Skip Navigation

Enrolling
CylancePROTECT Mobile
and
CylanceGATEWAY
users

You assign an enrollment policy to users to allow them to activate the
CylancePROTECT Mobile
app on mobile devices and
CylanceGATEWAY
agent on
Windows
and
macOS
devices.
The enrollment policy includes separate settings for mobile and desktop devices. You can specify the supported device types and the text for email messages to be sent to users to provide activation instructions and a password or
QR Code
required to begin the activation process. You can specify the number of days that the activation password or
QR Code
is valid under
Settings > Activation
. The setting applies to all enrollment policies.
Users must have the following policies assigned to them before they can activate the
CylancePROTECT Mobile
app or the
CylanceGATEWAY
agent.
User type
Required policies
CylancePROTECT Mobile
app user without
CylanceGATEWAY
support
  • Enrollment policy
  • CylancePROTECT Mobile
    policy
CylancePROTECT Mobile
app user with only
CylanceGATEWAY
support
  • Enrollment policy
  • Gateway Service policy
CylancePROTECT Mobile
app user with both
CylancePROTECT Mobile
and
CylanceGATEWAY
support
  • Enrollment policy
  • CylancePROTECT Mobile
    policy
  • Gateway Service policy
Desktop user with
CylanceGATEWAY
agent
  • Enrollment policy
  • Gateway Service policy
The
CylanceGATEWAY
agent communicates over secure websockets (WSS) with the management console and must be able to establish this connection directly. You must configure your organization's network to allow connections to the appropriate domains. For example, to allow the
CylanceGATEWAY
agent to activate and periodically authenticate, you must allow access to idp.blackberry.com and the domain for your region. If your environment uses an authentication proxy, you must allow the traffic on the proxy server. If the appropriate domains are not allowed, the
CylanceGATEWAY
agent will not be able to open the browser to complete the authentication process. For more information on the domains that must be allowed for
CylanceGATEWAY
, visit support.blackberry.com/community to read article 79017. For information on the network requirements for
Cylance Endpoint Security
, see Cylance Endpoint Security network requirements.