Obtain an Entra app ID for BlackBerry Work
- Sign in to entra.microsoft.com.
- In the left column, click Applications > App registrations.
- Click New registration.
- In the Name field, enter a name for the BlackBerry Work app. This is the name that users will see.
- Select a supported account type. Although Multitenant is supported, in most cases this should be Single tenant.
- In the Redirect URI drop-down list, select Public client (mobile & desktop) and enter: com.blackberry.work://connect/o365/redirect
- Click Register.
- If you enable Entra ID conditional access, perform the following actions:
- Click the Redirect URIs link (i.e. '0 web, 0 spa, 1 public client').
- In the Platform Type section, select the Mobile and desktop applications check box for the app that you registered.
- Click Add Redirect URL.
- Do any of the following:
Devices
Steps
- iOS
- macOS
- In the Select a platform to add redirect URI screen, click iOS/macOS.
- In the Bundle ID field, type com.good.gcs.g3.
- Click Configure.
Android
- In the Select a platform to add redirect URI screen, click Android.
- In the Package name field, type com.good.gcs.
- In the Signature hash field, type zRsXTl1cL/Seb6GumLzvoecPA8w=.
- Click Configure.
- In the left column, in the Manage section, click API permissions.
- Click Add a permission.
- In the Select an API section, click the Microsoft APIs tab.
- Do one or more of the following:
Environment Permissions If your environment is configured to use Microsoft 365
- Click Microsoft Graph. If Microsoft Graph is not listed, add Microsoft Graph.
- In delegated permissions, select the following permissions:
- Sign in and read user profile checkbox (User > User.Read)
- Send mail as a user checkbox (Mail > Mail.Send)
- Access mailboxes as the signed-in user via Exchange Web Services checkbox (EWS > EWS.AccessAsUser.All).
- Have full access to user calendars checkbox (Calendars > Calendars.ReadWrite)
- Read presence information of all users in your organization checkbox (Presence > Presence.Read.All)
- Click one of the following:
- If Microsoft Graph existed in the API permissions, click Update permissions.
- If you needed to add Microsoft Graph, click Create.
- Click Add permissions.
If your environment is configured to use Microsoft SharePoint Online or Entra-IP to enable modern authentication for the BlackBerry Work client
- Click the APIs my organization uses tab.
- Search for and click the BEMS app that you created in Obtain an Azure app ID for the BEMS-Docs component service. For example, AzureAppIDforBEMS.
- Select all delegated permissions.
- Click Delegated permissions.
- Click expand all. Make sure that all options are selected.
- Click Add permissions.
- Click Grant admin consent for <Organization name> to apply the permissions for the app. These settings will not be applied to the app until you have granted the updated permissions.
- Click Yes.
- You can now copy the Application ID for the app that you created. In the Manage section, click Overview. It is located under the name of the app, in the Application (client) ID field. You use the Application ID in the app configuration settings for BlackBerry Work. For more information about the app configuration, see BlackBerry Work app configuration settings.