Create a local group

You can create a local user group in BlackBerry UEM that you can assign IT policies, profiles, and apps to. When you add user accounts to the group, the properties that you assign to the group are assigned to each member of the group. You can add both local user accounts and directory user accounts to a local group.

  1. In the management console, on the menu bar, click Groups > User.
  2. Click Local group icon..
  3. Type a name and a description for the group.
  4. Do any of the following:

    Task

    Steps

    Assign a user role to the local group.

    1. In the User role section, click Add icon..
    2. In the drop-down list, click the name of the user role that you want to assign to the group.
    3. Click Add.

    Assign an IT policy or profile to the local group.

    1. In the IT policy and profiles section, click Add icon..
    2. Click IT policy or a profile type.
    3. In the drop-down list, click the name of the IT policy or profile that you want to assign to the group.
    4. Click Assign.
  5. If you want to assign an app or app group to the local group, do the following:
    1. In the Assigned apps section, click Add icon..
    2. Search for and select the app or app group that you want to assign.
    3. Click Next.
    4. In the Disposition drop-down list, select one of the following:
      • Required: Install the app automatically on devices and prevent users from uninstalling the app.
      • Optional: Allow users to install and uninstall the app.
      • Denied (Android only): Prevent users from installing the app.
    5. If you are assigning a Google Play app to Android Enterprise and Android Management devices, and you set the Disposition to required or optional, in the Update Mode drop-down list, click the appropriate option:
      • Default: When a new version of the app is available in Google Play, the device is notified. Any restrictions or conditions from an assigned device SR requirements profile are applied to the app update.
      • High Priority: When a new version of the app is available in Google Play, the device is notified. Any restrictions or conditions from an assigned device SR requirements profile are ignored. In larger deployments this can take up to 24 hours.
      • Postpone: When a new version of the app is available in Google Play, the device is notified after 90 days, then the update is applied using the latest available version. Any restrictions or conditions from an assigned device SR requirements profile are applied. Note that users can manually update the app at any time.
    6. If you are assigning an Apple VPP app for iOS or macOS, and you set the Disposition to required or optional, in the Update Mode drop-down list, click the appropriate option:
      • Default: When a new version of the app is available, it will be pushed to devices automatically.
      • Postpone: When a new version of the app is available, it will not be pushed to devices automatically.
    7. For iOS devices, to assign per-app VPN settings to an app or an app group, in the Per app VPN drop-down list, select the settings to associate with the app or app group.
    8. If you assign an iOS or macOS app, choose the appropriate value in the Target drop-down list:
      • Work: The app is installed as a work app that you manage with UEM.
      • Personal:
        • If it is not a VPP app, the app is managed by UEM and a “personal” label is associated with the assigned app in the management console. The personal label does not impact how the app is managed on devices.
        • If it is an iOS or macOS VPP app with the Disposition set to Optional, the user will be redirected to the App Store to install the app as unmanaged. Unmanaged apps cannot be removed from devices by UEM and are not subject to UEM controls such as IT policy rules. When you set the app assignment as Optional and Personal, when you are prompted to assign the appropriate VPP license (step l below), you must set “Assign license to” to “User” to make it an unmanaged app.
    9. If available, for iOS and Android devices, in the App configuration drop-down list, click the app configuration that you want to assign to the app.
    10. If you use Android Enterprise and have created tracks for apps in the Google Play console, in the Track drop-down list, click the track to assign to the app.
    11. Click Assign or Next.
    12. If you are assigning a VPP app, click Yes to assign a user license or device license to the app. In the App license drop-down list, click the appropriate VPP account. In the Assign license to drop-down list, click User or Device. When you set the app assignment as Optional and Personal, you must assign a user license to make it an unmanaged app.
  6. Click Add.