Skip Navigation

Architecture:
CylancePROTECT Mobile

The UEM, device, and cloud components of the BlackBerry Protect UEM architecture
Component
Description
BlackBerry UEM
management console
Use the
UEM
management console to:
  • Scan hosted
    Android
    apps for malware when you upload the app files to
    UEM
    for deployment
  • Maintain a list of approved apps that are exempt from
    Android
    malware detection and
    iOS
    and
    Android
    sideload detection
  • Maintain a list of restricted apps that are flagged as malware on
    Android
    devices without requiring a malware scan
  • Maintain a list of approved and blocked domains and IP addresses for safe browsing
  • Enable and configure integrity checking for
    BlackBerry Dynamics
    apps on
    iOS
    devices
  • Enable and configure hardware certificate attestation for
    BlackBerry Dynamics
    apps on
    Android
    devices
CylancePROTECT
profile
Create a
CylancePROTECT
profile and assign it to users to enable
CylancePROTECT Mobile
features on
iOS
and
Android
devices.
Activation profile
Create and assign a
UEM
activation profile to users to enable
iOS
integrity checking and
Android
hardware certificate attestation for
BlackBerry Dynamics
apps at the time of activation.
Compliance profile
Create and assign a
UEM
compliance profile to users to take the appropriate management actions when:
  • Malware is detected on an
    Android
    device
  • A sideloaded app is detected on an
    iOS
    or
    Android
    device
  • A
    BlackBerry Dynamics
    app on an
    iOS
    device fails an integrity check
  • A
    BlackBerry Dynamics
    app on an
    Android
    device fails hardware certificate attestation
CylanceINFINITY
CylanceINFINITY is a cloud-based platform that uses sophisticated AI and machine learning to determine whether software and websites are potentially malicious and a threat to the security of device endpoints in a
UEM
domain.
When you upload an
Android
app that you want to deploy with
UEM
,
UEM
sends the app files to
CylanceINFINITY
for analysis and risk assessment.
CylanceINFINITY
returns a confidence score that identifies the app as safe or as malware.
The
UEM Client
and
BlackBerry Dynamics
apps on
Android
devices send app files to
CylanceINFINITY
for analysis and risk assessment.
CylanceINFINITY
returns a confidence score that identifies the app as safe or as malware.
When a user navigates to a URL in a
BlackBerry Dynamics
app, the app sends the URL to
CylanceINFINITY
in real-time to determine if it is safe. You can choose the user experience when a user tries to navigate to an unsafe URL.
Apple
DeviceCheck framework
The
iOS
integrity check feature allows you to leverage the Apple DeviceCheck framework to periodically verify the integrity of
BlackBerry Dynamics
apps on users'
iOS
devices.
BlackBerry UEM Client
and
BlackBerry Dynamics
apps
UEM
communicates with the
UEM Client
on a user’s device to apply configuration settings and profiles.
BlackBerry Dynamics
apps are productivity apps that give users secure access to work resources.
The
BlackBerry Dynamics SDK
and the
CylancePROTECT Mobile
library are integrated with the
BlackBerry Access
,
BlackBerry Work
, and 
UEM Client
apps, supporting additional functionality that allows these apps to detect malware and insecure
Wi-Fi
on
Android
devices, sideloaded apps and insecure network connections on
iOS
and
Android
devices (for
iOS
, the
UEM Client
and
BlackBerry Work
only), and unsafe URLs when using
BlackBerry Access
and other
BlackBerry Dynamics
apps.