Installation and Configuration Guide

Local Navigation

Find the LDAP information that the BlackBerry Administration Service requires

You can use the ldp.exe utility to access the domain controller in your organization's environment and locate the LDAP information before you install the BlackBerry® Administration Service.
Before you begin:
  • Verify that you have a domain-administrator account.
  • Download and install the Windows® support tools. For more information about installing the support tools, visit www.microsoft.com to read articles 892777 and 301423.
  1. On the Start menu, click Run.
  2. Type ldp.
  3. Click OK.
  4. On the Connection menu, click Connect.
  5. Connect to the domain controller.
  6. On the Connection menu, click Bind.
  7. In the Bind dialog box, click OK.
  8. To set the LDAP search base to the BaseDN and permit the BlackBerry Administration Service to search the entire directory tree for user accounts, perform the following actions:
    1. In the ldp window, on the View menu, click Tree.
    2. In the drop-down list, select the first option.
    3. Copy the BaseDN to a text file (for example, DC=yourDepartment,DC=yourOrganization,DC=net).
  9. To permit the BlackBerry Administration Service to access only the part of the directory tree that includes current and prospective BlackBerry device users in your organization, specify a specific area in the directory tree as the LDAP search base (for example, OU=Users,DC=yourDepartment,DC=yourOrganization,DC=net).
  10. To locate the administrator account information, in the Microsoft® Active Directory® Users and Computers console, find the user name for the administrator account. If you use Windows Server® 2003, verify that the administrator account has a password.
  11. Transfer the text file to the computer that you want to install the BlackBerry Administration Service on.

Configure the BlackBerry Administration Service to authenticate user accounts from multiple Microsoft Active Directory domains

During the installation process, the setup application prompts you to specify the LDAP server URL, search base, and the credentials for an LDAP administrator so that the BlackBerry® Administration Service can access the LDAP server and authenticate user accounts.

If the user accounts in your organization's environment are stored in more than one domain in a Microsoft® Active Directory® forest, you must configure the LDAP settings that the BlackBerry Administration Service uses so that the BlackBerry Administration Service can search the global catalog.

  1. During the installation process, specify the DNS host name of a global catalog server as the LDAP server name that is included in the LDAP server URL.
  2. Specify the LDAP port number to be 3268.
  3. Specify the LDAP user name and password to be the user name and password of an administrator account that has permission to read user attributes from the global catalog.

Was this information helpful? Send us your comments.