Data flow: Activating an Android Enterprise Work space only device using a managed Google Play account
This data flow applies when you allow BlackBerry UEM to manage Google Play accounts.
- You perform the following actions:
- Add a user to BlackBerry UEM as a local user account or using the account information retrieved from your company directory.
- Make sure that the "Work space only” activation type is assigned to the user.
- Set the user's activation password.
- The user resets their device to the factory default settings.
- The device restarts and prompts the user to select a Wi-Fi network and to add an account.
- The user enters their Google credentials.
- The device performs the following actions:
- If the device is not encrypted, prompts the user to encrypt the device and restarts
- Downloads the BlackBerry UEM Client from Google Play and installs it
- The BlackBerry UEM Client on the device prompts the user to type their email address and activation password.
- The user types their email address and activation password or scans the QR Code.
- The BlackBerry UEM Client performs the following actions:
- Establishes a connection to the BlackBerry Infrastructure
- Sends a request for activation information to the BlackBerry Infrastructure
- The BlackBerry Infrastructure performs the following actions:
- Verifies that the user is a valid, registered user
- Retrieves the BlackBerry UEM server address for the user
- Sends the server address to the BlackBerry UEM Client
- The BlackBerry UEM Client establishes a connection with BlackBerry UEM using an HTTP CONNECT call over port 443 and sends an activation request to BlackBerry UEM. The activation request includes the username, password, device operating system, and unique device identifier.
- BlackBerry UEM performs the following actions:
- Determines the activation type assigned to the user account
- Connects to Google and creates a managed Google Play user
- Creates a device instance
- Associates the device instance with the specified user account
- Adds the enrollment session ID to an HTTP session
- Sends the user's managed Google Play account information and a successful authentication message to the device
- The BlackBerry UEM Client performs the following actions:
- Connects to Google to verify the user
- Creates a CSR using the information received from BlackBerry UEM and sends a client certificate request to BlackBerry UEM over HTTPS
- BlackBerry UEM performs the following actions:
- Validates the client certificate request against the enrollment session ID in the HTTP session
- Signs the client certificate request with the root certificate
- Sends the signed client certificate and root certificate back to the BlackBerry UEM Client
A mutually authenticated TLS session is established between the BlackBerry UEM Client and BlackBerry UEM.
- The BlackBerry UEM Client requests all configuration information and sends the device and software information to BlackBerry UEM.
- BlackBerry UEM stores the device information in the database and sends the requested configuration information to the device.
- The device sends an acknowledgment to BlackBerry UEM that it received and applied the configuration information. The activation process is complete.