Configuring BlackBerry UEM
    BlackBerry UEM
The following table summarizes the initial configuration tasks that are covered in this guide. Review them to determine which tasks you should complete based on your organization's needs. After you complete the appropriate tasks, you are ready to set up administrators, create and manage users and groups, set up device controls, and activate devices.
When you perform the configuration tasks in this guide, use the administrator account that you created when you installed 
UEM
. If you create additional administrator accounts to configure UEM
, you should assign the Security Administrator role to the accounts to ensure that the proper level of permissions are granted.| Task | On-prem | Cloud | Description | 
|---|---|---|---|
| √ | You can replace the default self-signed certificates that  UEMuses to authenticate communication between components and with devices. | ||
| √ | You can install and configure the  BlackBerry Connectivity Nodein a UEM Cloudenvironment to provide access to your organization's on-premises company directory and to enable secure connectivity features. | ||
| √ | √ | You can configure  UEMto send data through a proxy server before it reaches the BlackBerry Infrastructure. In UEM Cloudenvironments you can install a standalone BlackBerry Routerto function as a proxy server. | |
| √ | If your organization uses a proxy server for connections between servers inside your network, you may need to configure server-side proxy settings to allow  UEMcomponents to communicate with remote instances of the management console. | ||
| √ | If you want  UEMto send activation emails and other notifications to users, you must specify the SMTP server settings that UEMcan use. | ||
| √ | √ | Connect  UEMto your company directories to create user accounts, enable directory-linked groups, and to configure user onboarding and directory synchronization. | |
| √ | √ | Connect  UEMto Entrato create directory user accounts in UEM. | |
| √ | √ | Use  UEMto create, manage, and assign Microsoft Intuneapp protection profiles to protect data in Office
365apps. | |
| √ | √ | Configure  UEMto support Entra IDconditional access. | |
| √ | √ | Obtain and register an APNs certificate if you want to manage and send data to  iOSand macOSdevices. | |
| √ | √ | You can use the  UEMmanagement console to manage iOSdevices that your organization purchased from Applefor DEP. | |
| √ | √ | To support  Android Enterprisedevices, you must configure your Google Workspaceor Google Clouddomain to support third-party mobile device management providers and configure UEMto communicate with your Google Workspaceor Google Clouddomain. | |
| √ | √ | To support  Android Managementdevices, you configure Android Managementin the Google Cloudconsole and then add an Android Managementconnection in UEM. | |
| √ | √ | You can configure  UEMto support certain Chrome OSmanagement features. | |
| √ | √ | You can simplify the process for activating  Windows 10devices so that users don't need to specify a server address. | |
| √ | √ | You can migrate users, devices, groups and other data from supported  BlackBerryservers. | |
| √ | √ | You can configure network communications and other properties for  BlackBerry
        Dynamicsapps. | |
| √ | You can encrypt the connection between  UEMand Microsoft SQL
  Server. | ||
| √ | You can create a connection with  Cisco ISEto enable it to retrieve device data from UEMand enforce network access control policies. | ||
| √ | In a  UEMdark site environment, you must set up VPN access so that Samsung Knoxdevices can access your internal servers and resources. |