Blackberry PRD-10459-003 Administration Guide - Page 268

Configuring Integrated Windows authentication so that users can access resources on your organization's network, Configuring the Microsoft Active Directory account to delegate access

Page 268 highlights

Administration Guide Configuring Integrated Windows authentication so that users can access resources on your organization's network MIME type other Maximum number of bytes per connection (KB) 2048 Related topics Configure download limits for media content types, 265 Configuring Integrated Windows authentication so that users can access resources on your organization's network To permit BlackBerry® device users to access resources on your organization's network using BlackBerry devices without requiring the users to type a user name and password each time they access the network resources, you can configure the BlackBerry MDS Connection Service to support Integrated Windows® authentication. Users can then access network resources such as intranet sites and network shared folders on their devices using the BlackBerry® Browser or Files application without typing a user name and password. Before you configure the BlackBerry MDS Connection Service to support Integrated Windows authentication, you must create a Microsoft® Active Directory® account in each Microsoft Active Directory domain that includes resources that you want to turn on Integrated Windows authentication for. You must configure constrained delegation for the Microsoft Active Directory accounts so that they delegate access to each intranet site or network shared folder in the Microsoft Active Directory domain. You must also configure two-way trust between the Microsoft Active Directory domain that the BlackBerry MDS Connection Service is running on and other Microsoft Active Directory domains in other forests that the BlackBerry MDS Connection Service must connect to. The S4U2proxy extension that the BlackBerry MDS Connection Service uses to retrieve the Kerberos™ service tickets for users requires a two-way trust between Microsoft Active Directory domains. After you turn on Integrated Windows authentication and specify a Microsoft Active Directory account in the BlackBerry Administration Service, you must specify web address patterns for the network resources that you want to permit users to access, create a pull rule for the web address patterns, permit access to the web address patterns using the pull rule, and assign the pull rule to users or a group. After you configure the BlackBerry MDS Connection Service to support Integrated Windows authentication, the BlackBerry MDS Connection Service uses the Microsoft Active Directory account to verify login information for a user and access the network resources on behalf of the user. The BlackBerry Enterprise Server then sends information from the network resources to the user's device. Configuring the Microsoft Active Directory account to delegate access Prerequisites: Configuring the Microsoft Active Directory account to delegate access to an intranet site • Verify that you configured Integrated Windows® authentication for the application server that hosts the intranet site. 266

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420

MIME type
Maximum number of bytes per connection (KB)
other
2048
Related topics
Configure download limits for media content types, 265
Configuring Integrated Windows authentication so that
users can access resources on your organization's network
To permit BlackBerry® device users to access resources on your organization's network using BlackBerry devices
without requiring the users to type a user name and password each time they access the network resources, you
can configure the BlackBerry MDS Connection Service to support Integrated Windows® authentication. Users can
then access network resources such as intranet sites and network shared folders on their devices using the
BlackBerry® Browser or Files application without typing a user name and password.
Before you configure the BlackBerry MDS Connection Service to support Integrated Windows authentication, you
must create a Microsoft® Active Directory® account in each Microsoft Active Directory domain that includes resources
that you want to turn on Integrated Windows authentication for. You must configure constrained delegation for the
Microsoft Active Directory accounts so that they delegate access to each intranet site or network shared folder in
the Microsoft Active Directory domain.
You must also configure two-way trust between the Microsoft Active Directory domain that the BlackBerry MDS
Connection Service is running on and other Microsoft Active Directory domains in other forests that the BlackBerry
MDS Connection Service must connect to. The S4U2proxy extension that the BlackBerry MDS Connection Service
uses to retrieve the Kerberos™ service tickets for users requires a two-way trust between Microsoft Active Directory
domains.
After you turn on Integrated Windows authentication and specify a Microsoft Active Directory account in the
BlackBerry Administration Service, you must specify web address patterns for the network resources that you want
to permit users to access, create a pull rule for the web address patterns, permit access to the web address patterns
using the pull rule, and assign the pull rule to users or a group.
After you configure the BlackBerry MDS Connection Service to support Integrated Windows authentication, the
BlackBerry MDS Connection Service uses the Microsoft Active Directory account to verify login information for a user
and access the network resources on behalf of the user. The BlackBerry Enterprise Server then sends information
from the network resources to the user's device.
Configuring the Microsoft Active Directory account to delegate access
Prerequisites: Configuring the Microsoft Active Directory account to delegate access
to an intranet site
Verify that you configured Integrated Windows® authentication for the application server that hosts the intranet
site.
Administration Guide
Configuring Integrated Windows authentication so that users can access resources on your
organization's network
266