Restricting user access to content on web servers
You can prevent BlackBerry® device users from accessing specific web servers using the BlackBerry® Browser or applications on BlackBerry devices. To specify the web servers that you want users to access, you can turn on pull authorization to restrict access to all types of web content and create pull rules to specify a list of web servers that you permit users to access. Alternatively, you can create pull rules that specify a list of restricted web servers.
When you create pull rules, you can specify whether users must authenticate using RSA® authentication, integrated Windows® authentication, or both before the users can access the web servers.
Restrict requests for content on web servers from BlackBerry devices
- In the BlackBerry Administration Service, in the Servers and components menu, expand BlackBerry Solution topology > BlackBerry Domain > Component view > MDS Connection Service.
- Click the instance that you want to change.
- Click Edit instance.
- In the Access control section, in the Pull authorization drop-down list, click Yes.
- Click Save all.
Specify web address patterns
You can create pull rules that specify which web address patterns users can and cannot use to access web servers from the BlackBerry® Browser and other applications on their BlackBerry devices. To create a pull rule, you must first specify web address patterns (for example, specify addresses with domains that are allowed). You can assign the web address patterns to a pull rule that you create, and specify whether access to web servers that match the web address patterns is permitted or restricted on BlackBerry devices. After you create a pull rule, you must assign it to user accounts or groups.
A web site that uses DNS load balancing returns a single IP address to the BlackBerry MDS Connection Service but might use multiple IP addresses to provide access to the web site. As a result, the BlackBerry MDS Connection Service might not be able to restrict BlackBerry devices from accessing the web site.
- In the BlackBerry Administration Service, in the Servers and components menu, expand BlackBerry Solution topology > BlackBerry Domain > Component view.
- Click MDS Connection Service.
- Click Edit component.
- On the Pull URL patterns tab, in the appropriate protocol section, type the web address pattern of a web server that you want to control access to. The web address patterns are based on Java® regular expressions (for example, .*\..*domain.*).
- Click the Add icon.
- Click Save all.
Create a pull rule
- In the BlackBerry® Administration Service, in the Servers and components menu, expand BlackBerry Solution topology > BlackBerry Domain > Component view.
- Click MDS Connection Service.
- Click Edit component.
- On the Access control rules tab, in the Rule name field, type a name for the pull rule.
- In the Control type drop-down list, click Pull.
- Click the Add icon.
- Click Save all.
Restrict or permit web addresses and Intranet addresses using a pull rule
- Create a pull rule.
- If you want BlackBerry® device users to use RSA® authentication to access web servers, configure the BlackBerry® MDS Connection Service to authenticate BlackBerry devices to the RSA® Authentication Manager.
- If you want users to use integrated Windows® authentication when they access the web servers, configure the BlackBerry MDS Connection Service to authenticate devices to Microsoft® Active Directory®.
- In the BlackBerry Administration Service, on the Servers and components menu, expand BlackBerry Solution topology > BlackBerry Domain > Component view.
- Click MDS Connection Service.
- Click Edit component.
- On the Access control rules tab, click the Edit icon for a pull rule.
- In the URL pattern group drop-down list, click the protocol for the address that you want to assign to the pull rule.
- In the URL pattern drop-down list, click the address that you want to assign to the pull rule.
- In the Allowed drop-down list, perform one of the following actions:
-
In the Authentication drop-down list, perform one of the following actions:
- To require that a user authenticates to Microsoft Active Directory using Windows authentication, click Regular.
- To require that the BlackBerry MDS Connection Service authenticates a user using integrated Windows authentication, click Integrated.
- To require that a user authenticates to the RSA Authentication Manager using RSA authentication, click RSA.
- To require that the BlackBerry MDS Connection Service authenticates the user using integrated Windows authentication and that a user authenticates to the RSA Authentication Manager using RSA authentication, click Integrated and RSA.
- Click the Add icon.
- Repeat steps 5 to 8 for each address that you want to assign to the pull rule.
- Click Save all.
Assign a pull rule to the members of a group
- In the BlackBerry® Administration Service, in the BlackBerry solution management menu, expand User.
- Click Manage users.
- Click View more criteria.
- Search for a group.
- Click Select all results in the entire set.
- In the Add to user configuration list, click Add pull rule.
- In the Available pull rules list, click a pull rule.
- Click Add.
- Click Save.
Assign a pull rule to user accounts
- In the BlackBerry® Administration Service, in the BlackBerry solution management menu, expand User.
- Click Manage users.
- Search for one or more user accounts.
- Select the appropriate user accounts.
- In the Add to user configuration list, click Add pull rule.
- In the Available pull rules list, click a pull rule.
- Click Add.
- Click Save.