Data flow: Activating a BlackBerry OS device
BlackBerry
OS device
- You use the management console to create a new user account and use one of the following options to provide the user with activation details:
- Automatically generate a device activation password and send an email with activation instructions for the user
- Set a device activation password and communicate the username and password to the user directly or by email
- Don't set a device activation password and communicate theBlackBerry Web Desktop Manageraddress to the user so that they can set their own activation password
The device user list stored in theBlackBerry UEMdatabase is updated with the new device user name, email address, mailbox information, activation password, activation status, and other information. - TheBlackBerry DispatcherforBlackBerryOS assigns the new user to aBlackBerry Messaging Agent. TheBlackBerry Messaging Agentstarts to monitor the user's mailbox on the mail server for new email. An email containing an etp.dat file attachment is required to continue the activation process.
- The device user navigates to the Enterprise Activation screen on theBlackBerryOS (version 5.0 to 7.1) device and types the email address and activation password. The device user opens the menu and clicks Activate. The device displays "Activating."
- The device creates an activation request email that contains the email address, device PIN, and public key authentication information, based on the enterprise activation password the user typed. The device encrypts the email using SPEKE and sends it to theBlackBerry Infrastructure.
- TheBlackBerry Infrastructurereceives the activation request email and identifies it as an activation request. TheBlackBerry Infrastructureforwards the email using SMTP to the email address that the user typed on the Enterprise Activation screen.
- When the activation request email arrives in the user's mailbox, theBlackBerry Messaging Agentidentifies it and removes it from the user's mailbox. TheBlackBerry Messaging Agentrecognizes the etp.dat attachment in the activation request email and begins an authentication process.
- TheBlackBerry Messaging Agentcompares the authentication key received in the activation request email with the authentication key generated from the activation password and stored in theBlackBerry UEMdatabase. If the authentication keys match, theBlackBerry Messaging Agentnotifies theBlackBerryOS device that the activation request was received.
- BlackBerry UEMand theBlackBerryOS device establish an encryption key and verify their knowledge of the encryption key to each other.TheBlackBerryOS device displays "Encryption Verified. Waiting for Services."All the data sent between theBlackBerryOS device andBlackBerry UEMfrom now on is compressed and encrypted using this encryption key and the device can now be managed from the management console.
- TheBlackBerry Messaging Agentforwards a request to theBlackBerry Policy Serviceto generate service books. TheBlackBerry Policy Servicereceives and queues the request. TheBlackBerry Policy Serviceadds the unique authentication key that theBlackBerry UEMdomain uses to sign IT policy data and then forwards the IT policy data through theBlackBerry DispatcherforBlackBerryOS to the device. TheBlackBerry Policy Servicewaits for confirmation from the device that the IT policy has been applied successfully.
- TheBlackBerryOS device applies the IT policy and sends a confirmation toBlackBerry UEM. The IT policy applied to theBlackBerryOS device is now in a read-only state and can be modified only by updates sent from the sameBlackBerry UEMdomain.
- Once theBlackBerry Policy Servicereceives confirmation that the IT policy was applied successfully, theBlackBerry Policy Servicegenerates and sends the service books to theBlackBerryOS device.
- TheBlackBerryOS device receives the service books. The device user is notified that the email address has been activated.TheBlackBerryOS device displays "Services Received. Your email address, <username>@<domain>.com is now enabled."The device user can now send and receive email messages on theBlackBerryOS device.
- The slow synchronization process begins. TheBlackBerryOS device requests the synchronization configuration information from theBlackBerry Synchronization Service. The configuration information indicates whether wireless data synchronization onBlackBerry UEMis turned on and which organizer databases can be synchronized. The configuration information also provides database synchronization types (unidirectional or bidirectional) and conflict resolution settings.
- TheBlackBerry Synchronization Servicereturns the configuration information and synchronizes the databases on theBlackBerryOS device using that information.TheBlackBerryOS device andBlackBerry UEMdo not delete records during the initial synchronization process.
- The slow synchronization process is complete when all databases are synchronized between theBlackBerryOS device andBlackBerry UEM.The activation process is complete when theBlackBerryOS device displays “Activation Complete” and the device user account status displays “Completed” in the management console orBlackBerry Administration Service.