Configure an Active Directory connection
- For BlackBerry Workspaces Server on-premises environments, verify tha you are using a valid signed certificate for Active Directory FQDN. If you are using a self-signed certificate, contact support for help to manually importing the root and intermediate certificates to the server.
- For cloud environments that connect to a local Active Directory server, verify that you have a valid signed certificate.
- In the left pane, click Roles by Active Directory.
- Do one of the following:
- If this is your first Active Directory connection in your organization, proceed to step 3.
- If you already have a configured connection, click
>
.
- Select Enable provisioning of Active Directory Users and Groups, and specify the following settings:
- Expose Active Directory Users with the following email domains: Type the names of domains of users who will be able to query the Active Directory.
- Active Directory Server Addresses: Type up to three IP addresses of the Active Directory Domain Controller servers. If your environment uses LDAPS, you must include the protocol (for example, ldaps://myDomainController).
- Port: Type the port of the Active Directory server. The default value is 389 (LDAP port).
- Base DN: Type the base Distinguished Name in the Active Directory tree that will be exposed to the Workspaces Server. Use this setting if only part of the Active Directory tree will be accessible to the Workspaces Server).
- Username to connect to Active Directory: Type the username that the Workspaces Server uses to connect to Active Directory.
- Password to connect to Active Directory: Type the password for the above user.
- This is a global catalog server: Select this option if the server is a global catalog server. When you enable this option, make sure that the server port matches the global catalog port (3268 by default).
- Click Apply to test the parameters against the server to verify the connection.
- To add additional Active Directory connections, repeat steps 3 and 4. You can create multiple connections to the same Active Directory server (each connection must connect to different parts of the tree) or connections to multiple Active Directory servers.
- To verify a connection, click Verify.