud service | Strong integration with Entra ID and Microsoft 365 | Less suited to some legacy or mixed mail environments |
| Mobile application management | Approved app and business data | Protects corporate data within supported applications | May not provide the same mail-server mediation |
| VPN access | Network connection | Broad access to internal services | Can expose more of the network than email requires |
| Direct email access | Mail client and provider | Simple user experience and deployment | Greater reliance on identity and application controls |
Planning A Practical Rollout
A successful deployment starts with an inventory of mail platforms, user groups, device ownership models and existing authentication methods. Document which employees need mobile email, which applications are allowed and what should happen when a device becomes non-compliant. This prevents the gateway from becoming a collection of unclear exceptions.
Pilot the design with representative users from Sydney headquarters, regional offices and travelling staff. Include iOS and Android devices, personal and corporate-owned handsets, weak mobile connections and users who need calendar or attachment access. Testing should cover enrolment, certificate renewal, password changes, device wipe, lost-device reporting and employee offboarding.
The following practices help keep the service secure and manageable:
- Integrate the gateway with a clearly defined Workspace ONE UEM compliance policy.
- Prefer certificate-based access and modern authentication where supported.
- Block direct mobile connections to the mail server after the controlled path is tested.
- Separate personal-device policies from corporate-device policies and explain the privacy impact.
- Monitor gateway logs, failed connections and certificate expiry dates as part of routine operations.
Train the service desk to identify whether a failure comes from identity, device compliance, certificate configuration, network reachability or the mail platform. A documented escalation path is particularly valuable for Australian organisations supporting staff across multiple states, remote sites and international travel schedules.
AirWatch Secure Email Gateway can therefore serve as a practical enforcement point between mobile users and corporate email. Its value comes from the combined design: endpoint management establishes trust, the gateway applies access decisions, and the mail system remains protected behind a controlled connection.
Teams evaluating Workspace ONE can test how device compliance, application controls and email access fit together before committing to a wider rollout. Start with a defined pilot, validate the security and privacy requirements, and use the available 30-day free trial or a sales consultation to assess the configuration against your organisation’s real devices and mail environment.