Skip Navigation

Enable provisioning of 
Active Directory
 groups

In the 
BlackBerry UEM Cloud
 management console, you can enable provisioning of 
Microsoft Active Directory
 groups to allow 
BlackBerry Workspaces
 to use company directory connections that are configured in 
UEM
 (for example, 
Azure
 
Active Directory
 and 
Active Directory
 through the 
BlackBerry Connectivity Node
).
When you enable the provisioning of 
Active Directory
 groups:
  • In the 
    Workspaces
     administration console, Organization Administrators can grant permissions to 
    Workspaces
     to 
    Active Directory
     security groups. 
  • Workspaces
     users with sender permissions can use the Send a copy feature to send files to 
    Active Directory
     distribution lists. 
  • In the 
    UEM
     management console, administrators can assign roles to users according to the 
    Active Directory
     group they belong to. For each group that you add, you choose the roles that you want to automatically assign to its members. When a user creates a 
    BlackBerry Workspaces
     account using an email address in your organization's directory, the account is automatically assigned the appropriate role based on the group that they are a member of.
In 
BlackBerry UEM Cloud
 management console, add a company directory connection to an 
Azure
 
Active Directory
, or install the 
BlackBerry Connectivity Node
 and configure it to work with 
Microsoft Active Directory
.
  1. In the 
    BlackBerry UEM Cloud
     management console, click 
    Settings
     > 
    BlackBerry Workspaces
    .
  2. Click 
    Roles by Active Directory
  3. Select 
    Enable provisioning of AD users and groups
    .
  4. Click 
    Apply changes
    .