Create or modify a BlackBerry 2FA profile in BlackBerry UEM
version 12.8 or earlier
BlackBerry 2FA
profile in BlackBerry UEM
version 12.8 or earlierTo use
BlackBerry 2FA
, you must create a BlackBerry 2FA
profile and
assign it to users.- On the menu bar, clickPolicies and Profiles.
- ClickNetworks and connections>BlackBerry 2FA.
- Do one of the following:
- To create a profile, click .
- To modify a profile, click the name of the profile that you want to modify and click .
- Type a name for theBlackBerry 2FAprofile.
- Optionally, add a description for theBlackBerry 2FAprofile.
- Select an authentication option:
- SelectTwo-factor authenticationif you are creating a standardBlackBerry 2FAprofile.
- SelectSingle-factor authentication using enterprise passwordif you are creating a profile for users who do not have a device but need access to your organization's resources. This option is less secure because the user supplies only a directory password when they request authentication and no confirmation request to authenticate is sent. One-Time Password (OTP) tokens are not supported with this option.
- Select a password to use with device prompt:
- SelectEnterprise passwordif you are creating a profile for users who first need to supply their directory password when they request authentication and then receive a confirmation request on their device.
- SelectPassive device passwordif you are creating a profile forBlackBerry 10users who should receive a passive prompt to supply their workspace password to unlock their workspace and then receive a confirmation request for authentication on their devices. The passive prompt means that the user is not required to supply a workspace password if the device workspace is already unlocked when they request authentication.
- SelectActive device passwordif you are creating a profile forBlackBerry 10users who should receive an active prompt to supply their workspace password to unlock their workspace and then receive a confirmation request to authenticate on their devices. The active prompt means that the user must supply a workspace password if the device workspace is already unlocked when they request authentication.
- Optionally, if you use theEnterprise passwordauthentication policy, do any of the following:
- To allow users to use OTPs in theBlackBerry UEM Clientapp, selectAllow One-Time Password token. Specify the length of the OTPs that are generated.
- To allow users to request Direct Authentication, selectAllow Direct Authentication from user's device. Specify the duration, in seconds, that users have to compete the two-factor authentication process after they have started it on their mobile device. The maximum setting is "180."
- To allow users to set a self-rescue period, selectAllow self-rescue from BlackBerry UEM Self-Service. Specify, in hours, the default and maximum time that users can access your organization's resources without needing to respond to a confirmation prompt on their devices.
- To allow users to set a Preauthentication period, selectAllow Preauthentication from user's device. Specify, in hours, the default and maximum time that users can access your organization's resources without needing to respond to a confirmation prompt on their devices (the prompt will not appear).
- ClickAddorSave.