Information
The macOS built-in Mail.app _MUST_ be disabled.
The Mail.app contains functionality that can establish connections to Apple's iCloud, even when security controls to disable iCloud access have been put in place.
[IMPORTANT]
====
Some organizations allow the use of the built-in Mail.app for organizational communication. Information System Security Officers (ISSOs) may make the risk-based decision not to disable the macOS built-in Mail.app to avoid losing this functionality, but they are advised to first fully weigh the potential risks posed to their organization.
====
Solution
This is implemented by a Configuration Profile.
mobileconfig profile info:
com.apple.applicationaccess.new:
familyControlsEnabled:
True
pathBlackList:
/Applications/Mail.app