Skip Navigation

Allow only authorized devices to access
Exchange ActiveSync

If your organization uses
Microsoft Exchange Server
2010 or later, see Configure Microsoft Exchange to allow only authorized devices to access Exchange ActiveSync.
If your organization uses
Microsoft Office 365
, see Configure the mobile device access policy in Microsoft Office 365.

Configure
Microsoft Exchange
to allow only authorized devices to access
Exchange ActiveSync

You must configure
Microsoft Exchange Server
2010 or later to allow only authorized devices to access
Exchange ActiveSync
. Devices for existing users that are not explicitly added to the allowed list in
Microsoft Exchange
must be quarantined until
BlackBerry UEM
allows them access.
To perform this task, you must be a
Microsoft Exchange
administrator with the appropriate permissions to configure the Set-ActiveSyncOrganizationSettings. For information about how to allow only authorized devices to access
Exchange ActiveSync
, visit technet.microsoft.com to read article
Enable a Device for
Exchange ActiveSync
If your organization’s default access level for
Exchange ActiveSync
is set to allow, and you have users setup and successfully synchronizing their devices, you must make sure that these users have a personal exemption or device rule associated to their user account or device before you set the default access level to quarantine. If they do not, then they are quarantined and their devices do not synchronize until they are allowed by
BlackBerry UEM
.
For more information about setting the default access level for
Exchange ActiveSync
to quarantine, visit kb to read article KB33531.
  1. On a computer that hosts the
    Microsoft Exchange Management Shell
    , open the
    Microsoft Exchange Management Shell
    .
  2. Type
    Set-ActiveSyncOrganizationSettings –DefaultAccessLevel Quarantine
    . Press ENTER.

Configure the mobile device access policy in
Microsoft Office 365

To use the
BlackBerry Gatekeeping Service
with
Microsoft Office 365
, you must configure the mobile device access policy in
Microsoft Office 365
to quarantine devices by default.
Configure permissions for gatekeeping.
If your organization’s default access level for
Exchange ActiveSync
is set to allow, and you have users setup and successfully synchronizing their devices, you must make sure that these users have a personal exemption or device rule associated to their user account or device before you set the default access level to quarantine. If they do not, then they are quarantined and their devices do not synchronize until they are allowed by
BlackBerry UEM
.
For more information about setting the default access level for
Exchange ActiveSync
to quarantine, visit kb to read article KB33531.
  1. Log in to the
    Microsoft Office 365
    administration portal.
  2. In the side menu, click
    Admin
    .
  3. Click
    Exchange
    .
  4. In the
    Mobile
    section, click
    mobile device access
    .
  5. Click
    Edit
    .
  6. Click
    Quarantine - Let me decide to block or allow later
    .