Create a BlackBerry Persona policy
BlackBerry Persona
policyYou create a
BlackBerry Persona
policy to define which risk engines you want Persona
to use to determine user risk levels and the actions that the service should take for different types and levels of risk. How you configure the policy determines how Persona
enforces adaptive security standards that are appropriate for each user’s current activity and context.
Persona
offers several actions for the different types and levels of risk, from enforcing UEM group assignments to temporarily blocking BlackBerry
Dynamics
apps. For more information about how Persona
resolves conflicting assignments, see Resolving conflicting assignments and precedence rules.- In theBlackBerry Persona Analytics Portal, on the menu bar, clickPolicies.
- Click
.
- Type a name and description for the policy.
- If you don't wantPersonato take action for identity risk levels, turn offBehavioral pattern riskandApp anomaly riskand skip to step 7.
- To configure an action for a behavioral pattern or app anomaly risk, click
next to the risk level and do any of the following:
- ClickAssign to UEM group. Select a group from the list.
- ClickBlackBerry Dynamics apps actionand do one of the following:
- ClickAssign BlackBerry Dynamics override profile. Select a profile from the list.
- ClickBlock all BlackBerry Dynamics apps.
- ClickBlock the BlackBerry Dynamics app that initiated the request.
The Block allBlackBerry Dynamicsapps and Block theBlackBerry Dynamicsapp that initiated the action are available for the Critical and High risk levels only. - To allow users to reduce their behavioral risk level to low by completing aBlackBerry 2FAauthentication prompt, do the following:
- In theIdentity risksection, clickAutomatic risk reduction.
- In the drop-down list, click the risk levels that will allow automatic risk reduction.
- ClickApply.
If a user successfully authenticates to access aBlackBerry Dynamicsapp, the user cannot be prompted for another authentication (for example, a continuous authentication prompt or automatic risk reduction prompt) for a grace period of at least 5 minutes. - Choose one of the following methods to manage geozone risk levels and actions:MethodSteps
- Use learned geozones
- Do not use defined geozones
- Verify thatLearned geozone riskis turned on.
- Turn offDefined geozone risk.
- To configure an action for a learned geozone risk level, click
next to a risk level and do any of the following:
- ClickAssign to UEM group. Select a group from the list.
- ClickBlackBerry Dynamics apps actionand do one of the following:
- ClickAssign BlackBerry Dynamics override profile. Select a profile from the list.
- In the high risk level, clickBlock all BlackBerry Dynamics apps.
- In the high risk level, clickBlock the BlackBerry Dynamics app that initiated the request.
- Use learned geozones
- Use defined geozones
- Optional: Take special actions for certain defined geozones
- Verify thatLearned geozone riskandDefined geozone riskare turned on.
- To configure the default risk actions for both learned and defined geozones, click
next to a risk level and do any of the following:
- ClickAssign to UEM group. Select a group from the list.
- ClickBlackBerry Dynamics apps actionand do one of the following:
- ClickAssign BlackBerry Dynamics override profile. Select a profile from the list.
- For defined geozones, clickBlock all BlackBerry Dynamics apps.
- For defined geozones, clickBlock the BlackBerry Dynamics app that initiated the request.
- If you want to take special actions for a certain defined geozone, click
in the top-right corner of the table and click the geozone. Click
for the defined geozone and select the desired actions.
- Do not use learned geozones
- Use defined geozones
- Optional: Take special actions for certain defined geozones
- Optional: Take special actions for users that are not in defined geozones
- Turn offLearned geozone risk.
- Verify thatDefined geozone riskis turned on.
- To configure an action for all defined geozones set to a certain risk level, click
next to the risk level and do any of the following:
- ClickAssign to UEM group. Select a group from the list.
- ClickBlackBerry Dynamics apps actionand do one of the following:
- ClickAssign BlackBerry Dynamics override profile. Select a profile from the list.
- ClickBlock all BlackBerry Dynamics apps.
- ClickBlock the BlackBerry Dynamics app that initiated the request.
- If you want to take special actions for a certain defined geozone, click
in the top-right corner of the table and click the geozone. Click
for the defined geozone and select the desired actions.
- If you want to take special actions for users that are not in defined geozones, in the top-right corner of the table, click> Undefined geozone. Click
for the undefined geozone and select the desired actions.
- Do not use learned or defined geozones
Turn offDefined geozone riskandLearned geozone risk. - ClickSave.