Configure email notifications for BlackBerry Work

BEMS Cloud accepts push registration requests from devices, such as iOS and Android, and then communicates with the on-premises Microsoft Exchange Server or Microsoft Exchange Online to check the user's mailbox for changes. When you specify the on-premises Microsoft Exchange Server or Microsoft Exchange Online information, you specify the settings to create the default BEMS tenant for your organization.
When the default tenant is created, the following services are automatically enabled:
  • BlackBerry Directory Lookup: This service allows users to look up other users by first name, last name, and associated photo or avatar from the company directory.
  • BlackBerry Follow-Me: This feature supports the BlackBerry Dynamics Launcher on BlackBerry Work.

A hybrid modern authentication environment (for example, on-premises Microsoft Exchange Server and Microsoft Exchange Online), allows the on-premises Microsoft Exchange Server to use a more secure user authentication and authorization by consuming OAuth access tokens obtained from the cloud. For more information on how to configure an on-premises Microsoft Exchange Server to use hybrid modern authentication, see How to configure Exchange Server on-premises to use Hybrid Modern Authentication.

Verify that you have the following information and completed the appropriate tasks.
  1. In the management console, click Settings > BlackBerry Dynamics > Email notifications.
  2. In the Authentication type section, select an authentication type based on your environment and complete the associated tasks to allow BEMS to communicate with the Microsoft Exchange Server or Microsoft Exchange Online:
    Note: The Passive authentication type has been deprecated due to Microsoft's deprecation of the Application Impersonation permission in Microsoft Exchange Online environments. To avoid email notifications interruptions for users in the environment, you must configure BEMS to use certificate-based authentication for modern authentication, or Microsoft Graph to communicate to user's mailboxes. The passive authentication type will be removed in a future release.

    Authentication type

    Description

    Steps

    Credential

    This option uses a defined BEMS username and password to authenticate to the on-premises Microsoft Exchange Server using Basic authentication.

    1. In the Service account username field, enter the username of the BEMS service account. Use the format <domain>\<username>.
    2. In the Service account password field, enter the password for the service account.

    Client Certificate

    This option uses a client certificate to allow the BEMS service account to authenticate to the Microsoft Exchange Server or Microsoft Exchange Online.

    1. Beside the Certificate file (.pfx) field, click Browse. Navigate to and select the client certificate file.
    2. In the Password field, enter the password for the client certificate.
  3. If you connect to a Microsoft Exchange Online environment, you must enable and configure Modern Authentication. The "use Credentials if Modern authentication fails" option has been deprecated due to Microsoft's deprecation of the Application Impersonation permission for users' mailboxes that are on Microsoft Exchange Online, enabled for modern authentication, and configured to use credential or passive authentication methods. The option will be removed in a future release. Complete the following steps:
    1. Select the Enable Modern Authentication check box.
    2. In the Authentication authority field, enter the Authentication Server URL that BEMS accesses to retrieve the OAuth token for authentication with Microsoft Exchange Online (for example, https://login.microsoftonline.com/tenantname or https://login.microsoftonline.com/tenantid).
    3. In the Client application ID field, enter the client app ID. For instructions, see Obtain the client application ID with certificate-based authentication.
    4. In the Server name field, enter the FQDN of the Microsoft Exchange Online server (for example, https://outlook.office365.com).
  4. In the Service account username field, enter the username that is used to log in to the Microsoft Exchange Server . The username must be in the format of <Domain>\<Username> or UPN.
  5. In the Service account password field, enter the password for the service account username you provided.
  6. Optionally, in the Autodiscover URL override field, enter the Autodiscover URL to allow BEMS to obtain user information from the Microsoft Exchange Server or Microsoft Exchange Online server when it discovers users for BlackBerry Push Notifications.
    Note: If you don't enter a URL, BEMS uses Autodiscover to locate the Microsoft Exchange Server or Microsoft Exchange Online server to obtain user information.
  7. Select the Allow HTTP redirection and DNS SRV record check box to allow HTTP Redirection and DNS SRV lookups for retrieving the Autodiscover URL when discovering users for BlackBerry Push Notifications. By default, this feature is enabled.
  8. Select the Use BlackBerry Connectivity Node route to allow BEMS Cloud to connect to the Microsoft Exchange Server or Microsoft Exchange Online using the corporate network rather than using a direct connection from the BlackBerry BEMS Cloud infrastructure. This setting requires that the BlackBerry Connectivity Node is installed and configured in your environment. If your environment uses Entra ID conditional access, make sure that this option is selected.
  9. If your environment uses an internal URL to access and communicate with an on-premises Microsoft Exchange Server, select the Use internal Exchange Web Services URL check box. This setting requires that the "Use BlackBerry Connectivity Node route" setting is enabled. This option is not available if modern authentication is enabled.
  10. Optionally, select the Enable SCP Lookup check box to query Microsoft Active Directory using LDAP and locate Autodiscover endpoint URLs. This setting is valid only if the "Credential" authentication is selected and that a BlackBerry Connectivity Node is installed and configured in your environment. This option is not available when the "Autodiscover URL override" is specified.
  11. Select the Enable SSL for SCP check box. This allows BEMS to communicate with the Microsoft Active Directory using SSL. This setting requires that the "Enable SCP Lookup" is selected. If you enable this feature, you must add the Microsoft Active Directory SSL certificate to the BEMS Cloud database. For information on how to add the certificate, see Create a trusted connection between BEMS Cloud and Microsoft Exchange Server.
  12. If you enabled Enable SCP Lookup or Enable SCP Lookup and Enable SSL for SCP, specify the Domain Controllers for SCP to configure LDAP over SCP. If you have multiple domain controllers, separate the domain controllers using commas (for example, domaincontroller1.example.com,domaincontroller2.example.com, and so forth).
  13. Optionally, in the User email address field, enter an email address to test the connection to the Microsoft Exchange Server or Microsoft Exchange Online server. Click Test connection. If the test fails, resolve the issues that are identified and try the test again. You can delete the email address after you complete the test.
  14. Click Save.
Assign the BlackBerry Cloud Enterprise Services (com.blackberry.gdservice-entitlement.cloud) entitlement to users to receive email notifications for BlackBerry Work. If the entitlement is not assigned, users will not receive email notifications. For instructions, see Managing apps in the BlackBerry UEM administration content.