Enable smart card authentication

By default, end users authenticate on the mobile app by entering a username and password on the login screen. Administrators can also enable smart card authentication. When smart card authentication is enabled, when an operator starts the alert publishing, report summary, or accountability officer respond-on-behalf-of-others (ROBO) flows, a window appears to select a valid certificate. The certificate must already be present on the operator's device. When a valid certificate is selected, the operator can then complete the flow.

When smart card authentication is enabled, it becomes the primary authentication method. When the primary authentication type changes from username and password to smart card authentication or vice versa, any current access and refresh tokens expire and the operator must authenticate with the new primary authentication method when they access the alert publishing, report summary, or ROBO flows.

When smart card authentication is enabled, biometric authentication is disabled and the Face ID for alert publishing and reporting setting is not displayed on the Organization settings screen.

  1. In the navigation bar, click The Settings icon.
  2. On the Settings screen, in the Users section, click User Authentication.
  3. On the User Authentication screen, in the Enabled Authentication Methods section, select the Smart Card option.
  4. In the Assign Authentication Methods to Applications section, in the Mobile App section, select Smart Card from the Authentication Method drop-down list.
  5. Optionally, select ​​​​​​Username and Password​​​​ from the ​​​​​​Alternative Authentication Method​​​​ list to enable both Smart Card and Username/Password user authentication.
    If Username and Password is selected as an alternative authentication method, the user is redirected to the ​​​​​​BlackBerry AtHoc​​​​ management system to authenticate. If Username and Password is not selected as an alternative authentication method, the user is redirected to their smart card certificate to authenticate.
  6. Click Save.