Skip Navigation

Controlling which devices can access 
Exchange ActiveSync

You can stop unauthorized devices from using 
Exchange ActiveSync
 unless they are explicitly added to the allowed list. Devices that are not on the allowed list cannot access work email and organizer data. Using the 
BlackBerry Gatekeeping Service
 makes it easier to add devices to the allowed list.
To use the 
BlackBerry Gatekeeping Service
, you must create a gatekeeping configuration for 
Microsoft Exchange Server
 or 
Microsoft Office 365
 and assign a gatekeeping profile and an email profile (or an email app with an app configuration) to users that has the automatic gatekeeping server selected.
After you configure gatekeeping and assign a gatekeeping profile and an email profile (or an email app with an app configuration) to users, the users' devices are automatically added to the allowed list. If the gatekeeping profile, email profile, or email app is removed from a user, the user's device is removed from the allowed list and can no longer connect to 
Microsoft Exchange
 unless it is allowed using other means (for example, 
Windows PowerShell
).
You can install one or more instances of the 
BlackBerry Connectivity Node
 to add additional instances of the device connectivity components to your organization’s domain. Each 
BlackBerry Connectivity Node
 contains an instance of the 
BlackBerry Gatekeeping Service
. Each instance must be able to access your organization’s gatekeeping server. If you want gatekeeping data to be managed only by the 
BlackBerry Gatekeeping Service
 that is installed with the primary 
BlackBerry UEM
 components, you can change the default settings to disable the 
BlackBerry Gatekeeping Service
 in each 
BlackBerry Connectivity Node
. For more information about installing and configuring a 
BlackBerry Connectivity Node
see the Planning content and the Installation and upgrade content.
You can set up server groups to direct device connectivity traffic to a specific regional connection to the 
BlackBerry Infrastructure
. When you associate a gatekeeping profile with a server group, any user that is assigned that gatekeeping profile uses any active instance of the 
BlackBerry Gatekeeping Service
 in that server group. When you configure a server group, you can choose to disable the instances of the 
BlackBerry Gatekeeping Service
 in the group.