Configure email notifications for BlackBerry Work
BlackBerry Work
BEMS
Cloud accepts push registration requests from devices, such as iOS
and Android
, and then communicates with the on-premises Microsoft Exchange
Server
or Microsoft Exchange
Online
to check the user's mailbox for changes. When you specify the on-premises Microsoft Exchange
Server
or Microsoft Exchange
Online
information, you specify the settings to create the BEMS
Cloud tenant for your organization.
When the tenant is created, the following services are automatically enabled:
- BlackBerry Directory Lookup: This service allows users to look up other users by first name, last name, and associated photo or avatar from the company directory.
- BlackBerryFollow-Me: This feature supports theBlackBerry Dynamics LauncheronBlackBerry Work.
A hybrid modern authentication environment (for example, on-premises
Microsoft Exchange
Server
and Microsoft Exchange
Online
), allows the on-premises Microsoft Exchange
Server
to use a more secure user authentication and authorization by consuming OAuth access tokens obtained from the cloud. For more information on how to configure an on-premises Microsoft Exchange
Server
to use hybrid modern authentication, see How to configure Exchange Server on-premises to use Hybrid Modern Authentication.Verify that you have the following information and completed the appropriate tasks.
- If you have a hybrid environment, and you enable Modern Authentication, make sure that the on-premisesMicrosoft Exchange Serveris configured to use hybrid modern authentication. For more information, see How to configure Exchange Server on-premises to use Hybrid Modern Authentication. If theMicrosoft Exchange Serveris not configured appropriately, users won't receive email notifications.
- In aMicrosoft Exchange Onlineenvironment, verify that you have enabled modern authentication, and completed the following:
- If you use client-certificate authentication, do one of the following:
- If you have configuredEntra IDconditional access for your organization, make sure that theBlackBerry Connectivity Nodeis installed and configured in your environment.
- Configure email notifications forBlackBerry Work
- In an on-premisesMicrosoft Exchangeenvironment, make sure that theMicrosoft Exchange Serveris updated to support TLS 1.2 or push notifications will fail. Weaker cipher suites such as TLSv1 or TLS 1.0 are disabled by default. Disabling the cipher suites provides enhanced security.
- If you use SSL for SCP lookup, verify that you exported theMicrosoft Active DirectorySSL certificate.
- In the management console, clickSettings > BlackBerry Dynamics > Email notifications.
- In theAuthentication typesection, select an authentication type based on your environment and complete the associated tasks to allowBEMSto communicate with theMicrosoft Exchange ServerorMicrosoft Exchange Online:The Passive authentication type has been deprecated due toMicrosoft's deprecation of the Application Impersonation permission inMicrosoft Exchange Onlineenvironments. To avoid email notifications for users in the environment, you must configureBEMSto use certificate-based authentication for modern authentication, orMicrosoft Graphto communicate to user's mailboxes. The passive authentication type will be removed in a future release. For more information, see BEMS: Customers using Office 365 and EWS with Credential or Passive Authentication will stop receiving notifications.Authentication typeDescriptionStepsCredentialThis option uses a definedBEMSusername and password to authenticate to the on-premisesMicrosoft Exchange Serverusing Basic authentication.
- In theService account usernamefield, enter the username of theBEMSservice account. Use the format <domain>\<username>.
- In theService account passwordfield, enter the password for the service account.
Client CertificateThis option uses a client certificate to allow theBEMSservice account to authenticate to theMicrosoft Exchange ServerorMicrosoft Exchange Online.- Beside theCertificate file (.pfx)field, clickBrowse. Navigate to and select the client certificate file.
- In thePasswordfield, enter the password for the client certificate.
- If you connect to aMicrosoft Exchange Onlineenvironment, you must enable and configure Modern Authentication. The "use Credentials if Modern authentication fails" option has been deprecated due toMicrosoft's deprecation of the Application Impersonation permission for users' mailboxes that are onMicrosoft Exchange Online, enabled for modern authentication, and configured to use credential or passive authentication methods. The option will be removed in a future release. Complete the following steps:
- Select theEnable Modern Authenticationcheck box.
- In theAuthentication authorityfield, enter the Authentication Server URL thatBEMSaccesses to retrieve the OAuth token for authentication withMicrosoft Exchange Online(for example, https://login.microsoftonline.com/tenantnameor https://login.microsoftonline.com/tenantid).
- In theClient application IDfield, enter the client app ID. For instructions, see Obtain the client application ID with certificate-based authentication.
- In theServer namefield, enter the FQDN of theMicrosoft Exchange Onlineserver (for example, https://outlook.office365.com).
- In theService account usernamefield, enter the username that is used to log in to theMicrosoft Exchange Server. The username must be in the format of <Domain>\<Username> or UPN.
- In theService account passwordfield, enter the password for the service account username you provided.
- Optionally, in theAutodiscover URL overridefield, enter the Autodiscover URL to allowBEMSto obtain user information from theMicrosoft Exchange ServerorMicrosoft Exchange Onlineserver when it discovers users forBlackBerry Push Notifications.If you don't enter a URL,BEMSuses Autodiscover to locate theMicrosoft Exchange ServerorMicrosoft Exchange Onlineserver to obtain user information.
- Select theAllow HTTP redirection and DNS SRV recordcheck box to allow HTTP Redirection and DNS SRV lookups for retrieving the Autodiscover URL when discovering users forBlackBerry Push Notifications. By default, this feature is enabled.
- Select theUse BlackBerry Connectivity Node routeto allowBEMSCloud to connect to theMicrosoft Exchange ServerorMicrosoft Exchange Onlineusing the corporate network rather than using a direct connection from theBlackBerryBEMSCloud infrastructure. This setting requires that theBlackBerry Connectivity Nodeis installed and configured in your environment. If your environment usesEntra IDconditional access, make sure that this option is selected.
- If your environment uses an internal URL to access and communicate with an on-premisesMicrosoft Exchange Server, select theUse internal Exchange Web Services URLcheck box. This setting requires that the "Use BlackBerry Connectivity Node route" setting is enabled. This option is not available if modern authentication is enabled.
- Optionally, select theEnable SCP Lookupcheck box to queryMicrosoft Active Directoryusing LDAP and locate Autodiscover endpoint URLs. This setting is valid only if the "Credential" authentication is selected and that aBlackBerry Connectivity Nodeis installed and configured in your environment. This option is not available when the "Autodiscover URL override" is specified.
- Select theEnable SSL for SCPcheck box. This allowsBEMSto communicate with theMicrosoft Active Directoryusing SSL. This setting requires that the "Enable SCP Lookup" is selected. If you enable this feature, you must add theMicrosoft Active DirectorySSL certificate to theBEMSCloud database. For information on how to add the certificate, see Create a trusted connection between BEMS Cloud and Microsoft Exchange Server.
- If you enabledEnable SCP LookuporEnable SCP LookupandEnable SSL for SCP, specify theDomain Controllers for SCPto configure LDAP over SCP. If you have multiple domain controllers, separate the domain controllers using commas (for example, domaincontroller1.example.com,domaincontroller2.example.com, and so forth).
- Optionally, in theUser email addressfield, enter an email address to test the connection to theMicrosoft Exchange ServerorMicrosoft Exchange Onlineserver. ClickTest connection. If the test fails, resolve the issues that are identified and try the test again. You can delete the email address after you complete the test.
- ClickSave.
- Assign the BlackBerry Cloud Enterprise Services (com.blackberry.gdservice-entitlement.cloud) entitlement to users to receive email notifications forBlackBerry Work. If the entitlement is not assigned, users will not receive email notifications. For instructions, see Managing apps in theBlackBerry UEMadministration content.