Skip Navigation

Server and device requirements for 
BlackBerry Secure Connect Plus

To use 
BlackBerry Secure Connect Plus
, your organization's environment must meet the following requirements.
For the 
BlackBerry UEM
 domain:
  • Your organization's firewall must allow outbound connections over port 3101 to 
    <region>
    .turnb.bbsecure.com and 
    <region>
    .bbsecure.com. If you configure 
    BlackBerry UEM
     to use a proxy server, verify that the proxy server allows connections over port 3101 to these subdomains. For more information about domains and IP addresses to use in your firewall configuration, visit http://support.blackberry.com/community to read article 36470.
  • In each 
    BlackBerry UEM
     instance, the 
    BlackBerry Secure Connect Plus
     component must be running.
  • By default, 
    Android Enterprise
     devices are restricted from using 
    BlackBerry Secure Connect Plus
     to connect to 
    Google Play
     and underlying services (com.android.providers.media, com.android.vending, and com.google.android.apps.gcs). 
    Google Play
     does not have proxy support. 
    Android Enterprise
     devices use a direct connection over the Internet to 
    Google Play
    . These restrictions are configured in the Default enterprise connectivity profile and in any new enterprise connectivity profiles that you create. It is recommended to keep these restrictions in place. If you remove these restrictions, you must contact 
    Google Play
     support for the firewall configuration required to allow connections to 
    Google Play
     using 
    BlackBerry Secure Connect Plus
If your on-premises environment includes 
Knox Workspace
 or 
Android Enterprise
 devices with 
BlackBerry Dynamics
 apps, see Optimize secure tunnel connections for Android devices that use BlackBerry Dynamics apps.
If you use an email profile to enable the 
BlackBerry Secure Gateway
 for 
iOS
 devices, it is a best practice to configure per-app VPN for 
BlackBerry Secure Connect Plus
. For more information about the 
BlackBerry Secure Gateway
, see Protecting email data using the BlackBerry Secure Gateway.
For supported devices:
Device
Requirements
iOS
  • Devices must be activated using the 
    BlackBerry UEM Client
    , available from the 
    App Store
  • MDM controls
     activation type
Android Enterprise
  • Any of the following activation types:
    • Work space only
       (Premium)
    • Work and personal - full control
       (Premium)
    • Work and personal - user privacy
       (Premium)
Samsung Knox Workspace
  • Samsung Knox
     MDM 5.0 or later
  • Samsung Knox
     2.3 or later
  • Any of the following activation types:
    • Work space only
       (
      Samsung Knox
      )
    • Work and personal - full control
       (
      Samsung Knox
      )
    • Work and personal - user privacy
       (
      Samsung Knox
      )
BlackBerry 10
  • BlackBerry 10
     OS version 10.3.2 or later
  • Any of the following activation types:
    • Work and personal - Corporate
    • Work space only
    • Work and personal - Regulated