Connect BlackBerry UEM to Cisco ISE
BlackBerry UEM
to Cisco ISE
If you do not have a
Cisco Identity Services
Engine
(ISE) administrator account, send these instructions to a Cisco ISE
administrator, along with the required information about UEM
and the UEM
administrator account. For the latest Cisco ISE
documentation, visit Cisco ISE Configuration Guides.In a browser, navigate to
https://
where <server_name>
:<BlackBerry_Web_Services_port>
/enterprise/admin/util/ws?wsdl<server_name>
is the FQDN of the computer that hosts the BlackBerry UEM Core
component. The default <BlackBerry_Web_Services_port>
value is 18084. Use your browser to export the BlackBerry Web
Services
certificate and save it to your desktop.- Log in to theCisco ISEmanagement console.
- Import theBlackBerry Web Servicescertificate into theCisco ISEtrusted certificate store. Select the options to trust for client authentication and syslog, and to trust for authentication ofCiscoservices.
- Add an external MDM service and specify the details of theUEMinstance, including the FQDN or IP address of theUEMdomain, the port (default 18084), and the credentials of theUEMadministrator account.
- For the polling interval, specify how often, in minutes, you wantCisco ISEto pollUEMfor device data. It is a best practice to use the default value.If you set this value to 60 minutes or less, you might notice a significant performance impact on your organization’s environment. If you set this value to 0,Cisco ISEdoes not pollUEM.
- Enable and test the connection toUEM.
After the connection is established, you can view the dictionary attributes for
UEM
in the Cisco ISE
management console. Log entries for Cisco ISE
polling are written to the BlackBerry UEM Core
(CORE) log file.Perform the following configuration tasks in the
Cisco ISE
management console:
- Configure ACLs on the wireless LAN controller.
- Configure an authorization profile that will redirect devices to theBlackBerry UEM Self-Serviceconsole if they try to access the work network while the device is not activated onUEM. The user requires aUEMuser account to log in toBlackBerry UEM Self-Serviceand activate the device. Instruct users to contact theUEMadministrator whenCisco ISEdirects them to the enrollment page.
- Configure authorization policy rules that determine howCisco ISEhandles devices that are not activated onUEMor compliant withUEM.