Configure the Docs network and security settings
Docs
network and security settingsDocs
security settings control acceptable Microsoft
SharePoint Online
domains, the URL of the approved Microsoft Office Web Apps
(OWAS) and Office Online
Server, the appropriate LDAP domains to use, whether you want to use Kerberos constrained delegation for user authentication, and Entra
-IP authentication. Delegation allows a service to impersonate a user account to access resources throughout the network. Constrained delegation limits this trust to a select group of services explicitly specified by a domain administrator. Verify that one or more of the following are configured in your environment:
- Kerberos constrained delegation for theBlackBerry Docsservice is configured in your environment. For more information, see Configuring Kerberos constrained delegation for the Docs service.
- Resource-based Kerberos constrained delegation for theBlackBerry Docsservice is configured in your environment. For more information, see Configuring resource-based Kerberos constrained delegation for the Docs service.
- If your environment is configured to useEntra-IP, have the following information. For more information, see Obtain an Entra app ID for the Docs component service.
- EntraTenant Name
- BEMSServiceEntraApplication ID
- BEMSServiceEntraApplication Key
- Optionally, you can configureBEMSto allow users to authenticate toMicrosoft SharePoint Onlinewith an email address that is different from the email address that was used to install and activateBlackBerry Work. For more information, see Enable the use of an alternate email address to authenticate to the Docs service.
- In theBlackBerry Enterprise Mobility Server Dashboard, underBlackBerry Services Configuration, clickDocs.
- ClickSettings.
- To allowDocsto use Kerberos constrained delegation, select theEnable Kerberos Constrained Delegationcheck box.
- If your environment requires a separate account to administer KCD, select theUse Separate Credential for Kerberos Constrained Delegation for Microsoft SharePointcheck box and enter the required credentials.
- Separated by a comma, enter each of the Microsoft SharePoint Online domains you plan to make available. For more information, see Configuring support for Microsoft SharePoint Online and Microsoft OneDrive for Business.
- Enter the URL for your approved Office Web App or Office Online Server.
- Provide your Microsoft Active Directory user domains (separated by commas), then enter the correspondingLDAP Port. LDAP is used to look up users and their membership in user groups.
- Optionally, specify the timeout before theBEMSconnection attempt to the LDAP server times out. In theLDAP Connection Timeoutfield, increase or decrease the value, in seconds, as required. This setting is valid only ifUse SSL for LDAPis not enabled.
- Optionally, specify the timeout before theBEMSsearch for users and their membership in user groups times out. In theLDAP Search Timeoutfield, increase or decrease the value, in seconds, as required.
- To enable secure communication, select theUse SSL for LDAPcheck box.
- If your organization usesBlackBerry Workspaces, add theWorkspaces Public Key. Adding the public key allowsBEMSand theBlackBerry Workspacesserver to communicate with each other. For more information about locating the public key, contactBlackBerry Technical Support Services.
- To allowDocsto authenticate toEntra-IP, select theEnable Azure Information Protectioncheck box. Complete theAzure registrationfields to authenticateDocstoEntra-IP to allowDocsto decrypt protected documents and confirm the rights any given user has on a document.
- ClickSave.
If your environment has deployed
Entra
-IP Rights Management Services and uses a web proxy, configure Windows
with your proxy information, or BlackBerry Work
users will receive a permission error message when they attempt to access protected documents. For more information, see KB 139924.