Provisioning roles using Active Directory

You can assign BlackBerry Workspaces roles to users who belong to Microsoft Active Directory groups.

Workspaces owners and administrators can define groups based on Active Directory Security groups. Workspaces maintains an association between the BlackBerry Workspaces group and the Active Directory group.

Workspaces owners can share workspaces with groups created from Active Directory in the same way they share workspaces with Workspaces groups. Permissions can be assigned to these groups in the same way they are assigned to Workspaces groups.

When an Active Directory user attempts to access a workspace on the BlackBerry Workspaces Server, Workspaces queries the Active Directory server for all the Active Directory groups the user is a member of. Workspaces then checks whether any of these Active Directory groups are associated with Workspaces groups that permit the requested access. If a match is found, access is permitted. The user sees only those workspaces or folders that can be seen by the Workspaces groups associated with their Active Directory Security groups.

To improve performance, BlackBerry Workspaces caches the query response from Active Directory for a particular user for one hour. Subsequent queries check the cache first. If the information is no longer in the cache, the query will go to the Active Directory server.

Metadata about Active Directory groups, such as name and description, is updated on the associated BlackBerry Workspaces groups once per day.

BlackBerry Workspaces Exchange users can send emails with secured attachments to Active Directory Distribution Groups. They cannot send to Active Directory Security groups or to the Active Directory Domain Group (of all users). Permissions for recipients of emails to access the secure attachments are those that are explicitly set in the email or the default permissions for sending emails (for the sender). BlackBerry Workspaces uses Active Directory, as an address book to obtain the email addresses of all members of the Active Directory Distribution Group.