Skip Navigation

Android
: Enterprise connectivity profile settings

Setting
Description
Enable
BlackBerry Secure Connect Plus
This setting specifies whether work apps use
BlackBerry Secure Connect Plus
for sending work data between devices and your network.
Enterprise connectivity for
Android
devices with a work space
This setting specifies whether
Android Enterprise
and
Samsung Knox Workspace
devices use
BlackBerry Secure Connect Plus
for all apps in the work space, or only for specified apps.
  • "Container wide VPN" uses a VPN connection for all apps in the work space on the device.
  • "Per-app VPN" uses a VPN connection only for specified apps.
Apps restricted from using
BlackBerry Secure Connect Plus
This setting specifies apps in the work space on
Android Enterprise
devices that are not allowed to use
BlackBerry Secure Connect Plus
.
Click The Add icon and type the app package ID. Repeat as necessary to restrict additional apps.
By default,
Google Play
and underlying services (com.android.providers.media, com.android.vending, com.google.android.gms, and com.google.android.apps.gcs) are restricted because
Google Play
does not have proxy support. It is recommended to keep these restrictions in place. If you remove any of these restrictions, you must contact
Google Play
support for the firewall configuration required to allow connections to
Google Play
using
BlackBerry Secure Connect Plus
. By default, the packages are added to new enterprise connectivity profile, however you must add them to any existing profiles.
If the “Force work apps to only use VPN” IT policy rule is applied to the device, this setting is ignored and no work apps, including the
BlackBerry UEM Client
and
Google Play
are restricted from using BlackBerry Secure Connect Plus. In this case you will have to open ports in the firewall to allow the
BlackBerry UEM Client
to communicate with the
BlackBerry Infrastructure
through
BlackBerry UEM
. For more information about opening ports in the firewall when work apps use
BlackBerry Secure Connect Plus
, visit support.blackberry.com/community to read article 48330.
If your organization uses
BlackBerry Dynamics
apps, it is recommended that you restrict the apps from using
BlackBerry Secure Connect Plus
. If you don't, you must open additional ports in your organization’s firewall to allow the apps to send data to the
BlackBerry Dynamics NOC
, and network activity from the apps might be delayed because data is routed to both the
BlackBerry Infrastructure
and
BlackBerry Dynamics NOC
.
This setting is valid only if the "Enterprise connectivity for
Android
devices with a work space" setting is set to "Container wide VPN."
Apps allowed to use Enterprise Connectivity
This setting specifies apps in the work space on
Android Enterprise
and
Samsung Knox Workspace
devices that are allowed to use
BlackBerry Secure Connect Plus
. You can select apps from a list of available apps or specify the app package ID.
This setting is valid only if the "Enterprise connectivity for
Android
devices with a work space" setting is set to "Per-app VPN."
Proxy profile
If you want to route secure tunnel traffic from
Samsung Knox
devices with
Android Enterprise
activations and
Samsung Knox Workspace
2.5 and later devices to the work network through a proxy server, select the appropriate proxy profile.
This setting does not apply to
Android Enterprise
devices other than
Samsung Knox
devices or to devices with
Samsung Knox Workspace
version 2.4 and earlier.