Requirements and considerations for a BSI-certified UEM environment
    UEM
 environmentFor complete guidance on preparing your environment to install 
BlackBerry UEM
, see the UEM Planning Guide. The following table highlights requirements or considerations that are specific to a BSI-certified UEM
 environment:| Item | Requirements | 
|---|---|
| Certified version of  BlackBerry UEM | BlackBerry UEMon-premises version 12.21 MR1 (build 40.32.0). Earlier versions of  UEMon-premises and UEM Cloudare not BSI-certified. | 
| Third-party software requirements and considerations | 
 | 
| Supported devices and activation types | 
 UEMsupports other devices as well, but only iOSdevices enrolled using DEP and Samsungdevices enrolled using Samsung Knoxare supported in a BSI-certified environment. | 
| UEMcomponents and features that are not supported | The following  UEMcomponents or features are not supported in a BSI-certified environment: 
 | 
| Supported ciphersuites | In a BSI-certified environment,  UEMsupports a stricter list of GCM ciphersuites for TLS communications: 
 Every external service that  UEMcommunicates with must support these ciphersuites. | 
| Certificate validation and requirements | Verify that the certificates that you upload to  UEMfor syslog and LDAP integrations are trustworthy and have the basic constraints and key usage fields set. Note the following certification validation details and requirements for using certificates with  UEMin a BSI-certified environment: 
 | 
| Consideration when configuring software updates for DEP devices | In a BSI-certified environment, if you configure OS updates for supervised DEP devices (Users > Managed devices > select user(s) > Update), some tool tips and UI text may indicate that the OS update time on  iOS17 and later devices is the device local time, but for all supported iOSversions the time is handled as server UTC time instead. |