Skip Navigation

Android
: Enterprise connectivity profile settings

Setting
Description
Enable 
BlackBerry Secure Connect Plus
This setting specifies whether work apps use 
BlackBerry Secure Connect Plus
 for sending work data between devices and your network.
Enterprise connectivity for 
Android
 devices with a work space
This setting specifies whether 
Android Enterprise
 and 
Samsung Knox Workspace
 devices use 
BlackBerry Secure Connect Plus
 for all apps in the work space, or only for specified apps.
  • "Container wide VPN" uses a VPN connection for all apps in the work space on the device.
  • "Per-app VPN" uses a VPN connection only for specified apps.
Apps restricted from using 
BlackBerry Secure Connect Plus
This setting specifies apps in the work space on 
Android Enterprise
 devices that are not allowed to use 
BlackBerry Secure Connect Plus
.
Click The Add icon and type the app package ID. Repeat as necessary to restrict additional apps.
By default, 
Google Play
 and underlying services (com.android.providers.media, com.android.vending, com.google.android.gms, and com.google.android.apps.gcs) are restricted because 
Google Play
 does not have proxy support. It is recommended to keep these restrictions in place. If you remove any of these restrictions, you must contact 
Google Play
 support for the firewall configuration required to allow connections to 
Google Play
 using 
BlackBerry Secure Connect Plus
.
If the “Force work apps to only use VPN” IT policy rule is applied to the device, this setting is ignored and no work apps, including the 
BlackBerry UEM Client
 and 
Google Play
 are restricted from using BlackBerry Secure Connect Plus. In this case you will have to open ports in the firewall to allow the 
BlackBerry UEM Client
 to communicate with the 
BlackBerry Infrastructure
 through 
BlackBerry UEM
. For more information about opening ports in the firewall when work apps use 
BlackBerry Secure Connect Plus
, visit support.blackberry.com/community to read article 48330.
If your organization uses 
BlackBerry Dynamics
 apps, it is recommended that you restrict the apps from using 
BlackBerry Secure Connect Plus
. If you don't, you must open additional ports in your organization’s firewall to allow the apps to send data to the 
BlackBerry Dynamics NOC
, and network activity from the apps might be delayed because data is routed to both the 
BlackBerry Infrastructure
 and 
BlackBerry Dynamics NOC
.
This setting is valid only if the "Enterprise connectivity for 
Android
 devices with a work space" setting is set to "Container wide VPN."
Apps allowed to use Enterprise Connectivity
This setting specifies apps in the work space on 
Android Enterprise
 and 
Samsung Knox Workspace
 devices that are allowed to use 
BlackBerry Secure Connect Plus
. You can select apps from a list of available apps or specify the app package ID.
This setting is valid only if the "Enterprise connectivity for 
Android
 devices with a work space" setting is set to "Per-app VPN."
Proxy profile
If you want to route secure tunnel traffic from 
Samsung Knox
 devices with 
Android Enterprise
 activations and 
Samsung Knox Workspace
 2.5 and later devices to the work network through a proxy server, select the appropriate proxy profile.
This setting does not apply to 
Android Enterprise
 devices other than 
Samsung Knox
 devices or to devices with 
Samsung Knox Workspace
 version 2.4 and earlier.