Create an activation profile

  1. In the management console, on the menu bar, click Policies and profiles > Policy > Activation.
  2. Click Add icon..
  3. Type a name and description for the profile.
  4. In the Number of devices that a user can activate field, specify the maximum number of devices that a user can activate.
  5. In the Device ownership drop-down list, select one of the following:
    • If some users activate personal devices and some users activate work devices, select Not specified.
    • If most users activate work devices, select Work.
    • If most users activate personal devices, select Personal.
  6. Optionally, in the Assign organization notice drop-down list, select an organization notice.
    If you assign an organization notice, users activating iOS, iPadOS, macOS, or Windows 10 devices must accept the notice to complete the activation process.
  7. In the Device types that users can activate section, select the device OS types that users can activate. This setting controls which OS tabs display and can be configured in the profile.
  8. For each device type that you include in the activation profile, perform the following actions:
    1. Click the tab for the device type.
    2. In the Device model restrictions drop-down list, select one of the following options:
      • No restrictions: Users can activate any device model.
      • Allow selected device models: Users can activate only the device models that you specify.
      • Do not allow selected device models: Users cannot activate the device models that you specify.

      If you restrict the device models that users can activate, click Edit to select the devices you want to allow or restrict and click Save.

    3. In the Minimum allowed version drop-down list, select the minimum allowed OS version.
    4. Select the supported activation types.

      For Android devices, you can select multiple activation types and rank them. For all other device types, you can select only one activation type.

      You must create separate activation profiles for Android Enterprise and Android Management. If Android Enterprise and Android Management activation types are specified in the same profile, the Android Management type will take precedence, even if it is ranked lower than Android Enterprise. Only the password and activation information for the Android Management activation type will be embedded in the QR Code.

  9. For iOS and iPadOS devices, perform the following actions:
    1. If you selected the User privacy activation type and you want to enable SIM-based licensing, select Allow access to SIM card and device hardware information to enable SIM-based licensing.
    2. If you selected the User privacy activation type and you want to manage specific features, select the appropriate check boxes.
    3. If you selected the MDM controls or User privacy (with SIM-based licensing) activation types and you only want to activate supervised devices, select Do not allow unsupervised devices to activate.
    4. If you selected the MDM controls activation type and you want to allow UEM to restrict activation by device ID, select Allow only approved device IDs. See Import or export a list of approved device IDs.
    5. If you have enabled BlackBerry Protect Mobile and you want to perform iOS app integrity checks, select one of the following attestation methods:
      • Perform app integrity check on BlackBerry Dynamics app activation: Use this method to send challenges to devices when they are activated to check the integrity of iOS work apps.
      • Perform periodic app integrity checks: Use this method to send challenges to devices to check the integrity of iOS work apps.
    6. Optionally, if you want to perform managed device attestation for iOS devices, in the Managed device attestation section, select one of the following attestation methods:
      • Perform Managed device attestation on device activation: Use this method to send challenges to devices when they are activated to check the integrity of the device properties.
      • Perform periodic Managed device attestation: Use this method to send challenges periodically to check the integrity of the device properties.

      Managed device attestation applies to the MDM controls and the User privacy activation types, but not the User privacy - User enrollment activation type. When you select the User privacy activation type, you must select at least one of the management options (such as "Allow VPN management").

  10. For iOS and macOS devices, if you want to use SCEP or ACME to send client certificates to devices, in the Identity certificate section, select the certificate type (SCEP or ACME).
    • If you selected SCEP, in the Key strength drop-down list, select the appropriate value.
    • If you selected ACME, in the RSA strength drop-down list, select the appropriate value.
  11. For Android devices, perform the following actions:
    1. If you selected more than one activation type, click the arrows to rank them. Devices receive the highest ranked profile that they support.
    2. If you selected a Samsung Knox activation type and you want to use Google Play to manage work apps, select Google Play app management for Samsung Knox Workspace devices. This option is available only if you have configured a connection to a Google domain.
      Samsung Knox activation types will be deprecated in a future release. Devices that support Knox Platform for Enterprise can be activated using the Android Enterprise activation types.
    3. If you selected an Android Enterprise activation type, select the appropriate Android Enterprise options:
      • To enable BlackBerry Secure Connect Plus and Knox Platform for Enterprise features (for devices that support Samsung Knox) on devices with an appropriate license, select When activating Android Enterprise devices, enable premium UEM functionality such as BlackBerry Secure Connect Plus.
      • To enable Samsung Knox DualDAR encryption for devices that support it, select Enable Samsung Knox DualDAR Workspace.
      • To allow Google Play app management in the work space, select Add Google Play account to work space.
      • To allow UEM to restrict activation by device ID, select Allow only approved device IDs. This option is supported only for Work space only and Work and personal - full control devices. See Import or export a list of approved device IDs.
      • To specify the network type that users can activate a device over, in the QR Code enrollment drop-down list, select a network. This option is supported only for Work space only and Work and personal - full control devices.
    4. Optionally, in the Play Integrity attestation options section, select one of the following attestation methods:
      • Perform Play Integrity attestation for device: Use this method to send challenges to test the authenticity and integrity of devices.
      • Perform Play Integrity attestation on BlackBerry Dynamics app activation: Use this method to send challenges to test the authenticity and integrity of BlackBerry Dynamics apps when they are activated.
    5. If you want UEM to send challenges to devices when they are activated to ensure the required security patch level is installed, in the Hardware attestation options section, select Enforce attestation compliance rules during activation.
  12. For macOS devices using Apple ADE, if you want UEM to set up a local administrator account on the device during activation (in addition to the primary user account), in the Account Configuration section, select the Enabled check box, then perform the following actions. The local administrator account is set up in the background during device activation. If the user wants to log in with the local administrator account, a UEM administrator can view the generated password in the user's device details in the management console and provide it to the user, or you can instruct the user to view the generated password in UEM Self-Service, if they are granted that permission. If you do not select this option, UEM sets up a primary user account only.
    1. By default, UEM sets up the primary user account as a standard user. If you want UEM to set up the primary user account as an administrator, in addition to the local administrator account that UEM creates, clear the Set primary setup account as regular user check box.
    2. If you want UEM to skip the creation of a primary user account, select the Skip primary setup account creation check box. If selected, UEM will create a local administrator account only.
    3. If you want UEM to set up the primary user account, select the desired option for populating the full name and user name:
      • If you do not want UEM to populate the full name and user name when setting up the primary user account, select the Don't auto populate primary account information check box. The user will be prompted for these values during the activation process.
      • If you want UEM to auto-populate the full name and user name values for the user, in the Primary account full name field, type the variable %UserDisplayName%, and in the Primary account user name field, type the variable %UserName%. If you do not want the user to be able to change these values during primary account setup, select the Lock primary account information check box.
    4. In the Managed local user short name field, type the variable %UserName%.
    5. In the Auto Setup Admin Account Item section, in the Full Name field, type Administrator. In the Short Name field, type Admin.
    6. If you want to hide the local administrator account from the list of accounts on the device, select the Hidden check box. A user can still log in with the credentials of the local administrator account.
    7. The password for the local administrator account on the device can be viewed in the UEM management console or in UEM Self-Service. In the Specify the number of minutes that a password is valid after it is viewed field, type how long, in minutes, the password for the local administrator account is valid after it is viewed in either console (default 60 minutes).
    8. If you want UEM to create the local administrator account only if the device is network-tethered, select the Request requires network tether check box.
  13. For Windows 10 devices, select one or both form factor options.
  14. Click Add.
  • If necessary, rank activation profiles.
  • Assign the profile to user accounts and groups.
  • After an Android Management or Android Enterprise device is activated, you can view the device password expiry date and the work profile password expiry date in the device details in the management console.