Summary
This is the admin side of iMessage capture: how an administrator creates an iMessage connection in MirrorWeb Insight and sends the activation email to the user. The user then completes setup on their own device — that end-user process is covered in Setting up Your Device for iMessage Archiving.
The iMessage connection form is the same as the WhatsApp form, with one extra field: a Login type selector that appears only for iMessage.
Prerequisites
Admin access to Connection management in MirrorWeb Insight.
An available iMessage licence for your organisation. If your licence quota is reached, the platform option shows a License quota reached tooltip and cannot be selected.
The user's work email address (where the connection invite is sent) and the phone number to be captured.
Step-by-Step Instructions
Step 1: Open the Connections tab
In Connection management, go to the Connections tab.
Step 2: Start a new connection
Select Add connections, then New Connection.
Step 3: Select iMessage (Platform selection)
On the Platform selection step, choose the iMessage platform card.
Note: If iMessage is greyed out with a License quota reached tooltip, your organisation has no remaining iMessage licences. Free up or request a licence before continuing.
Step 4: Enter the connection details
On the Connection details step, complete the form:
Connection name — optional. Enter an optional name for this connection.
User email address — required. This is where the connection invite will be sent to.
Phone number — required. The phone number we'll be tracking for this connection. (The phone-number field defaults to a US country code.)
Login type — Select the type of login required for this connection. This field appears only for iMessage connections; choose an option from the Select a login type... list (see Step 5).
Then select Create connection.
Step 5: Choose the Login type
The Login type selector ("Select the type of login required for this connection.") appears only for iMessage connections. It determines how the user signs in when they link their device — that is, which credentials the activation flow asks them for.
The list of available login types is loaded at runtime from your organisation's configuration, so the exact set shown to you depends on how your organisation is set up. The login types that the platform recognises are:
iCloud (
icloud) — the user signs in with their iCloud / Apple Account credentials. This is the default if no other type is selected, and the device-linking flow guides the user through entering their Apple Account credentials and completing Apple's OTP/MFA step. Use this for a standard personal Apple Account sign-in.
Note: For bulk upload, the iMessage Login type column currently supports only iCloud ("iMessage requires a login type (we currently only support iCloud)").
The platform also recognises the following login types, which sign the user in through your organisation's identity provider rather than directly with an Apple Account. Use these when your organisation requires Apple Account sign-in to go through its single sign-on provider:
Azure AD (
azure_ad) — sign in via Microsoft Entra ID / Azure AD.Okta (
okta) — sign in via Okta.
After you have created the connection, the connection detail view shows the chosen Login type (for example, iCloud, Azure AD, or Okta).
Step 6: Send the activation email
A newly created connection shows the status Unactivated and no invite is sent automatically — you send it.
For a single connection: use the send-email action on the connection's row (Send connection request). The action is unavailable for a connection that is Already connected.
For several connections at once: use the bulk send action to open the Send connection requests dialog, then select Send. Connections that don't require authentication are ignored.
Note: For a connection that is already Pending, the system sends a reminder rather than a new request.
Step 7: Track activation status
The connection's status moves from Unactivated to Pending to Connected as the user completes setup on their device. The connection detail view also shows First connection email sent, Last connection email sent, and Last reminder email sent (or No authentication request sent if none has gone out yet).
Notes
Note: The user receives the activation email at the User email address entered above and completes linking on their own device, which includes verifying an email code, signing in with their iCloud / Apple Account credentials, completing Apple's OTP/MFA step, and optionally setting up SMS forwarding. See Setting up Your Device for iMessage Archiving for the user-facing steps, How to complete OTP and MFA verification for mobile capture for the verification step, and How to manage SMS forwarding for iMessage capture for the SMS forwarding flow.