Configure the Docs security settings
Docs
security settingsDocs
security settings control acceptable Microsoft
SharePoint Online
domains, the URL of the approved Microsoft Office Web Apps
(OWAS), the appropriate LDAP domains to use, whether you want to use Kerberos constrained delegation for user authentication, and Azure
-IP authentication. Delegation allows a service to impersonate a user account to access resources throughout the network. Constrained delegation limits this trust to a select group of services explicitly specified by a domain administrator. Verify that one or more of the following are configured in your environment:
- Kerberos constrained delegation for theBlackBerry Docsservice is configured in your environment. For instructions, see Configuring Kerberos constrained delegation for the Docs service.
- Resource-based Kerberos constrained delegation for theBlackBerry Docsservice is configured in your environment. For instructions, see Configuring resource based Kerberos constrained delegation for the Docs service.
- Your environment is configured to useAzure-IP, have the following information. For instructions, see Obtain the Azure IP authentication information for the Docs service.
- BPOS TenantID
- Symmetric Key
- AppPrincipalID
- AzureTenant Name
- BEMSServiceAzureApplication ID
- BEMSServiceAzureApplication Key
- In theBlackBerry Enterprise Mobility Server Dashboard, underBlackBerry Services Configuration, clickDocs.
- ClickSettings.
- Select theEnable Kerberos Constrained Delegationcheckbox to allowDocsto use Kerberos constrained delegation.
- Separated by a comma, enter each of theMicrosoft SharePoint Onlinedomains you plan to make available. For more information, see Configuring support for Microsoft SharePoint Online and Microsoft OneDrive for Business.
- Enter the URL for your approvedOffice Web App Server.
- Provide yourMicrosoft Active Directoryuser domains (separated by commas), then enter the correspondingLDAP Port. LDAP (Lighweight Directory Access Protocol) is used to look up users and their membership in user groups.
- Select theUse SSL for LDAPcheckbox for secure communication with yourMicrosoft Active Directoryservers.
- Add theWorkspaces Public Key. Adding the public key allowsBEMSand theBlackBerry Workspacesserver to communicate with each other. For more information about locating the public key, contactBlackBerry Technical Support Services.
- Select theEnable Azure Information Protectionscheck box to allowDocsto authenticate toAzure-IP. Complete the required fields to authenticateDocstoAzure-IP to allow theDocsto decrypt protected documents and confirm the rights any given user has on a document.
- ClickSave.
- Restart theGood Technology Common Servicesfor the changes to take effect.