Create an activation profile
- In the management console, on the menu bar, clickPolicies and profiles > Policy > Activation.
- Click .
- Type a name and description for the profile.
- In theNumber of devices that a user can activatefield, specify the maximum number of devices that a user can activate.
- In theDevice ownershipdrop-down list, select one of the following:
- If some users activate personal devices and some users activate work devices, selectNot specified.
- If most users activate work devices, selectWork
- If most users activate personal devices, selectPersonal.
- Optionally, in theAssign organization noticedrop-down list, select an organization notice. If you assign an organization notice, users activatingiOS,iPadOS,macOS, orWindows 10devices must accept the notice to complete the activation process.
- In theDevice types that users can activatesection, select the device OS types that users can activate.
- For each device type that you include in the activation profile, perform the following actions:
- Click the tab for the device type.
- In theDevice model restrictionsdrop-down list, select one of the following options:
- No restrictions: Users can activate any device model.
- Allow selected device models: Users can activate only the device models that you specify.
- Do not allow selected device models: Users can't activate the device models that you specify.
If you restrict the device models users can activate, clickEditto select the devices you want to allow or restrict and clickSave. - In theMinimum allowed versiondrop-down list, select the minimum allowed OS version.
- Select the supported activation types.ForAndroiddevices, you can select multiple activation types and rank them. For all other device types, you can select only one activation type.You must create separate activation profiles forAndroid EnterpriseandAndroid Management. IfAndroid EnterpriseandAndroid Managementactivation types are specified in the same profile, theAndroid Managementtype will take precedence, even if it is ranked lower thanAndroid Enterprise. Only the password and activation information for theAndroid Managementactivation type will be embedded in the QR Code.
- ForiOSandiPadOSdevices, perform the following actions:
- If you selected theUser privacyactivation type and you want to enable SIM-based licensing, selectAllow access to SIM card and device hardware information to enable SIM-based licensing.
- If you selected theUser privacyactivation type and you want to manage specific features, select the appropriate check boxes.
- If you selected the MDM controls orUser privacy(with SIM-based licensing) activation types and you only want to activate supervised devices, selectDo not allow unsupervised devices to activate.
- Optionally, in theiOS app integrity checksection, select one of the following attestation methods:
- Perform app integrity check on BlackBerry Dynamics app activation: Use this method to send challenges to devices when they are activated to check the integrity ofiOSwork apps.
- Perform periodic app integrity checks: Use this method to send challenges to devices to check the integrity ofiOSwork apps.
To performiOSapp integrity checking, you must enableCylancePROTECTin yourUEMdomain. For more information, see Enable CylancePROTECT Mobile in your UEM domain. - Optionally, in theManaged device attestationsection, select one of the following attestation methods:
- Perform Managed device attestation on device activation: Use this method to send challenges to devices when they are activated to check the integrity of the device properties.
- Perform periodic Managed device attestation: Use this method to send challenges periodically to check the integrity of the device properties.
To perform managed device attestation oniOSdevices, you must enable the feature. For more information, see Configure attestation foriOSdevices in the Administration content.Managed device attestation applies to theMDM controlsand theUser privacyactivation types, but not theUser privacy - User enrollmentactivation type. When you select theUser privacyactivation type, you must select at least one of the management options (such as "Allow VPN management"). - ForAndroiddevices, perform the following actions:
- If you selected more than one activation type type, click the up and down arrows to rank them. Devices receive the highest ranked profile that they support.
- If you selected aSamsung Knoxactivation type and you want to useGoogle Playto manage work apps, selectGoogle Play app management for Samsung Knox Workspace devices. This option is available only if you have configured a connection to a Google domain..Samsung Knoxactivation types will be deprecated in a future release. Devices that supportKnox Platform for Enterprisecan be activated using theAndroid Enterpriseactivation types.
- If you selected anAndroid Enterpriseactivation type, select the appropriateAndroid Enterpriseoptions:
- To enableBlackBerry Secure Connect PlusandKnoxPlatform for Enterprise features (for devices that supportSamsung Knox) on devices with an appropriate license, selectWhen activating Android Enterprise devices, enable premium UEM functionality such as BlackBerry Secure Connect Plus.
- To enableSamsung KnoxDualDAR encryption for devices that support it, selectEnable Samsung Knox DualDAR Workspace.
- To allowGoogle Playapp management in the work space, selectAdd Google Play account to work space.
- To allowUEMto restrict activation by device ID, selectAllow only approved device IDsThis option is supported only forWork space onlyandWork and personal - full controldevices.
- To specify the network type that users can activate a device over, in theQR Code enrollmentdrop-down list, select a network. This option is supported only forWork space onlyandWork and personal - full controldevices.
- Optionally, in theSafetyNet or Play Integrity attestation optionssection, select one of the following attestation methods:
- Perform SafetyNet or Play Integrity attestation for device: Use this method to send challenges to test the authenticity and integrity of devices.
- Perform SafetyNet attestation on device activation (Applies only to UEM Client versions that do not support Play Integrity): Use this method to send challenges to test the authenticity and integrity of devices when they are activated.
- Perform SafetyNet or Play Integrity attestation on BlackBerry Dynamics app activation: Use this method to send challenges to test the authenticity and integrity ofBlackBerry Dynamicsapps when they are activated.
- If you wantUEMto send challenges to devices when they are activated to ensure the required security patch level is installed, in theHardware attestation optionssection, selectEnforce attestation compliance rules during activation.
- ForWindows 10devices, select one or both form factor options.
- ClickAdd.
- If necessary, rank activation profiles.
- Assign the profile to user accounts and groups.