Prerequisites: BlackBerry Push Notifications service

Microsoft Graph push notifications are sent (or pushed) from Microsoft 365 to the reverse proxy server to the BEMS instance. BEMS then accesses the user's mailbox and sends email notifications to the user's device.

If you deploy BEMS in a mixed environment, where BEMS and Microsoft Exchange are not co-located, there are additional requirements and prerequisites which may apply. Consider the following scenarios:

Scenario

Tasks

Cloud-based BEMS with on-premises Microsoft Exchange

  1. Do one of the following:
    • Expose Microsoft Exchange Web Services and Autodiscover from your on-premises Microsoft Exchange to the Internet on port 443.
    • Install the BlackBerry Connectivity Node and enable "Use BlackBerry Connectivity Node route". For more information, see Configure email notifications for BlackBerry Work.
  2. Basic Authentication, modern authentication, and certificate-based authentication are supported for Microsoft Exchange Web Services and Autodiscover.

On-Premises BEMS with Microsoft Exchange Online

  1. You must expose Microsoft Exchange Web Services and autodiscover from Microsoft Exchange Online to on-premises BEMS on port 443.
  2. BEMS supports Modern Authentication and Microsoft Graph.

Hybrid environment (On-premises BEMS with on-premises Microsoft Exchange and Microsoft Exchange Online)

  1. You must expose Microsoft Exchange Web Services and autodiscover from Microsoft Exchange Online to on-premises BEMS on port 443.
  2. BEMS supports the following:
    • On-premises Microsoft Exchange: Both Basic Authentication and Windows authentication are supported for Microsoft Exchange Web Services and Autodiscover.
    • Cloud-based Microsoft Exchange: Modern Authentication and Microsoft Graph.
  3. The BEMSAdmin account must have impersonation rights on the on-premises Microsoft Exchange. For more information, see Grant application impersonation permission to the service account.