Skip Navigation

Configuring
Microsoft Active Directory
authentication in an environment that includes a resource forest

If your organization's environment includes a resource forest that is dedicated to running
Microsoft Exchange
, you can configure
Microsoft Active Directory
authentication for user accounts that are located in trusted account forests.
If a resource forest exists in your organization's environment, you must install
BlackBerry UEM
in the resource forest. In the resource forest, you create a mailbox for each user account and associate mailboxes with the user accounts. When you associate the mailboxes in the resource forest with user accounts in the account forests, the user accounts obtain full access to the mailboxes and the user accounts in the account forests are connected to the
Microsoft Exchange
server.
To authenticate users who log in to
BlackBerry UEM
,
BlackBerry UEM
must read the user information that is stored in the global catalog servers that are part of the resource forest. You must create a
Microsoft Active Directory
account for
BlackBerry UEM
that is located in a
Windows
domain that is part of the resource forest. When you create the directory connection, you provide the
Windows
domain, username, and password for the
Microsoft Active Directory
account, and, if required, the names of the global catalog servers that
BlackBerry UEM
can use.
For more information, visit technet.microsoft.com to read
Manage linked mailboxes
.