Steps to migrate existing on-premises users to Microsoft Outlook Online using modern authentication

Step

Action


Step one icon

Configure modern authentication and validate that it is working correctly.


Step two icon

Create, edit, or copy an existing BlackBerry Dynamics Connectivity profile for the migrating users. Include the following information:
  • If the authentication server and Microsoft Exchange Online must be accessed through the internal network, add the appropriate hosts to the Additional servers section.
    Common Microsoft Exchange Online (Microsoft 365) hosts include the following:
    • aadcdn.msauth.net
    • Microsoft's Content Distribution servers (for example, aad.cdn.mstauth.net)
    • login.microsoftonline.com
    Common Microsoft Exchange Online hosts:
    • autodiscover-s.outlook.com
    • outlook.office365.com
  • If the authentication and Microsoft Exchange Online can be accessed using the Internet, you can improve performance by specifying “Direct” when you add the authentication server and Microsoft 365 servers to the Additional servers list. Note: If your Default route is set to Direct, this is not required.

For more information, see KB 64405.


Step 3 icon

Create a new BlackBerry Work app configuration with the modern authentication settings. The new app configuration must include the following:
  • Same settings as the original app configuration as well as the modern authentication settings
  • Select the "Enable Flow Enabled" checkbox and set the expiration date to allow users to send and receive email messages during the migration.
  • If your environment doesn't use Autodiscover, specify the ActiveSync Server and Exchange Web services URL endpoint fields.
  • If your environment is configured for Kerberos Constrained delegation or uses certificate-based authentication for the on-premises Microsoft Exchange Server, but not for the modern authentication endpoint, clear the Security settings "Use Kerberos Constrained Delegation in place of login/password" and "Use client certificate in place of login/password" checkboxes or users are prompted for credentials.

Step four icon

Assign the app configuration with the correct modern authentication settings to users. For instructions, see the content for your app:

Step five icon

Migrate user mailboxes from your on-premises Microsoft Exchange server to Microsoft Exchange Online.

After the migration completes, users receive a prompt to log in to their mailboxes. Wait while the BlackBerry Dynamics apps trigger autodiscover and connect to the new mailbox location. The amount of time this takes depends on how many users have been migrated and how often BlackBerry Work is opened. Refer to the Last Contact Time and container activity report to estimate whether users have received the new mailbox configuration from autodiscover.