Configure the Docs network and security settings
- Kerberos constrained delegation for the BlackBerry Docs service is configured in your environment. For more information, see Configuring Kerberos constrained delegation for the Docs service.
- Resource-based Kerberos constrained delegation for the BlackBerry Docs service is configured in your environment. For more information, see Configuring Kerberos constrained delegation for the Docs service.
- If your environment is configured to use Entra-IP, have the following information. For more information, see Obtain an Entra app ID for the Docs component service.
- Entra Tenant Name
- BEMS Service Entra Application ID
- BEMS Service Entra Application Key
- Optionally, you can configure BEMS to allow users to authenticate to Microsoft SharePoint Online with an email address that is different from the email address that was used to install and activate BlackBerry Work. For more information, see Enable the use of an alternate email address to authenticate to the Docs service.
- In the BlackBerry Enterprise Mobility Server Dashboard, under BlackBerry Services Configuration, click Docs.
- Click Settings.
- To allow Docs to use Kerberos constrained delegation, select the Enable Kerberos Constrained Delegation check box.
- If your environment requires a separate account to administer KCD, select the Use Separate Credential for Kerberos Constrained Delegation for Microsoft SharePoint check box and enter the required credentials.
- Separated by a comma, enter each of the Microsoft SharePoint Online domains you plan to make available. For more information, see Configuring support for Microsoft SharePoint Online and Microsoft OneDrive for Business.
- Enter the URL for your approved Office Web App or Office Online Server.
- Provide your Microsoft Active Directory user domains (separated by commas), then enter the corresponding LDAP Port. LDAP is used to look up users and their membership in user groups.
- Optionally, specify the timeout before the BEMS connection attempt to the LDAP server times out. In the LDAP Connection Timeout field, increase or decrease the value, in seconds, as required. This setting is valid only if Use SSL for LDAP is not enabled.
- Optionally, specify the timeout before the BEMS search for users and their membership in user groups times out. In the LDAP Search Timeout field, increase or decrease the value, in seconds, as required.
- To enable secure communication, select the Use SSL for LDAP check box.
- If your organization uses BlackBerry Workspaces, add the Workspaces Public Key. Adding the public key allows BEMS and the BlackBerry Workspaces server to communicate with each other. For more information about locating the public key, contact BlackBerry Technical Support Services.
- To allow Docs to authenticate to Entra-IP, select the Enable Azure Information Protection check box. Complete the Azure registration fields to authenticate Docs to Entra-IP to allow Docs to decrypt protected documents and confirm the rights any given user has on a document.
- Click Save.