Connect BlackBerry UEM to Cisco ISE

If you do not have a Cisco Identity Services Engine (ISE) administrator account, send these instructions to a Cisco ISE administrator, along with the required information about UEM and the UEM administrator account. For the latest Cisco ISE documentation, visit Cisco ISE Configuration Guides.
In a browser, navigate to https://<server_name>:<BlackBerry_Web_Services_port>/enterprise/admin/util/ws?wsdl where <server_name> is the FQDN of the computer that hosts the BlackBerry UEM Core component. The default <BlackBerry_Web_Services_port> value is 18084. Use your browser to export the BlackBerry Web Services certificate and save it to your desktop.
  1. Log in to the Cisco ISE management console.
  2. Import the BlackBerry Web Services certificate into the Cisco ISE trusted certificate store. Select the options to trust for client authentication and syslog, and to trust for authentication of Cisco services.
  3. Add an external MDM service and specify the details of the UEM instance, including the FQDN or IP address of the UEM domain, the port (default 18084), and the credentials of the UEM administrator account.
  4. For the polling interval, specify how often, in minutes, you want Cisco ISE to poll UEM for device data. It is a best practice to use the default value.
    If you set this value to 60 minutes or less, you might notice a significant performance impact on your organization’s environment. If you set this value to 0, Cisco ISE does not poll UEM.
  5. Enable and test the connection to UEM.
After the connection is established, you can view the dictionary attributes for UEM in the Cisco ISE management console. Log entries for Cisco ISE polling are written to the BlackBerry UEM Core (CORE) log file.
Perform the following configuration tasks in the Cisco ISE management console:
  • Configure ACLs on the wireless LAN controller.
  • Configure an authorization profile that will redirect devices to the BlackBerry UEM Self-Service console if they try to access the work network while the device is not activated on UEM. The user requires a UEM user account to log in to BlackBerry UEM Self-Service and activate the device. Instruct users to contact the UEM administrator when Cisco ISE directs them to the enrollment page.
  • Configure authorization policy rules that determine how Cisco ISE handles devices that are not activated on UEM or compliant with UEM.