Prerequisites to support sideload detection on Android devices

  • Install the UEM Client and/or BlackBerry Dynamics apps on users’ devices (see the software requirements). Whether sideload detection is initiated by the UEM Client or a specific BlackBerry Dynamics app depends on the device activation type and the authentication delegate configured in the BlackBerry Dynamics profile.
  • The following settings are recommended based on device activation types:

    Activation type

    Recommended settings

    Android Enterprise

    Android Management

    In the BlackBerry Dynamics profile that is assigned to users:
    • Enable "Enable UEM Client to enroll in BlackBerry Dynamics." This setting is enabled by default in new BlackBerry Dynamics profiles that you create.
    • Enable “Do not require password” for Android devices. This allows the UEM Client to run activities in the background without prompting the user for a BlackBerry Dynamics password.
    • Configure the UEM Client as the authentication delegate. If a sideloaded app is detected and the configured compliance action is to prevent BlackBerry Dynamics apps from running, the UEM Client can block all BlackBerry Dynamics apps until compliance is restored.

    Note that for this activation type, sideload detection is always performed by the UEM Client.

    Samsung Knox

    In the BlackBerry Dynamics profile that is assigned to users, configure a BlackBerry Dynamics app that runs in the work space as the authentication delegate. This enables one BlackBerry Dynamics app to manage authentication, sideload detection, and compliance enforcement on behalf of all BlackBerry Dynamics apps.

    User privacy

    In the BlackBerry Dynamics profile that is assigned to users:
    • Enable "Enable UEM Client to enroll in BlackBerry Dynamics." This setting is enabled by default in new BlackBerry Dynamics profiles that you create.
    • Verify that “Do not require password” for Android devices is not enabled, for security purposes. Notify users that they will have to specify a BlackBerry Dynamics password when prompted.
    • Configure the UEM Client or a specific BlackBerry Dynamics app as the authentication delegate. The UEM Client is recommended because it can run in the background. The authentication delegate can authenticate any BlackBerry Dynamics app on the device and will manage sideload detection on behalf of all BlackBerry Dynamics apps. If a sideloaded app is detected and the configured compliance action is to prevent BlackBerry Dynamics apps from running, the authentication delegate can block all BlackBerry Dynamics apps until compliance is restored.
    • If you do not configure an authentication delegate, malware scanning will be performed by the UEM Client and each BlackBerry Dynamics app, which can consume device resources.

    Device registration for BlackBerry 2FA only

    Sideload detection is not applicable to this activation type.