Create a BlackBerry Enterprise Identity policy for PingFederate users
BlackBerry Enterprise Identity
policy for PingFederate
users- In theBlackBerry UEMconsole, on the menu bar, clickPolicies and Profiles > BlackBerry Enterprise Identity > Add a policy.
- Enter a name and description for the policy.
- In theMinimum authenticatorlevel drop-down, select the number that corresponds to the authentication level for one of the Authentication levels forPing Identityon theSettings > BlackBerry Enterprise Identity > Settingsscreen. You can choose a level that corresponds to the following options: Ping password, Ping password + BlackBerry 2FA, or Ping password + PingID.
- Optionally, you can add a Risk scenario which provides additional security if certain conditions exist, such as if a user is not on an internal network. In theRisk scenariostable, click+.
- Enter a nameand description for the risk scenario.
- Select a Minimum authentication level that corresponds to one of the Authenticator levels for Ping on the Settings > BlackBerry Enterprise Identity > Settings screen. You can choose to allow your users to enter only their password or respond to aBlackBerry 2FAprompt or enter their PingID if any of the risk factors are present when the user logs into the service. Choose from the following Risk factors:
- Network detection: If you want to assess whether a user's app or browser is connected to the same network asBlackBerry UEM, select the Network detection option, and in the Configuration drop-down list, select the desired option.
- Browser detection: If you want to establish a reference of trust between the browser andEnterprise Identitythe first time that the user opens a browser, select the Browser detection option, and in the Configuration drop-down list, select the desired option.
- BlackBerry Persona: If you want to useCylancePERSONA Mobilerisk levels and geozones as risk factors, choose theCylancePERSONAoption
- ClickSave.
- ClickSave.
Assign the policy to your organization’s
PingFederate
users. If you have your users configured in a group you can follow the Assign an Enterprise Identity policy to a user group topic to easily assign the policy to all the users at once.