Create a gatekeeping configuration
You can create a gatekeeping configuration so that devices that comply with your organization's security policies can connect to the
Microsoft Exchange
Server
or Microsoft 365
.- If you want to use modern authentication, Add an Entra app and obtain its Entra details for configuring modern authentication.
- Do one of the following:
- If you haveBlackBerry UEMin an on-premises environment, on the menu bar, clickSettings > External integration > Microsoft Exchange gatekeeping.
- If you haveBlackBerry UEM Cloud, in theBlackBerry Connectivity Nodeconsole (http:/localhost:8088), clickGeneral settings > BlackBerry Gatekeeping Service.
- In theMicrosoft Exchange Serverlist section, click .
- Perform one of the following tasks:TaskStepsConnect toMicrosoft 365using modern authenticationBefore you configureBlackBerry UEMto use modern authentication, you must generate a certificate that has public and private keys. You can useOpenSSLor PowerShell to generate the certificate. For more information, refer to Associate a certificate with the Entra app ID for modern authentication.
- Select theModern authenticationcheck box.
- In theExchange Online connection namefield, type a name for the connection.
- ClickBrowseand select the certificate to use for authentication.
- In theCertificate passwordfield, type the password for the certificate.
- Specify yourEntra Application ID.
- Specify yourEntra organization.
Connect to yourMicrosoft Exchange ServerorMicrosoft 365using basic authentication- In theServer namefield, type the name of theMicrosoft Exchange ServerorMicrosoft 365environment that you want to manage access to.
- Type the username and password for the account that you created to manageExchange ActiveSyncgatekeeping.
- In theAuthentication typedrop-down list, select the type of authentication that is used for theMicrosoft Exchange ServerorMicrosoft 365.
- To enable SSL authentication betweenBlackBerry UEMand theMicrosoft Exchange ServerorMicrosoft 365, select theUse SSLcheck box. Optionally, select additional certificate checks.
- In theProxy typedrop-down list, select the type of proxy configuration, if any, that is used betweenBlackBerry UEMand theMicrosoft Exchange ServerorMicrosoft 365.
- If you selected a proxy configuration in the previous step, select the authentication type that is used on the proxy server.
- If necessary, selectAuthentication requiredand type the username and password.
- ClickTest Connectionto verify that the connection is successful.
- ClickSave.
- Create a gatekeeping profile and assign it to user accounts, user groups, or device groups.
- If you configured aBlackBerry Connectivity Nodeserver group with one or more active instances of theBlackBerry Gatekeeping Service, associate the gatekeeping profile with the appropriate server group. Any user that is assigned that gatekeeping profile can use any active instance of theBlackBerry Gatekeeping Servicein that server group.