Create a BlackBerry Dynamics Notification profile

BlackBerry Dynamics Notification profiles are available in UEM Cloud environments only.

If your organization's environment contains multiple instances of Microsoft Exchange Server or Microsoft Exchange Online, and you want to configure email notifications from these email domains for different groups of users, you can use BlackBerry Dynamics Notification profiles to manage these additional configurations. When you create and assign a BlackBerry Dynamics Notification profile, you configure the BlackBerry Mail (Push Notifications) service to connect to a specific Microsoft Exchange Server or Microsoft Exchange Online instance for that email domain.

When a user is assigned a BlackBerry Dynamics Notification profile, the configuration from the profile will be used instead of the default configuration (Settings > BlackBerry Dynamics > Email notifications). If you create and assign multiple profiles, rank them to control which profile is applied to a user when group assignments conflict. If a user is not assigned a BlackBerry Dynamics Notification profile, the default configuration is used.

Note that when you create and assign the BlackBerry Dynamics Notification profile to users, the profile is assigned to 60 users every three minutes.

Verify that you have completed steps 1-4 of the configure email notifications for BlackBerry Work in a cloud environment to create the default configuration for BlackBerry Work email notifications in the UEM Cloud management console (Settings > BlackBerry Dynamics > Email notifications). This default configuration is required to set up BEMS, and establishes the default email notification settings that BEMS will apply for any users that are not assigned a BlackBerry Dynamics Notification profile.
  1. In the BlackBerry UEM management console, on the menu bar, click Policies and profiles > Policy > BlackBerry Dynamics Notification Profile.
  2. Click + to create a new profile, or click the name of the profile that you want to copy and make the necessary updates.
  3. Type a name and description for the profile.
  4. In the Authentication type section, select how you want BEMS to authenticate with Microsoft Exchange Server or Microsoft Exchange Online:

    Authentication option

    Steps

    Authenticate using a service account

    a. Select Credential.

    b. In the Service account username field, specify the username of the BEMS service account in the following format:
    • Microsoft Exchange Server: <domain>\<username> or UPN
    • Microsoft Exchange Online: <username>@<domain>

    c. In the Service account password field, specify the password of the service account.

    Authenticate using a client certificate

    a. Select Client certificate.

    b. Next to the Certificate file field, click the Browse button. Navigate to and select the .pfx client certificate.

    c. In the Password field, specify the certificate password.

  5. In a Microsoft Exchange Online environment, you must enable and configure modern authentication:
    1. Select Enable modern authentication.
    2. In the Authentication authority field, specify the URL of the authentication server that BEMS will access to retrieve the OAuth token for authentication with Microsoft Exchange Online (for example, https://login.microsoftonline.com/<tenantname> or https://login.microsoftonline.com/<tenantid>).
    3. In the Client app ID field, specify the client app ID.
    4. In the Server name field, specify the FQDN of the Microsoft Exchange Online server (for example, https://outlook.office365.com).
  6. If you want BEMS to obtain user information from Microsoft Exchange Server or Microsoft Exchange Online when it discovers users, in the Autodiscover URL override field, specify the autodiscover URL (for example, https://ad.example.com/autodiscover/autodiscover.svc).

    If you don't specify a URL, BEMS uses autodiscover to automatically locate the Microsoft Exchange Server or Microsoft Exchange Online.

  7. If you do not want BEMS to use HTTP redirection and DNS SRV lookups to retrieve the autodiscover URL, clear the Allow HTTP redirection and DNS SRV record check box.
  8. If you want BEMS to use the corporate network, through the BlackBerry Connectivity Node, to connect to Microsoft Exchange Server or Microsoft Exchange Online, rather than a direct connection from the BlackBerry Infrastructure, select the Use BlackBerry Connectivity Node route check box.

    This setting must be turned on if your environment uses Entra ID conditional access.

  9. In the Test account user email address field, specify an email address to use to test the connection from BEMS to Microsoft Exchange Server or Microsoft Exchange Online.
  10. If your environment uses Microsoft Exchange Online, select the Use Microsoft Graph client check box. If your environment still uses Microsoft Exchange Web Services (EWS), when you assign the profile, BEMS will automatically migrate Microsoft 365 users to Microsoft Graph at a rate of 50 users every 5 minutes. Do the following to allow BEMS to communicate with Microsoft Graph to access user mailboxes:
    1. Select how you want the BEMS service account to authenticate with Microsoft Graph:
      • Client secret: Obtain the client secret and paste it in the Client secret field.
      • Client certificate: Browse to and select the client certificate (.pfx) and specify the certificate password in the Password field.
    2. In the Authentication authority field, specify the URL of the authentication server that BEMS will access to retrieve the OAuth token for authentication with Microsoft Graph.
    3. In the Client app ID field, specify the client app ID.
    4. In the Server name field, specify the FQDN for Microsoft Graph.
    5. In the Test account user email address field, specify an email address to use to test the connection from BEMS to Microsoft Graph.
  11. For Active Directory users and groups that use the PSO (Password Settings Object) method to set the maximum password age, you can configure BlackBerry Work to display a warning message when a user's Active Directory password is about to expire. This feature requires the BlackBerry Connectivity Node. To enable this feature, do the following:
    1. Select the Enable password expiry check box.
    2. Specify the LDAP server name (for example, ldap.<DNS_domain_name>), LDAP port, LDAP logon account (domain\username or UPN for Microsoft Exchange Server or <username>@<domain> for Microsoft Exchange Online), and LDAP logon password.
    3. In the Base DN (Domain controller) field, specify the base DN for LDAP search.
    4. If you want to route data through an SSL-encrypted connection, select the Enable SSL LDAP check box.

      This requires you to import the LDAP certificate into the BEMS keystore. For instructions, see Create a trusted connection between BEMS Cloud and Microsoft Exchange Server.

    5. In the Test account user email address field, specify an email address to use to test the connection to the LDAP server.
  12. Click Save. UEM completes the validation tests and saves the profile. If the validation tests fail, resolve the error message and save the profile again.
  • If you created more than one BlackBerry Dynamics Notification profile, rank the profiles. The ranking will be used to determine which profile will be applied to a user when conflicts occur from group assignment. Only one BlackBerry Dynamics Notification profile can be applied to a user. The assignment of a BlackBerry Dynamics Notification profile will outrank the default configuration from Settings > BlackBerry Dynamics > Email notifications. If a user is not assigned a BlackBerry Dynamics Notification profile, the default configuration is applied.
  • Assign the profile to users and groups. If a user has been added as a delegate to a Microsoft Exchange user's mailbox, make sure that the delegate and delegatee are assigned the same BlackBerry Dynamics Notification profile.