Configure RSA SecurID soft token authentication
BlackBerry Work
for iOS
and Android
devices supports RSA SecurID soft token authentication. The software consists of an app and a separately installed, software-based security token that transfers password protection to BlackBerry Work
. BlackBerry Work
contains an embedded RSA SecurID authenticator that can generate and display a 6-digit or 8-digit token code at 30 and 60 second intervals.
To use the RSA SecurID software token app for authentication,
BlackBerry Work
must be configured to support RSA token import using the Compressed Token Format (CTF) URL.- Verify that the RSA SecurID Software Token app is installed on the device. If the RSA SecurID app is not installed, the device OS displays an error or redirects the user to theAppleApp StoreorGoogle PlayStore.
- Verify that you have provisioned the RSA SecurID software token for the user.
- Verify the URL scheme for your users’ devices:
- iOSandiPadOSdevices: com.rsa.securid://ctf/?ctfData=TOKENDATAIn the steps below, you will send a SDTID file to users’ devices.
- Androiddevices: http://127.0.0.1/securid/ctf?ctfData=TOKENDATAIn the steps below, you will send the seed record token data to users' devices. If you have a SDTID file, you must convert it to a CTF format. For more information, see RSA SecurID Software Token Converter Documentation.
- In theBlackBerry UEMmanagement console, on the menu bar, clickApps.
- Search for and clickBlackBerry Work.
- On theBlackBerry Dynamicstab, in theApp configurationtable, click the app configuration that you want to edit.
- On theInteroperabilitytab, complete one of the following tasks:TaskStepsSend the SDTID file as an attachment (iOSandiPadOSonly)
- In theFile Handlingsection, select theEnable exporting to 3rd-party native appscheck box.
- In the drop-down list, selectAllow exporting only to these apps.
- In theEnter App IDfield, enter the RSA SecurID Software Token app ID.
- Send the SDTID file to your users.
- Request users to open the email in theBlackBerry Workapp, tap the RSA token attachment, and follow the on-screen prompts to complete the authentication process.
Send the seed record token data in a clickable link in the email body (iOS,iPadOS, andAndroid)- In theLaunch 3rd party appsection, select theEnable integration with 3rd party RSA SecurID app using CTF token seedcheck box.
- Send the seed record to your users. The seed record must be in a CTF URL format. See theBefore you beginsection above to verify that you are using the appropriate URL scheme for your users' devices.
- Request users to open the email in theBlackBerry Workapp, tap the RSA token link, and follow the on-screen prompts to complete the authentication process.