Skip Navigation

Enable and configure onboarding and offboarding

You can automatically onboard users that are members of universal and global groups. Onboarding is not supported for domain local groups.
  • Verify that a company directory synchronization is not in progress. You cannot save the changes you make to the company directory connection until the synchronization is complete.
  • To onboard members of global groups, you must enable support for global groups in your Microsoft Active Directory connection settings.
  1. On the menu bar, click
    Settings > External integration > Company directory
    .
  2. Click the company directory name that you want to edit.
  3. On the
    Sync settings
    tab, select the
    Enable directory-linked groups
    check box.
  4. Select the
    Enable onboarding
    check box.
  5. Perform the following actions for each group that you want to configure for onboarding with a device activation option:
    1. Click The add icon.
    2. Type a company directory group name. Click The search icon.
    3. Select the group. Click
      Add
      .
    4. Optionally, select
      Link nested groups
      .
    5. In the
      Device activation
      section, select whether you want onboarded users to receive an autogenerated activation password or no activation password. If you select the autogenerated password option, configure the activation period and select an activation email template.
  6. To onboard users with
    BlackBerry Dynamics
    , select the
    Onboard users with BlackBerry Dynamics apps only
    check box.
  7. Perform the following actions for each group that you want to onboard with activation for
    BlackBerry Dynamics
    apps only:
    1. Click The Add icon.
    2. Type a company directory group name. Click The search icon.
    3. Select the group. Click
      Add
      .
    4. Optionally, select
      Link nested groups
      .
    5. Select the number of access keys to generate per user added, the access key expiration, and the email template.
  8. To delete device data when a user is offboarded, select the
    Delete device data when the user is removed from all onboarding directory groups
    check box. Select one of the following options:
    • Delete only work data
    • Delete all device data
    • Delete all device data for corporate owned/delete only work data for individually owed
  9. To delete a user account from
    BlackBerry UEM
    when a user is removed from all onboarding groups, select
    Delete user when the user is removed from all onboarding directory groups
    . The first time that a synchronization cycle occurs after a user account is removed from all onboarding directory groups, the user account is deleted from
    BlackBerry UEM
    .
  10. To prevent user accounts or device data from being deleted from
    BlackBerry UEM
    unexpectedly, select
    Offboarding protection
    .
    Offboarding protection means that users will not be deleted from
    BlackBerry UEM
    until two hours after the next synchronization cycle.
  11. To force the synchronization of company directory groups, select the
    Force synchronization
    checkbox.
    If selected, when a group is removed from your company directory, the links to that group are removed from onboarding directory groups and directory-linked groups. If not selected, if a company directory group is not found, the synchronization process is canceled.
  12. In the
    Sync limit
    field, type the maximum number of changes you want to allow for each synchronization process.The default setting is five.
    If the number of changes to be synchronized exceeds the synchronization limit, you can prevent the synchronization process from running. Changes are calculated by adding the following: users to add to groups, users to remove from groups, users to be onboarded, users to be offboarded.
  13. In the
    Maximum nesting level of directory groups
    field, type the number of nested levels to synchronize for company directory groups.
  14. Click
    Save
    .