What is BlackBerry Access?..............................................................................5
Getting started with BlackBerry Access............................................................ 6
System requirements............................................................................................................................................. 6
Remote data wipe.....................................................................................................................................42
Send device commands to BlackBerry Access in BlackBerry UEM......................................................42
Send device commands to BlackBerry Access in Good Control.......................................................... 43
Secure storage of browsing activity........................................................................................................44
||iii
SSL and TLS..............................................................................................................................................44
User passwords........................................................................................................................................ 44
Video support....................................................................................................................................................... 45
Video support FAQ....................................................................................................................................45
Configuring allowed Internet domains............................................................................................................... 46
BlackBerry Access is a secure browser that allows users to access your organization's intranet and business
applications through the work firewall, without using a VPN, on Android, iOS, Windows, and macOS devices.
BlackBerry Access is part of the suite of BlackBerry Dynamics mobile productivity apps. You deploy and manage
BlackBerry Access using BlackBerry UEM or a standalone Good Control server. Both solutions give you the ability
to configure app settings to meet the needs and standards of your organization.
The features offered by BlackBerry Access:
FeatureDescription
Secures dataBlackBerry Access secures work web apps in containers, ensuring that data
is protected and never leaves your organization's control. All browsing data is
encrypted with industry-leading FIPS-validated AES encryption, and BlackBerry
Access uses PAC file URLs to route work data securely.
User authenticationBlackBerry Access leverages standard user authentication methods, including
SSL, NTLM, and TLS, and supports credential persistence.
BlackBerry Access also supports single sign-on with Kerberos Constrained
Delegation across realms and RSA soft token generation.
Intuitive browser featuresBlackBerry Access provides an intuitive interface that makes it easy to
download content, set bookmarks, and browse in multiple tabs. BlackBerry
Access for iOS also captures and saves web clips, and allows users to view
streaming video with intuitive player controls.
App deploymentBlackBerry Access supports pop-ups that streamline the deployment of web
apps, including Cisco WebEx, Salesforce, and custom-developed apps. You
can deploy your organization's HTML5 desktop apps securely, and can provide
users with offline access to those apps.
Integrated app storeBlackBerry Access offers an integrated enterprise app store for Android and
iOS devices.
Remote commandsIf a user's device is compromised (for example, lost or stolen), you can
remotely delete browser data, lock the app, or wipe device data.
Integration with other appsBlackBerry Access for Windows and BlackBerry Access for macOS also
provide users with access to BlackBerry Work to access their mail, calendars,
and contacts from within the secure browser.
|What is BlackBerry Access?|5
Getting started with BlackBerry Access
System requirements
To use BlackBerry Access, your organization must meet the following requirements:
ItemRequirement
Management solutionOne of the following:
•BlackBerry UEM, version 12.6 MR1 or later
•Good Control version 2.3 or later, Good Proxy version 2.3 or later
Device OSFor device OS compatibility, see the Mobile/Desktop OS and Enterprise
Applications Compatibility Matrix.
DeployingBlackBerry Access
You can use eitherBlackBerry UEMorGood Controlto manageBlackBerry Access. If you have not configured
yourBlackBerry UEMorGood Controlenvironment, you must complete configuration tasks before you can
continue with the tasks in this guide. Refer to the table below for more information on which solution to use and
where to find more information.
Management optionDescription
BlackBerry UEM•If you require MDM capabilities, you must manageBlackBerry
BlackBerry Dynamics appsfor information about deployingBlackBerry
Accessin your organization.
Good Control•Although it is recommended that you useBlackBerry UEM, if you do
not require MDM, you can useGood Controlto manageBlackBerry
Access. For more information on the benefits of usingBlackBerry UEM,
seeBenefits of upgrading from Good Control to BlackBerry UEM.
Controldocumentationfor information about deployingBlackBerry
Accessin your organization.
|Getting started with BlackBerry Access|6
Downloading and activatingBlackBerry Access
PlatformDetails
•BlackBerry Access for
Androiddevices
•BlackBerry Access for
iOSdevices
•BlackBerry Access for
Windowsdevices
•BlackBerry Access for
macOSdevices
•For MDM managed devices, you can useBlackBerry UEMto
pushBlackBerry Accessto users, or you can make the app available
in users' work catalogs. Users can download theBlackBerry
UEM Clientfrom theGoogle Playstore orApp Store. TheUEM
Clientmanages the activation ofBlackBerry Dynamicsapps, so users
do not require an access key to activate the apps.
•For devices that are not MDM managed, users can
downloadBlackBerry Accessfrom theGoogle Playstore orApp
Store. UsingBlackBerry UEMorGood Control, you provide users with
an access key to activateBlackBerry Access(seeGenerate access
keys for BlackBerry Dynamics apps).
•Direct users to download and installBlackBerry Accessfrom
theBlackBerry Products and Application Support page.
•UsingBlackBerry UEMorGood Control, you provide users with an
access key to activateBlackBerry Access(seeGenerate access keys
When users installBlackBerry Access for WindowsorBlackBerry Access for macOS,BlackBerry Workis also
installed as an integrated web extension forBlackBerry Access.
Before you deployBlackBerry Access for WindowsorBlackBerry Access for macOSwithBlackBerry Work, note
the following prerequisites:
•Verify that the “DisableBlackBerry Work” app configuration setting is not selected (seeBlackBerry Accessapp
configuration settings).
•BlackBerry WorkusesMicrosoft Exchange Web Servicesinstead ofMicrosoft Exchange
ActiveSync.BlackBerry Workdoesn’t use a configuration file for theMicrosoft Exchange Web
ServicesAutodiscover service. Verify that theMicrosoft Exchange Web ServicesAutodiscover service
is enabled. For more information about using EWSEditor to check if the Autodiscover service is enabled,
visitsupport.blackberry.com/communityto read article 40351.
•Verify that theBlackBerry Enterprise Mobility Serveris configured for theMicrosoft Exchange Web
ServicesAutodiscover service. For instructions, see theBlackBerry Enterprise Mobility Server Installation and
Configuration content
Note: To useBEMSfor Autodiscover, the user must be assigned theBlackBerry Core and Mail
Services or Good Enterprise Services entitlement.The entitlement must be configured in theBlackBerry
Dynamicsconnectivity profile linked to the FQDN of theBEMSand port 8443. For more information,
seeConfigure BlackBerry Work connection settings.
.
Autodiscovery of the user's mailbox occurs as follows:
|Getting started with BlackBerry Access|7
1. BlackBerry Workconnects toBEMSto perform autodiscovery if the properBEMS-related entitlements
are configured in theBlackBerry Dynamicsconnectivity profile and assigned to the user.Good Enterprise
ServicesorBlackBerry Core and Mail Servicesentitlements both cover this requirement.
2. If that fails,BlackBerry Workattempts to connect to https://<emaildomain.com>/autodiscover/
autodiscover.svc
3. If that fails,BlackBerry Workattempts to connect tohttps://autodiscover.<emaildomain.com>/
autodiscover/autodiscover.svc.
•IfMicrosoft Exchange Web Servicesis using a self-signed server certificate, ensure that the “Alert user for
invalid or expired certificate” app configuration setting is not selected.
If you want to enableKerberosConstrained Delegation, note the following prerequisites:
•In theMicrosoft Internet Information Services(IIS), enableKerberosauthentication
(underWindowsauthentication) for theMicrosoft Exchange Web Servicesweb server.
•InMicrosoft Active Directory Users and Computers, in theMicrosoftManagement Console (MMC), on the
Delegation tab, add theMicrosoft Exchange Web ServicesHTTP service for theUEMorGoodadministrator
account.
•IfKerberosConstrained Delegation is enabled, users can’t enter their authentication credentials (username
and password). Authentication is delegated to theUEMorGoodadministrator account.
•For more information about setting upKerberosConstrained Delegation, readConfiguring Kerberos for
MakeBlackBerry Accessavailable to users inBlackBerry UEM
To manageBlackBerry AccessinBlackBerry UEM, you must addBlackBerry Accessto the app list. Your
organization must be entitled to useBlackBerry Accessin theBlackBerry Marketplace for Enterprise Software.
After your organization is entitled to use the app, you can update the app list to synchronize the apps
withBlackBerry UEMimmediately, or wait until it synchronizes automatically (UEMsynchronizesBlackBerry
Dynamicsapps every 24 hours). AfterBlackBerry Accesshas been added to the app list, you can assign it to
users.
For complete instructions for managingBlackBerry Dynamicsapps inBlackBerry UEM, seesee Managing
BlackBerry Dynamics apps
1. Log in to your account athttps://marketplace.blackberry.com/apps.
2. Locate the app in theBlackBerry Marketplace for Enterprise Softwareand request a trial. The app will be made
available to your organization and can be assigned to users after the app has been synchronized toBlackBerry
UEM.
3. To purchase the app, follow the instructions provided by the app developer.
After you finish:
•Update the app list.
•To allow users to install and activateBlackBerry Accesson their devices,assignBlackBerry Accessto a user
group oruser account.
•If you want to use theBlackBerry UEM Clientto manage the activation ofBlackBerry Access(and
otherBlackBerry Dynamicsapps) onAndroidoriOSdevices, instruct users to download theBlackBerry UEM
Clientfrom theGoogle Playstore orApp Store.
•If you want users to activateBlackBerry Accessusing an access key, useto send users an email with the
email address and access key they need to activate the app (seeGenerate access keys for BlackBerry
Dynamics apps).
Update the app list
1. On the menu bar, clickApps.
2.
Click.
Making BlackBerry Access available to users in Good Control
For more information about makingBlackBerry Accessavailable to users inGood Control,see theGood
ControlOnline Help.
Configuring BlackBerry Access app settings
Configure BlackBerry Access app settings in BlackBerry UEM
1. On the menu bar, click Apps.
2. Click the BlackBerry Access app.
|Managing BlackBerry Access|9
3. On the BlackBerry Dynamics tab, in the App configuration table, click +.
4. Type a name for the app configuration.
5. Configure the app settings. See BlackBerry Accessapp configuration settings for a description of the settings
that you can configure.
6. Click Save.
After you finish: Assign BlackBerry Access to a user group. or user account
Configure BlackBerry Access app settings in Good Control
1. On the menu bar, click Policy Sets.
2. Click the name of the policy that you want to assign to BlackBerry Access users.
3. Click the APPS tab.
4. Expand APP SPECIFIC POLICIES > BLACKBERRY ACCESS.
5. Configure the app settings. See BlackBerry Accessapp configuration settings for a description of the settings
that you can configure.
6. Click Update.
BlackBerry Accessapp configuration settings
General
SettingDescriptionApplies to
HomepageThis setting specifies the URL for the website that
you want to appear as the home screen when users
startBlackBerry Access.
The URL must begin with "http://" or "https://".
Allow user to set home
page
Use UIWebView to
render web content on
devices (only applicable
toiOSdevices 12.0 or
earlier)
This setting specifies whether users can set their own
home pages inBlackBerry Access.
This setting specifies whether to allowiOS12.0 and
earlier devices to use UIWebView. The default view is
WKWebView.
This setting specifies whether users can access
telephone and map URLs inBlackBerry Access.
This setting specifies whetherBlackBerry Accesscan
send its user agent string to servers hosting
websites that users visit. The user agent string
identifiesBlackBerry Accessin the HTTP request
headers.
Servers use the information in the user agent string to
provide content tailored toBlackBerry Access.
Accessallows pop-up windows.
Disabling pop-up windows may cause issues with
applications such asMicrosoft Exchange, that open
pop-up windows for tasks like composing new
email messages. If you disable this setting, when
an app tries to open a pop-up window,BlackBerry
Accessdisplays a message that pop-up windows are
blocked.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
Allow other applications
to open urls in full screen
mode. (iOS only)
Allow import
of bookmarks
fromSafariorFirefox
Push BookmarksThis setting specifies bookmarks that will be
Enable web clip featureThis setting specifies whether users can use web
This setting specifies whether apps can open in full
screen mode by default.
This setting specifies whether users can import
bookmarks that they export from other browsers
intoBlackBerry Access.
preloaded inBlackBerry Accessto make it easier for
users to access work intranet webpages.
You can copy and paste the text of your bookmarks
file directly into this text box. The bookmarks must
follow theNetscapebookmark file format. For more
information, seehttps://gist.github.com/jgarber623/
cdc8e2fa1cbcb6889872.
clips. Web clips are small icons on mobile devices
that link to webpages.
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
iOS
|Managing BlackBerry Access|11
SettingDescriptionApplies to
Allow users to perform
app diagnostics
Enable APK installation
(Android only)
Allow external apps
to open HTTP/HTTPS
URLs throughBlackBerry
Access
Do not allow download
from any HTTP or
HTTPS site you have not
approved by whitelisting
it inBlackBerry Control
This setting specifies whether users can perform
app diagnostics forBlackBerry Access. If this setting
is selected, the “Run Diagnostics” option appears
in theBlackBerry Accesssettings menu on users’
devices.
This setting specifies whether users can download
and install .apk files.
This setting specifies whether third-party apps on the
device can open webpages inBlackBerry Access.
Note: ForBlackBerry Access for iOS, links in
third-party, non-BlackBerry Dynamicsapps can
open inBlackBerry Accessonly if they launch
with the following URL scheme:access://open?
This setting specifies whetherBlackBerry
Accessusers can download content from HTTP or
HTTPS webpages even if they haven't been added to
an allowed list.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
Do not allow download
from any HTTPS site
you have not approved
by whitelisting it
inBlackBerry Control
Enable export of
downloaded files to OS
file system (Windows
and Mac)
Enable import of files
from OS file system
Enable Direct DownloadsThis setting specifies whetherBlackBerry Workusers
This setting specifies whetherBlackBerry
Accessusers can download content from HTTPS
webpages even if they haven't been added to an
allowed list.
This setting specifies whetherBlackBerry Workusers
can download files directly to their device's
default download folder, instead of theBlackBerry
Dynamicssecure container.
Note that allowing users to bypass the secure
container is a potential security risk.
This setting specifies whetherBlackBerry Workusers
can attach files that aren't in theBlackBerry
Dynamicssecure container.
can download attachments in email messages
directly to the device's file system, instead of into
the Download Manager in theBlackBerry Dynamics
Launcher.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Work for
Windows
•BlackBerry Work for
macOS
•BlackBerry Work for
Windows
•BlackBerry Work for
macOS
•BlackBerry Work for
Windows
•BlackBerry Work for
macOS
|Managing BlackBerry Access|12
SettingDescriptionApplies to
DisableBlackBerry WorkThis setting specifies whether users can
useBlackBerry Work.
Open HTML files
from otherBlackBerry
Dynamicsapplications
This setting specifies whetherBlackBerry
Accesscan open HTML files from otherBlackBerry
Dynamicsapps.
Accessusers can allow webpages to access their
device's location.
This setting specifies whetherBlackBerry Accesscan
open custom URL schemes supported by third-party
apps. By default,BlackBerry Accessopens only HTTP
and HTTPS URL schemes.
If you select this setting, you must also set the "Enter
comma separated URL schemes" setting.
Note: Each URL string must be mapped as
yourstring://your.URL.string. For example, for Webex,
you could use wbx://yourcompany.webex.com.
In Access, the user would click on the anchor tag
<a href="wbx://blackberry.webex.com">wbx://
blackberry.webex.com</a> to open the local Webex
app and pass the string yourcompany.webex.com to
the app.
•BlackBerry Work for
Windows
•BlackBerry Work for
macOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
Enter comma separated
URL schemes
This setting specifies the custom URL schemes
thatBlackBerry Accesscan open.
The list must be separated by commas. For example,
itms-services,market,wbx,lync, where "itms-services"
isApp Store, "market" isGoogle Play, "watchdox"
isBlackBerry Workspaces, "wbx" isWebEx, and "lync"
isMicrosoft Lync Server.
This setting is valid only if the "Enable 3rd Party
Applications" setting is selected.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
|Managing BlackBerry Access|13
SettingDescriptionApplies to
Enter JSON for search
engine titles and URLs
Enable QR Code
scanning
This setting specifies search engine links that
are added to the end of users' search results for
bookmarks, history, or downloads. They provide
users with easier access to search engines when they
perform searches.
In the text box, specify the search engine labels to
show inBlackBerry Accesssuch asGoogleand the
corresponding search engine URLs. The text must
be in .json format and each entry must end with
[[GASEARCHKEY]]. For example:
This setting specifies whether users can scan a QR
code.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
To force policy update
to device, enter current
date and time and click
update
Security
SettingDescriptionApplies to
Allow SHA1 leaf or
intermediate certificates
Allow legacy/weak
algorithms (DES)
This setting allows you to send the updated app
settings to devices. It also refreshes PAC files.
Enter the current date and time, in either 24-hour
format or 12-hour format (for example, 02-16-2017
12:04AM in 12-hour format and 02-16-2017 0004 in
24-hour format) and click Update.
This setting specifies whetherBlackBerry
Accessusers can access https websites that
use SHA1 signature TLS certificates and expired
certificates. By default, this setting is selected.
This setting specifies whetherBlackBerry Accesscan
use 3DES algorithms.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
|Managing BlackBerry Access|14
SettingDescriptionApplies to
Allow user to securely
save authentication
credentials
Expire stored credentials
after
Alert user for invalid or
expired certificate
This setting specifies whetherBlackBerry
Accessusers can save their authentication
credentials that they use to access webpages.
This setting specifies when the stored user
credentials expire. You can choose between "'Never
Expire" or "24 Hrs."
This setting is valid only if the "Allow user to securely
save authentication credentials" setting is selected.
This setting specifies whether users will be notified
when certificates are invalid or expired.
use only IP addresses and URLs listed in Connectivity
profiles. If an IP address or a URL is explicitly defined
to route DIRECT, the site is allowed and routes
DIRECT.
External sites that are not explicitly defined in the
Connectivity profile are blocked. However, if the
default route is configured to use aBlackBerry
Proxycluster, all undefined IP addresses and URLs
are allowed. If external sites are not allowed, they are
blocked.
If the default route is set to DIRECT, all sites that are
not explicitly allowed are blocked.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
|Managing BlackBerry Access|15
SettingDescriptionApplies to
Allow URL not in Allowed
Domains of Connectivity
Profiles to be loaded in
native browser
When user selects apply
to all during prompt
to open in third party
browser, do not prompt
again for all the hosts
under same domain.
Do not prompt client cert
authorization for all sites
This setting specifies whether, whenBlackBerry
Accessusers try to access webpages from
domains that aren't listed in the allowed domains in
Connectivity profiles, they are opened in the device's
native browser instead ofBlackBerry Access.
This setting is valid only if the "Enforce strict tunnel"
setting is selected.
This setting specifies whether,when user selects
“Always open links from “ <domain>” in Safari“, the
user will not be prompted again for any other hosts
user accesses within same domain.
When a user uploads only one certificate
toBlackBerry UEMthat matches a recognized CA,
selecting this setting allows the webpage requesting
authorization to obtain the certificate without
prompting the user. If the user has uploaded multiple
certificates from the same CA, the user is prompted
to select the certificate to use.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
Do not prompt client cert
authorization for white
listed sites only
List all certificates
available to user to
choose for client cert
authentication
When a user uploads only one certificate
toBlackBerry UEMthat matches a recognized CA,
selecting this setting allows all domains listed in the
allowed domains portion in Connectivity profiles to
obtain the certificate without prompting the user.
If the user has uploaded multiple certificates from
the same CA, the user is prompted to select the
certificate to use.
Specify whether all uploaded encryption certificates
are displayed when a user attempts to access
websites that require a client cert
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
|Managing BlackBerry Access|16
Network
SettingDescriptionApplies to
Enter comma
separatedKerberosrealm
mappings e.g.:
foo=FOO.COMPANY.COM
EnableKerberosForwardable
Ticket
Resolve short names
to full qualified
domain name (FQDN)
forKerberosauthentication
This setting specifiesKerberosrealm
mappings.Kerberosauthentication realms define
areas that are under control ofKerberos. These
mappings allow you to equate realm names with other
names that are accessible or for some other reason.
The limit is 4000 characters.
This setting specifies whetherKerberosForwardable
tickets can be used.
Forwardable tickets inKerberosare client-side
authentication credentials that are tied to a particular
IP address that can be treated as new tickets with
other IP addresses.
This setting specifies whether users can reach
servers by typing the unqualified domain name
instead of the FQDN forKerberosauthentication.
Enabling this setting may impact performance.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
Disable file upload and
download on mobile
connections (Windows
Only)
Enable Web ProxyThis setting specifies whetherBlackBerry Accesscan
This setting specifies whether files can be
downloaded or uploaded when users are connected
to a mobile network instead of aWi-Finetwork.
inBlackBerry Access.
communicate through a web proxy server.
•BlackBerry Access for
Windows
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
|Managing BlackBerry Access|17
SettingDescriptionApplies to
Use Proxy Auto
Configuration
Enter URL for PAC file
location
PAC files make it easier for users to work with proxy
servers by hiding the complexities of authentication
from the end user.
If your organization uses a PAC file to define proxy
rules, you can select this setting to use the proxy
server settings from the PAC file that you specify.
Enabling this setting will override static web proxy
settings.
This setting requiresBlackBerry Dynamicsservers
version 1.6 and later.
This setting is valid only if the "Enable Web Proxy"
setting is selected.
This setting specifies the URL for the web server that
hosts the PAC file, including the PAC file name. For
example, http://www.example.com/PACfile.pac.
Note: The PAC file must not be hosted on the
same server asGood Controlor on the same server
asBlackBerry UEMor any of its components. This
configuration is not supported.
The limit is 4000 characters.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
This setting is valid only if the "Enable Web Proxy" and
"Use Proxy Auto Configuration" settings are selected.
Use Static Web Proxy
(Full Tunnel)
Proxy HostThis setting specifies the the FQDN or IP address of
This setting specifies whether communications are
enabled through a single web proxy service only.
This setting is valid only if the "Enable Web Proxy"
setting is selected.
Note: Enabling this setting overrides 'Enforce strict
tunnel' settings.
the proxy server.
This setting is valid only if the "Use Static Web Proxy
(Full Tunnel)" setting is selected.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
|Managing BlackBerry Access|18
SettingDescriptionApplies to
Proxy PortThis setting specifies the port number of the proxy
server.
This setting is valid only if the "Use Static Web Proxy
(Full Tunnel)" setting is selected.
Enable PAC proxy check
for all the sub-resources
RSA
SettingDescriptionApplies to
You can use this setting to enforce PAC processing
without caching.
Selecting this setting has an impact on the
performance of your organization’s environment.
It is recommended to use this feature for special
circumstances only.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
EnableRSA SecurIDThis setting specifies whether users can useRSA
SecurIDtoken authentication to authenticate
withBlackBerry Access, instead of a password.
Prompt PIN for PINPAD
Token
Token File Password
Retry Count
Token Request SendTo
Email Address
This setting specifies whether users are always
prompted for anRSA SecurIDPIN.
This setting is valid only if the "Enable RSA SecurID"
setting is selected.
This setting specifies the number of times that a user
can enter an incorrectRSA SecurIDPIN before they
are locked out.
This setting is valid only if the "Enable RSA SecurID"
setting is selected.
This setting specifies the email address of
yourRSAauthentication manager. AllRSA
SecurIDtoken seed record requests are sent to this
address.
This setting is valid only if the "Enable RSA SecurID"
setting is selected.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
|Managing BlackBerry Access|19
SettingDescriptionApplies to
Token Request CC Email
Address
Token Request Email
Subject
Features
SettingDescriptionApplies to
Allow user to uploadThis setting specifies whether users can upload files
Allow user to take new
photos/videos and
upload
This setting specifies the email address that should
be CC'd for allRSA SecurIDtoken seed record
requests.
This setting is valid only if the "EnableRSA SecurID"
setting is selected.
This setting specifies the email subject for token
request emails.
This setting is valid only if the "EnableRSA SecurID"
setting is selected.
to web pages inBlackBerry Access. Files can have a
maximum size of 20 MB.
This setting specifies whether users can take photos
and videos and upload the photos and videosto a
web page. Users must allowBlackBerry Accessto
access their cameras. Files can have a maximum size
of 20 MB.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
Allow user to select
existing photos/videos to
upload
Allow user to select files
from file providers to
upload
Allow user to upload
files from the download
manager
This setting specifies whether users can upload
existing photos and videos from their photo libraries
to a web page. Files can have a maximum size of 20
MB.
This setting specifies whether users can upload files
from other file apps. Files can have a maximum size
of 20 MB.
This setting specifies whether users can upload files
that have been downloaded to the downloads folder
inBlackBerry Access.
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
•BlackBerry Access for
Android
•BlackBerry Access for
iOS
|Managing BlackBerry Access|20
BlackBerry Work(Mac and Win)
SettingDescriptionApplies to
Launch mail app on
browser start
Enable avatar photosThis setting specifies whether users can set avatar
EWS serverOptionally, you can use this setting to specify the
This setting specifies whether the mail app opens
instead of a browser windowwhenBlackBerry
Accessstarts.
photos. If it is disabled, the user's initials appear
instead.
URL that the mail app uses forMicrosoft Exchange
Web Servicesprovisioning.Otherwise,BlackBerry
Workuses autodiscovery methods to locate the EWS
server.
Optionally, you can enter a series of name=value pairs
separated by commas, where the name designates
an email domain and the value designates the URL
for the EWS endpoint for that domain.Using this
method, administrators can assign multiple users
with different EWS endpoints to the same application
policy and be able to controlwhere the mail app
accesses mail, based on the user’s email domain.
Note: BlackBerry Accessdoes not validate the
entries. All related logs are prefixed by[WEB_MAIL]
EWS URL Resolution:at the INFO log level.
This setting specifies whether the mail app can
useKerberosconstrained delegation.
This setting specifies whether users can use SSL
certificates instead of using a login and password
to authenticate withBlackBerry Work. Depending
on your environment, SSL certificates must be
uploaded toBlackBerry UEMorGood Control. For
more information, seeManaging certificates.
Workdisplays notifications for mail and calendar
events.
Enable email
Classification
This setting specifies whether to enable email
classification markings, such as INTERNAL,
CONFIDENTIAL, NO FORWARD, and/or NO REPLY.If
selected, specify the following sample information in
theClassifications and caveatsfield as required:
Display warning while
sending message if
recipient's email domain
is unauthorized
Default signing algorithmThis setting specifies the algorithm to use for signing
Default encryption
algorithm
Enable Revocation
Checking
This setting specifies whether to display a warning if
the user is sending an email to a recipient in an email
domain that is not authorized. If selected, specify
email domains you want to authorize in the Authorize
email domains field.
Users will notice that email addresses in untrusted
domains appear in purple text.
sent messages.
This setting specifies the algorithm to use for
encrypting sent messages.
This setting allows you to setrevocation checking
of all certificates used for signing/encryption and
signing verification/decryption of S/MIME messages.
•When you select this box,Use AIA extension incertificate if presentis selected by default.
•In theDefault OSCP URLfield, specify the web
address of the OSCP service.The OCSP URI is
used by the S/MIME verification APIs as an OCSP
revocation check service if an AIA extension is not
present in a certificate or if theUse AIA extensionin certificate if presentcheck box is not selected.
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
|Managing BlackBerry Access|23
SettingDescriptionApplies to
UseOffice 365Modern
Authentication
This setting allows you to configure options
forMicrosoft Office 365. Modern authentication
enablesBlackBerry Workto us sign-in features such
as Multi-Factor Authentication and SAML-based
third-party Identity Providers. If selected, specify the
following:
•In theAzureApp ID field, specify theMicrosoft
Azureapp ID forBlackBerry Work.
For information on how obtain anAzureapp
ID, seeObtain anAzureapp ID forBlackBerry
WorkforWindowsandmacOS.
•In theOffice 365Sign On URL field, specify the
web address thatBlackBerry Workshould use
when it signs in toOffice 365. If you do not
specify a value,BlackBerry Workuses https://
login.microsoftonline.com during setup.
•In theOffice 365Tenant ID field, specify the
tenant ID of theOffice 365server that you
wantBlackBerry Workto connect to during setup.
If you do not specify a value, a value of "common"
is used.
•In theOffice 365Resource field, specify the
resource URL of theOffice 365server that you
wantBlackBerry Workto connect to during
setup. If you do not specify a value,BlackBerry
Workuseshttps://outlook.office365.com during
setup.
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
BlackBerry Access(Mac and Win)
SettingDescriptionApplies to
Enable WebRTCThis setting specifies whether to enableaccess
to WebRTC protocol-based destinations such
asCitrixVDI browser-based access.
For information on how to configureBlackBerry
Accessto support WebRTC, seeConfigure access to
WebRTC-based destinations.
Enable Microphone
Access
This setting specifies whetherBlackBerry
Accessshould display a prompt that allows users to
permit websites to use the device's microphone. You
can enable it only if WebRTC is enabled.
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
|Managing BlackBerry Access|24
SettingDescriptionApplies to
Enable Camera AccessThis setting specifies whetherBlackBerry
Accessshould display a prompt that allows users to
permit websites touse the device's camera.You can
enable it only if WebRTC is enabled.
Enable UDP Protocol
support
Enable PrintingThis setting specifies whether to allow users to print
Enable embedded PDF
viewer
Automatically open
PDF andMicrosoft
Officedocuments after
download
This setting specifies whether to allow UDP
connections initiated by websites.
web pages.
This setting specifies whether to allow users to view
embedded PDFs from withinBlackBerry Access.
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
EnableMicrosoft
OfficeURI support
OnlyMicrosoft OfficeURIs that specify online
documents are supported.
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
|Managing BlackBerry Access|25
SettingDescriptionApplies to
Enable Upgrade
Notifications
Enable Awingu ExtensionThis setting specifies whether to enable the Awingu
This setting specifies whether to push notifications to
users when a new upgrade is available.
If selected, specify the following:
•In the Min Windows Version field, specify the
minimumBlackBerry Access for Windowsversion.
If there are versions available that are later than
the version specified in this field, users will be sent
an upgrade notification.
•In the Min Mac Version field, specify the
minimumBlackBerry Access for macOSversion. If
there are versions available that are later than the
version specified in this field, users will be sent an
upgrade notification.
•In the Win Download URL field, specify the URL for
theBlackBerry Access for Windowsapp.
•In the Mac Download URL field, specify the URL
for theBlackBerry Access for Windowsapp.
•In the Notification Message, you can create a
custom message or leave the default message.
extension which allows users to store their Awingu
credentials. Also, when enabled, an icon is added to
the toolbar inBlackBerry Accessand users can launch
Awingu by clicking the icon in the toolbar.
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
If selected, you must specify the following:
•In the Awingu URL field, specify your
organization's Awingu URL. For example,
yourcompany.awingu.com
•In the Awingu DOMAIN field, specify your
organization's Awingu domain.
|Managing BlackBerry Access|26
SettingDescriptionApplies to
Enable installation of
extensions
Enable developer modeThis setting allows you to enable developer mode
This setting specifies whether to allow websites to
download extensions for third-party apps.
If selected, in the Permitted Extension Ids field,
specify one more more extension IDs that can be
installed. The source can be from any URL.
Note: WebExandSkypecan be enabled either by
adding their extension ids or by adding their protocols
to the external protocols list.
In theChromeapp store, users can add only apps that
have permitted extensions.
If anextension is enabled and installed, and
the administrator removes its ID, the extension
is removed fromBlackBerry Access. If the
administrator re-adds the extension, the user must
restartBlackBerry Accessto be able to add the app
from theChromeapp store.
inBlackBerry Access.
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
•BlackBerry Access for
Windows
•BlackBerry Access for
macOS
Obtain anAzureapp ID forBlackBerry WorkforWindowsandmacOS
If you are configuringOffice 365settings in the app configuration forBlackBerry Work, you may need to obtain
and copy theAzureapp ID forBlackBerry WorkforWindowsandmacOS.
Note: If you have already created anAzureapp ID forBlackBerry WorkforiOSandBlackBerry
WorkforAndroid,make sure that you do not use the sameAzureapp ID forforBlackBerry
WorkforWindowsandmacOS.BlackBerry WorkforWindowsandmacOSneed their ownAzureapp ID.
1. Log on toportal.azure.com.
2. In the left column, clickAzure Active Directory.
3. ClickApp registrations.
4. ClickNew registration.
5. In theNamefield, enter a name for the app. This is the name that users will see.
6. Select a supported account type.
7. In theRedirect URIdrop-down list, selectPublic client (mobile & desktop). and enterchrome-extension://
glilhfdenplejncjmngdaojopbobomfa/login.html
8. ClickRegister.
9. In theManagesection, clickAPI permissions.
10.ClickAdd a permission.
11.In theSelect an APIsection, click theMicrosoft APIstab.
12.SelectExchange.
13.If your environment is usingOffice 365 Exchange Online, set the following permissions:
|Managing BlackBerry Access|27
•Delegated permissions: Access mailboxes as the signed-in user via Exchange Web Services (EWS >
EWS.AccessAsUser.All).
14.ClickAdd permissions.
15.ClickMicrosoft Graph. IfMicrosoft Graphis not listed, addMicrosoft Graph.
16.Set the following permissions forMicrosoft Graph:
•Delegated permissions
•Sign in and read user profile (User > User.Read)
•Send mail as a user(Mail > Mail.Send)
17.Click one of the following:
•IfMicrosoft Graphexisted in the API permissions list, clickUpdate permissions.
•If you needed to addMicrosoft Graph, clickCreate.
18.ClickGrant Permissionsto apply the permissions for the app. These settings will not be applied to the app
until you have granted the updated permissions.
19.ClickYes.
You can now copy the Application ID for the app that you created.In theManagesection, clickOverview.It is
located under the name of the app, in the Application ID field.
Configuring the BlackBerry Dynamics Launcher
The BlackBerry Dynamics Launcher allows users to access their BlackBerry Dynamics apps in one place. Using
the BlackBerry Dynamics Launcher button, users can access things such as BlackBerry Work (mail, calendar,
contacts), app catalogs, and downloads, from the BlackBerry Access browser window.
You can configure the BlackBerry Dynamics Launcher in the BlackBerry Enterprise Mobility Server. You can also
set a customized icon for the BlackBerry Dynamics Launcher.
For more information, see the BlackBerry Enterprise Mobility Server content.
Adding the work app catalog to the BlackBerry Dynamics Launcher
You can add the work app catalog to the BlackBerry Dynamics Launcher so that users have quick access to a list
of their assigned work apps.
For BlackBerry Access for Android devices, when users select the BlackBerry UEM App Catalog icon in the
BlackBerry Dynamics Launcher, the work app catalog opens in the BlackBerry UEM Client.
For BlackBerry Access for iOS devices, when users select the BlackBerry UEM App Catalog icon in the BlackBerry
Dynamics Launcher, the work app catalog opens in the BlackBerry Access for iOS browser.
For more information about using BlackBerry UEM to manage BlackBerry Access, see the Getting started with
BlackBerry UEM and BlackBerry Dynamics content.
For more information about using Good Control to manage BlackBerry Access, visit http://help.blackberry.com/
en/good-control-good-proxy/current/ to read the Good Control Help Guide.
TheBlackBerry UEM App Catalogfeature is configured automatically byBlackBerry UEMand must be able to
route through the Internet. If theRoute all trafficoption is not selected in theBlackBerry DynamicsConnectivity
profile, you must configure the *.bbsecure.com domain requests to route through Direct. For more information on
theBlackBerry DynamicsConnectivity profile, seeSetting up network connections for BlackBerry Dynamics apps.
1. On the menu bar, clickPolicies and Profiles.
2. ClickNetworks and connections>BlackBerry Dynamics connectivity.
3. Select the connectivity profile that you want to edit.
4. In theDomaintable, click+.
5. On theAllowed Domainscreen, enter the following:
a) In theDomainfield, enter*.bbsecure.com.
b) SelectDirect.
6. ClickSave.
Configure single sign-on for BlackBerry Access in Good Control
You can enable single sign-on for BlackBerry Access in an environment that's already set up for Microsoft Office
365 with Microsoft Active Directory Federation Services and single sign-on.
Before you begin:
•Configure single sign-on in Office 365 with Active Directory Federation Services version 2.0 or 3.0, relying on
Windows Authentication and Kerberos.
•Configure Good Control for Kerberos constrained delegation.
•Verify that the "Identify BlackBerry Access in User Agent" app setting is selected in BlackBerry UEM or Good
Control.
1. Verify the SPN for Active Directory Federation Services. For Active Directory Federation Services to use
Kerberos, the Active Directory Federation Services service must have registered an SPN. This SPN should
already be registered by the prerequisite Active Directory Federation Services configuration in Office 365.
a) Open a command prompt on a computer with Active Directory RSAT tools installed.
b) Enter the command: setspn -q HOST/fqdn.of.adfs.server where fqdn.of.adfs.server is the FQDN of your
Active Directory Federation Services server.
This command exposes the name service account that serves Active Directory Federation Services. For a safer
form of delegation (HOST allows any protocol, only HTTP is needed) you might want to register the HTTP
SPN of the Active Directory Federation Services service account with the following command: setspn -SHTTP/fqdn.of.adfs.serverADFS_service_account, where ADFS_service_account is the name of the Active
Directory Federation Services service account shown in the previous command.
2. Enable the User Agent in Active Directory Federation Services. By default, Active Directory Federation Services
allows only known user agents to use Windows Authentication. All other user agents are considered external
and are served with Forms Based Authentication (FBA) or certificate authentication.
a) To enable single sign-on in BlackBerry Access you need to add the BlackBerry Access user agent string
to Active Directory Federation Services to allow Windows Authentication for BlackBerry Access and
Kerberos constrained delegation. For all platforms, the BlackBerry Access user agent string begins with
Mozilla/5.0.
|Managing BlackBerry Access|29
b) To verify the Active Directory Federation Services user agents, enter the following command: Get-
e) Restart the Active Directory Federation Services service.
3. Set delegation on the Kerberos account of Good Control.
a) Log in to Good Control.
b) Navigate to the Server Properties tab.
c) Scroll to find the value of the gc.krb5.principal.name property. Set this object name in Microsoft Active
Directory.
d) On your Microsoft Active Directory server, click the Delegation tab.
e) Click ADD and enter the Active Directory Federation Services service account name that you discovered in
step 1.
f) Add the HTTP SPN.
g) Click OK.
Configure single sign-on for BlackBerry Access in BlackBerry UEM
You can enable single sign-on for BlackBerry Access in an environment that's already set up for Microsoft Office
365 with Microsoft Active Directory Federation Services and single sign-on.
Before you begin:
•Configure single sign-on in Office 365 with Active Directory Federation Services version 2.0 or 3.0, relying on
Windows Authentication and Kerberos.
•Configure BlackBerry UEM for Kerberos constrained delegation.
•Verify that the "Identify BlackBerry Access in User Agent" app setting is selected in BlackBerry UEM.
1. Verify the SPN for Active Directory Federation Services. For Active Directory Federation Services to use
Kerberos, the Active Directory Federation Services service must have registered an SPN. This SPN should
already be registered by the prerequisite Active Directory Federation Services configuration in Office 365.
a) Open a command prompt on a computer with Active Directory RSAT tools installed.
b) Enter the command: setspn -q HOST/fqdn.of.adfs.server where fqdn.of.adfs.server is the FQDN of your
Active Directory Federation Services server.
This command exposes the name service account that serves Active Directory Federation Services. For a safer
form of delegation (HOST allows any protocol, only HTTP is needed) you might want to register the HTTP
SPN of the Active Directory Federation Services service account with the following command: setspn -SHTTP/fqdn.of.adfs.serverADFS_service_account, where ADFS_service_account is the name of the Active
Directory Federation Services service account shown in the previous command.
|Managing BlackBerry Access|30
Loading...
+ 82 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.