Configuring BlackBerry Enterprise Identity to work with Workspaces

You must have the following environment:
  • An on-premise installation of Workspaces.
  • BlackBerry UEM with Enterprise Identity enabled.
  1. Go to https://<your server>/saml-idp/saml/metadata.
  2. Download the metadata file.
  3. Create a certificate and key pair.
  4. Follow the steps in Create a SaaS service in the BlackBerry UEM console to create a Workspaces service.
  5. Map the service entity ID and the signin / signout URL from the metadata to the corresponding fields in the Workspaces service.
  6. Configure the IDP signing certificate and private key using the key pair you generated.
  7. Set the claims as E-mail Address (http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddresses).
  8. Click Save.
  9. Download the metadata for the Workspaces service.
  10. With an administrator account, log in to the Workspaces management console.
  11. Click Authentication type and select BlackBerry Enterprise Identity.
  12. Upload the metadata you downloaded from UEM for Workspaces. This creates a new IDP in Workspaces.
  13. Click Save.
  14. Log into Workspaces BlackBerry Workspaces Configuration Tool and associate the tenant with the new IDP.
  15. Log into the Workspaces URL and verify that it directs to the IDP.
  16. Verify that the integration works by entering the username and password for a user that is entitled with BlackBerry Enterprise Identity.