Skip Navigation

Device management modes

The following tables list the device management modes to help you plan your environment. Some of these options can be combined or used in conjunction, and some modes are exclusive. For more information about and instructions to configure these features, see the Administration content.

iOS

Activation type
Device management mode
UEM service for behind-the-firewall enterprise connectivity
MDM controls
Enterprise email only
Yes
  • iOS
     email app only: 
    BlackBerry Secure Gateway
MDM controls
Device-wide VPN for email and apps
Yes
  • iOS
     email app: 
    BlackBerry Secure Gateway
  • Additional apps: 
    BlackBerry Secure Connect Plus
MDM controls
Device Control and App Deployment (
BlackBerry UEM Client
)
No
  • Behind the firewall with VPN profile 
MDM controls
BlackBerry Dynamics
Yes
  • BlackBerry Dynamics
     apps: 
    BlackBerry Proxy
MDM controls
iOS
 Supervised - DEP
Yes
  • Email only: 
    BlackBerry Secure Gateway
  • Email and apps: 
    BlackBerry Secure Connect Plus
  • Dynamics apps: 
    BlackBerry Proxy
MDM controls
iOS
 Supervised - 
Apple Configurator
  2
Yes
  • Email and apps: 
    BlackBerry Secure Connect Plus
  • Dynamics apps: 
    BlackBerry Proxy
MDM controls
Microsoft Intune
Yes
  • Email and apps: 
    BlackBerry Secure Connect Plus
  • Dynamics apps: 
    BlackBerry Proxy
User privacy
Enterprise email only
Yes
  • iOS
     email app only: 
    BlackBerry Secure Gateway
User privacy
Work Apps catalog (
BlackBerry UEM Client
)
No
  • Behind the firewall with Activation Profile: Allow VPN management
  • VPN profile
User privacy
BlackBerry Dynamics
Yes
  • Dynamics apps: 
    BlackBerry Proxy
User privacy
Microsoft Intune
Yes
  • Dynamics apps: 
    BlackBerry Proxy
Device registration for 
BlackBerry 2FA
 only
BlackBerry 2FA
 only
No

Android

The activation types in this section support 
Samsung Knox
 policies on 
Samsung
 devices and 
BlackBerry Dynamics
 for additional security in the work profile.
Activation type
Device management mode
UEM service for behind-the-firewall enterprise connectivity
Work and personal - user privacy
 (
Android Enterprise
 with work profile)
Android Enterprise
No
  • Third-party VPN
Work and personal - user privacy
 (
Android Enterprise
 with work profile) (Premium)
Android Enterprise
Yes
  • Email and apps: 
    BlackBerry Secure Connect Plus
Work space only
 (
Android Enterprise
 fully managed device)
Android Enterprise
  • Manual user activation
  • Zero-touch enrollment 
No
  • Third-party VPN
Work space only
  (
Android Enterprise
 fully managed device) (Premium)
Android Enterprise
  • Manual user activation
  • Zero-touch enrollment 
Yes
  • Email and apps: 
    BlackBerry Secure Connect Plus
Work and personal - full control
 (
Android Enterprise
 fully managed device with work profile)
Android Enterprise
No
  • Third-party VPN
Work and personal - full control
 (
Android Enterprise
 fully managed device with work profile) (Premium)
Android Enterprise
Yes
  • Email and apps: 
    BlackBerry Secure Connect Plus

Android
 legacy management types

As of 
Android
10, 
Google
 has deprecated the use of 
Android
 device administrator for 
Samsung Knox
 and 
MDM controls
 has been deprecated by 
Google
.
Activation type
Device management mode
UEM service for behind-the-firewall enterprise connectivity
MDM controls
Device Control and App Deployment (
BlackBerry UEM Client
)
No
MDM controls
BlackBerry Dynamics
Yes
  • Email and apps: 
    BlackBerry Proxy
MDM controls
Microsoft Intune
Yes
  • Email and apps: 
    BlackBerry Secure Connect Plus
  • Dynamics apps: 
    BlackBerry Proxy
Work and personal - full control
Samsung Knox
Yes
  • Email and apps: 
    BlackBerry Secure Connect Plus
Work and personal - user privacy
Samsung Knox
Yes
  • Email and apps: 
    BlackBerry Secure Connect Plus
Work space only
Samsung Knox
Yes
  • Email and apps: 
    BlackBerry Secure Connect Plus
User privacy
Microsoft Intune
Yes
  • Dynamics apps: 
    BlackBerry Proxy
Device registration for 
BlackBerry 2FA
 only
BlackBerry 2FA
 only
No

BlackBerry 10

Activation type
Device management mode
UEM service for behind-the-firewall enterprise connectivity
Work and personal - Corporate
Work perimeter and user privacy perimeter
Yes
  • Email and apps: 
    BlackBerry Secure Connect Plus
     or 
    BlackBerry Dispatcher
     with Mobile Data Connection Service
Work and personal - Regulated
Work and personal perimeter regulation
Yes
  • Email and apps: 
    BlackBerry Secure Connect Plus
     or 
    BlackBerry Dispatcher
     with Mobile Data Connection Service
Work space only
Work perimeter only (Enterprise connectivity via 
BlackBerry Secure Connect Plus
 or 
BlackBerry Dispatcher
, MDS-CS)
Redundancy via 
BlackBerry Affinity Manager
Yes
  • Email and apps: 
    BlackBerry Secure Connect Plus
     or 
    BlackBerry Dispatcher
     with Mobile Data Connection Service

macOS
/
OS X

Activation type
Device management mode
UEM service for behind-the-firewall enterprise connectivity
MDM controls
Device management
No
  • Behind the firewall with VPN profile 

Windows

Activation type
Device management mode
UEM service for behind-the-firewall enterprise connectivity
MDM controls
Device management
No
  • Behind the firewall with VPN profile (
    Windows 10
    )  
MDM controls
BlackBerry Dynamics
Yes
  • Dynamics apps: 
    BlackBerry Proxy
MDM controls
Microsoft Intune
No (unless combined with 
BlackBerry Dynamics
)
  • Behind the firewall with VPN profile (
    Windows 10
    )