Configure BEMS to communicate with a Microsoft Exchange Online environment using Microsoft Graph API

Before BEMS can send email notifications to users' devices, it must subscribe to changes on a user's mailbox. You can configure BEMS to subscribe to mailboxes using Microsoft Graph API. Microsoft Graph push notifications are sent (or pushed) from Microsoft 365 to the reverse proxy server to the BEMS instance. BEMS then accesses the user's mailbox and sends email notifications to the user's device. For more information, see Data flow: BEMS notification flow using the Microsoft Graph API. BEMS subscribes to the Microsoft Graph API change notifications using webhooks. You can configure BEMS to use the Microsoft Graph API in the following scenarios:
  • Your BEMS is configured to use modern authentication.
  • Your BEMS connects with Microsoft Exchange Online mailboxes.

If you have an existing BEMS instance that is configured to use Microsoft Exchange Web Services (EWS) for Exchange Online to access Microsoft 365 mailboxes, when you enable "Use Microsoft Graph", BEMS will automatically migrate all Microsoft 365 users from using EWS to Microsoft Graph at a rate of 50 users every 5 minutes.

For information on configuring email notifications for BlackBerry Work using BEMS Cloud, see the BlackBerry Work Administration content.

Verify that you obtained the following:
  1. In the BlackBerry Enterprise Mobility Server Dashboard, under BlackBerry Services Configuration, click Mail.
  2. Click Microsoft Graph.
  3. Select the Use Microsoft Graph check box.
  4. In the Select Authentication type section, select an authentication type based on your environment and complete the associated tasks to allow BEMS to communicate with Microsoft Exchange Online:

    Authentication type

    Description

    Task

    Client Certificate

    This option uses a client certificate to allow the BEMS service account to authenticate to Microsoft Exchange Online.

    1. For the Upload PFX file, click Choose File and select the client certificate file. For instructions on obtaining the .PFX file, see Associate a certificate with the Entra app ID for BEMS
    2. In the Enter PFX file Password field, enter the password for the client certificate.

    Client Secret

    This option uses a client secret to allow the BEMS service account to authenticate to Microsoft Exchange Online. The client secret is created during the application registration process.

    In the Client Secret field, enter the Client secret Value.

  5. In the Authentication Authority field, enter the Authentication Server URL that BEMS accesses and retrieve the OAuth token for authentication with Microsoft Exchange Online. The authentication server URL must be in the format of https://login.microsoftonline.com/tenantname or https://login.microsoftonline.com/tenantid.
  6. In the Client Application ID field, enter the Entra app.
  7. In the Server Name field, enter the FQDN of the Microsoft Graph server. By default, the field is prepopulated with https://graph.microsoft.com
  8. In the External Notification URL field, enter the URL that your IT provided. Enter https://<BEMS_server_name:port>/notificationClient (for example, bems.example.com:443/notificationClient). The External Notification URL is an externally routable address, such as a reverse proxy, where Graph will send the notifications. For more information, see the Port requirements in the BEMS Installation content.
  9. In the End User Email Address field, type an email address to test connectivity to Microsoft Exchange Online using the service account. Click Test. You can delete the email address after you complete the test.
  10. Click Save.
  11. Configure the Autodiscover and Exchange Options. For instructions see one of the following:
If you selected Client Certificate authentication, you can view the certificate information. Click Mail. The following certificate information is displayed:
  • Subject
  • Issuer
  • Validation period
  • Serial number