For the AirWatch server to start issuing the PowerShell commands, you must set up a PowerShell Admin User account on Office 365 or the Exchange Server. This user account is a service account that must also have specific roles associated to it for AirWatch to operate.

Create an Office 365 Service Account

You must create the service account to associate with the service account all your user mailbox accounts that require protection.


To create user mailboxes in Exchange 2016, refer

To create user mailbox in Exchange 2013, refer

To create a service account in Office 365:

  1. Log in to your Office 365 as an administrator.
  2. Navigate to Office 365 admin center > USERS > Active Users.
  3. Select the " +" icon to add a new user. The create new user account page appears.
  4. On the create new user account page:
    1. Enter the first name, last name, display name, user name, and your email domain.
    2. Select Type password and enter the password for the service account.
    3. Deselect the Make this person change their password the next time they sign in check box.
    4. Enter the email address of the recipient to whom the password must be sent. Select Create.
    5. Select Close.

    An Office 365 license is assigned to the service account. The service account does not require an Office 365 license to be assigned to it. You can remove the assigned license by editing the license.

  5. Select your service account from the Active users list.
  6. Select Edit next to the Assigned License. The Assigned License page appears.
  7. Deselect the check box for the assigned license. Select Save.

Assign Roles to the Office 365 Service Account

After you create a service account, use the Exchange Admin Center to create specialized roles for the service account. These roles provide AirWatch all the permissions required to operate.


You can also create custom roles for Exchange 2013 and Exchange 2016 service accounts using the Exchange Admin Center.


To assign roles to the service account:

  1. Navigate to Exchange Admin Center > Permissions> admin roles.
  2. Select the " +" icon to create a new role group. The new role group page appears.
  3. Enter the details.
    Settings Descriptions
    Name Enter the name for the role.
    Description Enter the description for the role.
    Write Scope Select Default from the drop-down menu.
    Roles Add Mail recipients, Organization Client Access, and Recipient Policiesas the roles.
  4. Save the settings.

If you are an AirWatch SaaS and an Office 365 user, your configuration is complete. The remaining steps are applicable for on-premise Exchange and AirWatch configurations.

Assign Roles to the Exchange 2010 Service Account

For Exchange 2010, you can set up a PowerShell Admin User on Exchange Management Console through the Administration tab. Use permissions that can set up the PowerShell Admin user roles.

To configure the PowerShell admin user on Exchange console:

  1. Navigate to Toolbox and access the Role Based Access Control User Editor in the Exchange Management Console.
  2. Once the Internet browser opens, enter in the credentials (domain or user and password) of the Exchange Administrator with relevant permissions. Signing in as the Exchange Administrator creates a test role group and the roles associated to this group.


  1. Select New to create new role group.
  2. Add the relevant roles; Mail Recipients, Organization Client Access, and Recipient Policies. Then, select Save to

    create a new role group specific to AirWatch PowerShell Integration.