Skip Navigation

Activation types: 
Android
 devices

For 
Android
 devices, you can select multiple activation types and rank them to make sure that 
BlackBerry UEM
 assigns the most appropriate activation type for the device. For example, if you rank "
Work space only
 (
Samsung KNOX
)" first and "
MDM controls
" second, devices that support 
Samsung KNOX Workspace
 receive the first activation type.
KNOX
 MDM allows the device to use the 
KNOX
 MDM IT policy rules in 
BlackBerry UEM
 instead of the basic rules available for all 
Android
 devices. 
KNOX Workspace
 creates a separate work space on the device that keeps work data and apps separate from personal data and apps.
The 
Android
 activation types are organized in the following tables:
  • Android
     devices
  • Android Enterprise
     devices
  • Samsung KNOX Workspace
If you enable attestation for your organization’s 
BlackBerry UEM
 instance, during Android device activation, the authenticity and integrity of the device is checked. Ensure that users have 
BlackBerry UEM Client
 for 
Android
 version 12.9 MR1 or later installed on their devices before you enable this feature.
The MDM activation type does not support app configurations for 
BlackBerry Hub+ Services
. Also, 
Samsung KNOX
 devices will only receive a 
BlackBerry Hub+ Services
 app configuration if you use 
Google Play
 to manage work apps.

Android
 devices

The following activation types apply to all 
Android
 devices.
Activation type
Description
MDM controls
This activation type lets you manage the device using commands and IT policy rules. If the device supports 
KNOX
 MDM, this activation type applies the 
KNOX
 MDM IT policy rules. A separate work space is not created on the device, and there is no added security for work data.
If you do not want to apply 
KNOX
 MDM policy rules, clear the 
Activate Samsung KNOX on Samsung devices that have the MDM controls activation type assigned
 check box. This setting applies only to devices that support 
KNOX
 MDM.
During activation, users must grant Administrator permissions to the 
BlackBerry UEM Client
.
This activation type will be deprecated in a future release. For more information, visit https://support.blackberry.com/community to read article 48386.
User privacy
You can use the 
User privacy
 activation type to provide basic control of devices while making sure that users' personal data remains private. With this activation type, no separate container is installed on the device, and no added security for work data is provided. Devices activated with 
User privacy
 are activated on 
BlackBerry UEM
 and can use services such as Find my Phone and Root Detection, but administrators cannot control device policies.
Device registration for 
BlackBerry 2FA
 only
This activation type supports the 
BlackBerry 2FA
 solution for devices that 
BlackBerry UEM
 does not manage. This activation type does not provide any device management or controls, but allows devices to use the 
BlackBerry 2FA
 feature. To use this activation type, you must also assign the 
BlackBerry 2FA
 profile to users.
When a device is activated, you can view limited device information in the management console, and you can deactivate the device using a command.
This activation type is supported only for 
Microsoft Active Directory
 users.
For more information, see the BlackBerry 2FA content.

Android Enterprise
 devices

The following activation types apply only to 
Android Enterprise
 devices.
Activation type
Description
Work and personal - user privacy
 (
Android Enterprise
)
This activation type maintains privacy for personal data but lets you manage work data using commands and IT policy rules. This activation type creates a work profile on the device that separates work and personal data. Work and personal data are both protected using encryption and password authentication. 
To enable 
BlackBerry Secure Connect Plus
 and 
KNOX
 policies (for devices that support 
Knox Platform for Enterprise
), you must select the 
When activating Android Enterprise devices, enable premium UEM functionality such as BlackBerry Secure Connect Plus.
 option.
Users do not have to grant Administrator permissions to the 
BlackBerry UEM Client
.
Work space only
 (
Android Enterprise
)
If you assign this activation type to a user, you must also assign the 
Work space only
 activation email template to that user. Assigning that template makes sure that the user receives the 
Google
 activation code required during the activation process. 
This activation type lets you manage the entire device using commands and IT policy rules. This activation type requires the user to reset the device to factory settings before activating. The activation process installs a work profile and no personal profile. The user must create a password to access the device. All data on the device is protected using encryption and a method of authentication such as a password.
This activation type does not support 
BlackBerry Secure Connect Plus
.
During activation, the device installs the 
BlackBerry UEM Client
 automatically and grants it Administrator permissions. Users cannot revoke the Administrator permissions or uninstall the app.
This activation type applies 
KNOX
 policies to devices that support 
KNOX
 Platform for Enterprise. 
To enable 
BlackBerry Secure Connect Plus
 or 
KNOX
 Premium policies, you must select the 
When activating Android Enterprise devices, enable premium UEM functionality such as BlackBerry Secure Connect Plus.
 option.

Samsung KNOX Workspace
 devices

The following activation types apply only to 
Samsung
 devices that support 
KNOX Workspace
.
Activation type
Description
Work and personal - full control
 (
Samsung KNOX
)
This activation type lets you manage the entire device using commands and the 
KNOX
 MDM and 
KNOX Workspace
 IT policy rules. This activation type creates a separate work space on the device and the user must create a password to access the work space. Data in the work space is protected using encryption and a method of authentication such as a password, PIN, pattern, or fingerprint. This activation type supports the logging of device activity (SMS, MMS, and phone calls) in 
BlackBerry UEM
 log files.
During activation users must grant Administrator permissions to the 
BlackBerry UEM Client
.
Work and personal - user privacy
 - (
Samsung KNOX
)
This activation type maintains privacy for personal data, but lets you manage work data using commands and IT policy rules. This activation type does not support the 
KNOX
 MDM IT policy rules. This activation type creates a separate work space on the device and the user must create a password to access the work space. Data in the work space is protected using encryption and a method of authentication such as a password, PIN, pattern, or fingerprint. The user must also create a Screen lock password to protect the entire device and will not be able to use USB debugging mode.
During activation, users must grant Administrator permissions to the 
BlackBerry UEM Client
.
Work space only
 - (
Samsung KNOX
)
This activation type lets you manage the entire device using commands and the 
KNOX
 MDM and 
KNOX Workspace
 IT policy rules. This activation type removes the personal space and installs a work space. The user must create a password to access the device. All data on the device is protected using encryption and a method of authentication such as a password, PIN, pattern, or fingerprint. This activation type supports the logging of device activity (SMS, MMS, and phone calls) in 
BlackBerry UEM
 log files.
During activation, users must grant Administrator permissions to the 
BlackBerry UEM Client
.