Data flow: Activating a device to use Knox Workspace
- You perform the following actions:
- Add a user to BlackBerry UEM as a local user account or using the account information retrieved from your company directory
- Make sure the "Work and personal - full control (Samsung Knox)", "Work and personal - user privacy (Samsung Knox)", or "Work space only - (Samsung Knox)" activation type is assigned to the user
- Use one of the following options to provide the user with activation details:
- Automatically generate a device activation password and, optionally, a QR Code and send an email with activation instructions for the user
- Set a device activation password and communicate the username and password to the user directly or by email
- Don't set a device activation password and communicate the BlackBerry UEM Self-Service address to the user so that they can set their own activation password and view a QR Code.
- The user downloads and installs the BlackBerry UEM Client on the device. After it is installed, the user opens the BlackBerry UEM Client and enters the email address and activation password or scans the QR Code.
- The BlackBerry UEM Client performs the following actions:
- Establishes a connection to the BlackBerry Infrastructure
- Sends a request for activation information to the BlackBerry Infrastructure
- The BlackBerry Infrastructure performs the following actions:
- Verifies that the user is a valid, registered user
- Retrieves the BlackBerry UEM address for the user
- Sends the address to the BlackBerry UEM Client
- The BlackBerry UEM Client establishes a connection with BlackBerry UEM using an HTTP CONNECT call over port 443 and sends an activation request to BlackBerry UEM. The activation request includes the username, password, device operating system, and unique device identifier.
- BlackBerry UEM performs following actions:
- Inspects the credentials for validity
- Creates a device instance
- Associates the device instance with the specified user account in the BlackBerry UEM database
- Adds the enrollment session ID to an HTTP session
- Sends a successful authentication message to the device
- The BlackBerry UEM Client creates a CSR using the information received from BlackBerry UEM and sends a client certificate request to BlackBerry UEM over HTTPS.
- BlackBerry UEM performs the following actions:
- Validates the client certificate request against the enrollment session ID in the HTTP session
- Signs the client certificate request with the root certificate
- Sends the signed client certificate and root certificate back to the BlackBerry UEM Client
A mutually authenticated TLS session is established between the BlackBerry UEM Client and BlackBerry UEM.
- The BlackBerry UEM Client requests all configuration information and sends the device and software information to BlackBerry UEM.
- BlackBerry UEM stores the device information in the database and sends the requested configuration information to the device.
- The BlackBerry UEM Client determines if the device uses Knox Workspace and is running a supported version. If the device uses Knox Workspace, the device connects to the Samsung infrastructure and activates the Knox management license. After it is activated, the BlackBerry UEM Client applies the Knox MDM and Knox Workspace IT policy rules.
- The device sends an acknowledgment to BlackBerry UEM that it received and applied the configuration information. The activation process is complete.
After the activation is complete, the user is prompted to create a work space password for the Knox Workspace. Data in the Knox Workspace is protected using encryption and a method of authentication such as a password, PIN, pattern, or fingerprint.