Data flow: Activating a Windows 10 device
Windows 10
device- You perform the following actions:
- Configure the discovery service to simplifyWindows 10activations
- Add a user toBlackBerry UEMas a local user account or using the account information retrieved from your company directory
- Use one of the following options to provide the user with activation details:
- Automatically generate a device activation password and send an email with activation instructions for the user.
- Set a device activation password and select the option to send the activation information to the user by email.
- Don't set a device activation password and communicate theBlackBerry UEM Self-Serviceaddress to the user so that they can set their own activation password and view their server address.
- Provide the user a CA certificate generated byBlackBerry UEMto install on their device
- The user completes the following actions on their device:
- Checks that the device has Internet connectivity on port 443
- Opens and installs the certificate
- Navigates to Settings > Accounts > Work access and taps Connect
- When prompted, enters their email address and activation password they received on the activation email
- The device establishes a connection to the discovery service that you configured to simplifyWindows 10activations in your organization.
- The discovery service checks that the SRP ID for theBlackBerry UEMserver is valid and redirects the device toBlackBerry UEM.
- The device sends an activation request toBlackBerry UEMon port 443. The activation request includes the username, password, device operating system, and unique device identifier.
- BlackBerry UEMperforms following actions:
- Inspects the credentials for validity
- Creates a device instance
- Associates the device instance with the specified user account in theBlackBerry UEMdatabase
- Adds the enrollment session ID to an HTTP session
- Sends a successful authentication message to the device
- The device creates a CSR and sends it toBlackBerry UEMover HTTPS. The CSR contains the username and activation password.
- BlackBerry UEMvalidates the username and password, validates the CSR, and returns the client certificate and the CA certificate to the device.All communication between the device andBlackBerry UEMis now mutually authenticated end to end using these certificates.
- The device requests all configuration information.
- BlackBerry UEMstores the device information in the database and sends configuration information to the device.
- The device sends an acknowledgment toBlackBerry UEMthat it received and applied the configuration information. The activation process is complete.