Configure BlackBerry Tasks and BlackBerry Notes app settings

BlackBerry Tasks and BlackBerry Notes use Microsoft Exchange Web Services and do not use Exchange ActiveSync like BlackBerry Work. This means that BlackBerry Tasks and BlackBerry Notes may have different authentication configurations than BlackBerry Work.

Depending on your environment, if your users are configured with UPNs that are different from their email address, you might need to enable the "Use explicit UPN" property. For more information, see BlackBerry Dynamics global properties.
  1. On the menu bar, click Apps.
  2. Click the BlackBerry Notes or BlackBerry Tasks app.
  3. On the BlackBerry Dynamics tab, in the App configuration table, click The Add icon.
  4. Type a name for the app configuration.
  5. For the BlackBerry Tasks app only, on the Notifications tab, in the Select level or detail in Tasks reminders drop-down list, select whether to turn off task notifications on the user's device, to display a generic notification, or to display the title of the task in the notification.
  6. On the Configurations Settings tab, in the Security Settings section, configure the following settings:
    1. Select the Use of Kerberos Constrained Delegation in place of login/password option to use Kerberos Constrained Delegation as the login type for users. When Kerberos Contrained Delegation is used, users do not have to enter a password for Exchange ActiveSync.
    2. Select the Use client certificate in place of login/password option to require the use of certificates for login instead of a username and password. This is a requirement if certificate-based authentication is required for Microsoft Exchange Web Services.
  7. In the Embedded Hyperlink Support drop-down list, select the allowed behavior when a user opens a hyperlink.
  8. In the Enterprise Mobility Server section, configure the following:
    1. In the Server List Reshuffle Period (minutes) field, specify the frequency that the BEMS server list is reshuffled (if present), for load balancing purposes. The default setting is 10 minutes.
    2. In the Server List Quarantine Period (minutes) field, if a BEMS server is not working, BlackBerry Tasks will wait this period before it retries. The default setting is 10 minutes.
  9. On the Exchange Settings tab, configure the following:
    1. In the Exchange Web Services Authentication Methods (iOS only) section, choose the authentication methods to be used: Negotiate, NTLM, or Basic. If only certain authentication methods are supported from Microsoft Exchange, set those values to minimize the user setup time. (For example, if the EWS IIS Auth Setting is set to allow only NTLM, then select only NTLM above for an optimal setup experience.) If none are selected above, the default Microsoft Exchange setting will be used.
    2. In the Microsoft Exchange Settings section, in the Exchange Domain field, specify the default Windows NT domain that BlackBerry Tasks will try to connect to automatically when users log in to BlackBerry Notes or BlackBerry Tasks. If your server uses newer UPN (email@host.com) style login instead of the older (domain\user) style login, leave this field blank. In the Exchange Server field, specify the FQDN of the server, CAS Array, or Load Balancer that is responsible for providing Microsoft Exchange Web Services. If you leave this field blank, BlackBerry Notes or BlackBerry Tasks uses assisted autodiscover through BEMS if BEMS is configured, and if BEMS is listed in the application server list for BlackBerry Notes or BlackBerry Tasks. Enter only the FQDN of the Microsoft Exchange server. Do not include a protocol prefix such as https:// or a URI suffix.
  10. On the Exchange settings tab, configure the following settings:
    1. In the Exchange Web Services User Name Formats (iOS only) section, choose which of the following user name formats to use to authenticate with Microsoft Exchange Web Services: UPN, Domain\UserId, or SMTP. If only certain user name formats are supported from Microsoft Exchange, set those values to minimize the user setup time. (For example, if the EWS Auth Settings are set to allow only SMTP but not UPN, then deselect UPN in the app setting.) If none are selected above, authentication with all user name formats will be attempted.
    2. In the TLS Certificate Settings section, specify the user credential profile that contains the TLS certificate to be used to connect to Microsoft Exchange. The name of the profile that you specify here must match the name of the user credential profile that was created in the BlackBerry UEM management console. For more information on user credential profiles, see Sending client certificates to devices and apps using user credential profiles.
  11. In the Microsoft Office 365 Modern Auth Settings (Beta) section, configure options for Microsoft 365. If selected, specify the following:
    1. Select the Use Office 365 Modern Authentication option to use modern authentication instead of basic authentication. Modern authentication enables BlackBerry Notes and BlackBerry Tasks to use sign-in features such as Multi-Factor Authentication, SAML-based third-party Identity Providers, and smart card and certificate-based authentication.
    2. In the Office 365 Sign On URL field, specify the web address that BlackBerry Notes or BlackBerry Tasks should use when signing in to Office 365. If you do not specify a value, BlackBerry Notes or BlackBerry Tasks will use https://login.microsoftonline.com during setup.
    3. In the Office 365 Tenant ID field, specify the tenant ID of the Microsoft 365 server that you want BlackBerry Notes or BlackBerry Tasks to connect to during setup.
    4. In the Azure App ID field, specify the Microsoft Entra ID app ID for BlackBerry Notes or BlackBerry Tasks. For information on how obtain an Entra app ID, see Obtain an Azure app ID for BlackBerry Work.
    5. In the Office 365 Resource field, specify the URL of the Microsoft Exchange Online server.
    6. In the Redirect URI field, specify the URI that you entered in the Microsoft Entra ID portal.
    7. Select the Proxy Modern Authentication requests ( only) setting to force all Office 365 Modern Authentication requests to go through the BlackBerry Proxy instead of connecting directly to the Internet.
  12. In the Exchange User Name section, select UPN to use a UPN user name format instead of SMTP when authenticating with Microsoft Exchange.
  13. On the App Settings tab, configure the following:
    1. Select the Enable DLP Watermark option to display a user’s username and the date and time as a watermark on all screens in BlackBerry Notes or BlackBerry Tasks.
    2. Select the Allow users to perform app diagnostics option, to allow users to generate a diagnostics report and then email the results to their administrator.
  14. For BlackBerry Notes only, select the Store the Title of the Notes in the Note body option to save the note title with the note body. This option requires Microsoft Exchange 2016 or later.
  15. On the Interoperability tab, configure the following:
    1. For BlackBerry Tasks for iOS and BlackBerry Notes for iOS only, select the Tap a phone number to dial using native phone option to allow users to tap a phone number to dial using the device's native phone.
  16. On the Attachments tab, configure the following:
    1. Specify whether to allow incoming and outgoing attachments.
    2. Specify the maximum size.
    3. Specify the file extensions that are allowed or disallowed.
  17. On the Deprecated tab, select the Disable SSL Certificate Checking option to disable SSL certificate verification for Microsoft Exchange Web Services servers in test environments.
  18. Click Save.