Configure single sign-on for BlackBerry Dynamics apps in BlackBerry UEM
You can enable single sign-on for BlackBerry Dynamics apps in an environment that's already set up for Microsoft 365 with Microsoft Active Directory Federation Services and single sign-on.
Before you begin, make sure that you have configured the following:
- Configure single sign-on in Office 365 with Active Directory Federation Services version 2.0 or 3.0, relying on Windows Authentication and Kerberos.
- Configure BlackBerry UEM for Kerberos constrained delegation.
-
Verify the SPN for Active Directory Federation Services. For Active Directory Federation Services to use Kerberos, the Active Directory Federation Services service must have registered an SPN. This SPN should already be registered by the prerequisite Active Directory Federation Services configuration in Office 365.
-
Enable the User Agent in Active Directory Federation Services. By default, Active Directory Federation Services allows only known user agents to use Windows Authentication. All other user agents are considered external and are served with Forms Based Authentication (FBA) or certificate authentication.
-
Set delegation on the Kerberos account.
- Log in to BlackBerry UEM.
- Click Settings > BlackBerry Dynamics > Properties.
- Scroll to find the value of the gc.krb5.principal.name property. Set this object name in Microsoft Active Directory.
- On your Microsoft Active Directory server, click the Delegation tab.
- Click ADD and enter the Active Directory Federation Services service account name that you discovered in step 1.
- Add the HTTP SPN.
- Click OK.