BlackBerry UEM Cloud - Configuring the Mobile Security Dashboard

Prerequisites

You need the following details from your BlackBerry UEMClosed Unified Endpoint Management. An architecture and approach that controls different types of devices such as computers, smartphones and IoT devices from a centralized command point. Cloud Deployment:

  • Server: The URL of your BlackBerry UEM Cloud account. Example:https://xx1234.dd.uem.blackberry.com/

  • Client ID and Secret: The Client ID and Secret created in the BlackBerry UEM console. See Prerequisites - BlackBerry UEM Cloud .

  • SRP ID: The Tenant ID of your BlackBerry UEM account. To obtain the tenant ID, go to Services > UEM and expand your BlackBerry Cloud account.

Integration Procedure

00:03: This tutorial guides you through configuring the BlackBerry UEM cloud integration

00:07: on the Mobile Security Administrator portal.

00:10: Before you start, make sure that you have done the prerequisites in the BlackBerry

00:14: UEM side. To watch the prerequisites video, click the link at the top-right corner.

00:20: Log in to the checkpoint portal and access the mobile security dashboard.

00:24: Go to settings Integrations, then click add and select uems.

00:29: In the UEM

00:30: integration window, select BlackBerry UEM and click Next.

00:34: Select BlackBerry on-cloud and then click Next.

00:38: In the Server Setup page, enter a name for your integration. In the Server Address

00:42: field,

00:43: enter the URL of your BlackBerry UEM Cloud account.

00:48: Enter the Client ID and Client Secret

00:50: you created in the BlackBerry UEM portal.

00:54: In the S R P ID field, enter the Tenant ID of your BlackBerry UEM account.

00:59: Scroll down and click Verify.

01:02: After successful verification, click Next.

01:05: In the Synchronization section, from the Groups list, select the BlackBerry UEM

01:10: groups you need to integrate with Mobile Security. Optionally,

01:14: you can also select groups for the BlackBerry UEM Android Enterprise deployment.

01:19: Keep the defaults in the advanced section.

01:21: Then click verify after successful verification click next.

01:26: In the Tagging section, select the Tag device status and Tag device risk checkboxes.

01:31: This action sends the deployment status of the Mobile Security Protect app and the

01:35: device risk level to BlackBerry UEM.

01:38: Click Verify. After successful verification, click Next.

01:43: In the Deployment section, copy the token and save it.

01:46: You will need it to configure the Mobile Security Protect app deployment in the

01:50: BlackBerry UEM portal.

01:53: Click Finish to complete the integration

01:56: When the integration is complete, the BlackBerry UEM pane appears on the

02:00: Integrations page.

02:02: This completes the Blackberry UEM configuration in the Mobile Security admin portal.

02:07: Thank you for watching the video.

  1. Log in to the Check Point Portal and access the Mobile Security dashboard.

  2. Go to Settings > Integration.

  3. Click Add > UEMs.

  4. In the UEM integration window, select BlackBerry UEM and click Next.

    The BlackBerry Integration wizard appears.

  5. Select BlackBerry on-cloud.

  6. Click Next.

  7. Configure these settings:

Server Details

  1. In Server Setup section, enter this information:

    1. Display Name - Enter a name for your integration.

    2. Server Address - The URL of your BlackBerry UEM Cloud account

    3. Client ID - Enter the Client ID from BlackBerry UEM console.

    4. Client Secret - Enter the Client Secret from BlackBerry UEM console.

    5. SRP ID - Enter the Tenant ID of your BlackBerry UEM account.

  2. Click Verify.

  3. After successful verification, click Next.

Synchronization

In Synchronization section, select the user groups that you want to protect and that are synchronized with Mobile Security. All devices that belong to users in the selected group(s) are synchronized with Mobile Security.

Note - The selected groups must be of type user groups (not dynamic device groups).

  1. From the Groups list, select the group(s) you need for integration with BlackBerry UEM Cloud.

  2. (Optional)From the Android Enterprise Groups list, select the groups for the BlackBerry UEM Android Enterprise deployment.

    Note - This step applies only to Android devices with both personal and work profiles. Fully managed devices without a personal profile do not require to add these groups.

  3. In the Advanced section:

    1. Import Personally Identifiable Information (PII) and set the synchronization intervals.

      You can limit the import of the PII devices (users) to Mobile Security, by default it is set to ON.

      Note - If all entries are OFF, the placeholder information set

      for the email address is placed in the Device Owner's Email,

      in form of "UEMDevice UDID@vendor.UEM".

    2. Setting

      Description

      Values

      Device sync interval

      Interval to connect with UEM to sync devices.

      30-120 minutes, in 10 minute intervals.

      Device deletion threshold

      Percentage of devices allowed for deletion after UEM device sync (in %).

      0-100%

      Note - Use 100% for no threshold.

      100% value is recommended for:

      • Evaluation/test usage - When you are adding a small amount of devices.

      • Planned bulk deletion of devices from the UEM (see sk184319). After the devices are deleted from the Mobile Security Admin Portal, set it back to a safer value (such as 5–10%) to prevent accidental mass deletions in the future.

      Device deletion after

      Delay device deletion after several sync attempts - device is deleted after this amount of sync tries that confirmed deletion

      1-10 sync tries.

      App sync interval

      Interval to connect with UEM to sync applications.

      30-1440 minutes, in 10 minute intervals.

  4. Click Verify and then click Next.

Tagging

Specify whether to send information to BlackBerry UEM in order to communicate the deployment status of Mobile Security Protect and the risk level of the device.

  1. Enable the Tag device status checkbox:

    • The Device Status tag creates these CHKP_Status user groups in BlackBerry UEM:

      • CHKP_Status_ Provisioned

        When a device is provisioned in the Mobile Security dashboard, this device is placed in the CHKP_Status_Provisioned group.

      • CHKP_Status_Active

        After the user has installed and registered to Mobile Security, this device is moved from CHKP_Status_Provisioned group to the CHKP_Status_Active group.

      • CHKP_Status_Inactive

        If the device has not connected with Mobile Security for X number of days (configured by the Mobile Security admin), then the device is moved from CHKP_Status_Active group to CHKP_Status_Inactive group.

    • The CHKP_Status user groups are used to determine when to prompt the user to install the Mobile Security Protect app on their device. If none of CHKP_Status user groups are set for a device, then the device has not been synced with Mobile Security dashboard.

  2. Enable the Tag device risk checkbox.

    The Device Risk tag creates these CHKP_Risk groups in BlackBerry UEM:

    • CHKP_Risk_None

    • CHKP_Risk_Low

    • CHKP_Risk_Medium

    • CHKP_Risk_High

    The CHKP_Risk user groups are used to determine when to enact certain policies or actions on the device.

    If a device is determined to be at High, Medium, or Low risk, the device is placed in the respective group. If the device has no risks, then it is placed in the CHKP_Risk_None group.

    For example, if the Mobile Security Protect app indicates that the device is in Low risk, then the device will be moved to CHKP_Risk_Low group.

Deployment

In the Deployment section:

  1. Copy the token and save it for later to manage the application in Adding the Mobile Security Protect app to your App Catalog.

  2. In the Advanced section:

    1. Enable options to send email and/or SMS notification to the new users with instructions to download and install the Mobile Security Protect.

      Note - This option is required only for UEM-managed devices that are registered manually using QR code. It is not required for automatic or Zero-Touch registration.

    2. Click Finish.

    When the integration is complete, the BlackBerry UEM pane appears in the Integrations screen.