Configuring BlackBerry Enterprise Identity to work with Workspaces
- An on-premise installation of Workspaces.
- BlackBerry UEM with Enterprise Identity enabled.
- Go to https://<your server>/saml-idp/saml/metadata.
- Download the metadata file.
- Create a certificate and key pair.
- Follow the steps in Create a SaaS service in the BlackBerry UEM console to create a Workspaces service.
- Map the service entity ID and the signin / signout URL from the metadata to the corresponding fields in the Workspaces service.
- Configure the IDP signing certificate and private key using the key pair you generated.
- Set the claims as E-mail Address (http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddresses).
- Click Save.
- Download the metadata for the Workspaces service.
- With an administrator account, log in to the Workspaces management console.
- Click Authentication type and select BlackBerry Enterprise Identity.
- Upload the metadata you downloaded from UEM for Workspaces. This creates a new IDP in Workspaces.
- Click Save.
- Log into Workspaces BlackBerry Workspaces Configuration Tool and associate the tenant with the new IDP.
- Log into the Workspaces URL and verify that it directs to the IDP.
- Verify that the integration works by entering the username and password for a user that is entitled with BlackBerry Enterprise Identity.