Configure Constrained Delegation For The Microsoft Active Directory Account To Support Single Sign-On Authentication; Turn On Single Sign-On Authentication For The Blackberry Administration Service - Blackberry PRD-10459-016 - Enterprise Server For MS Exchange Administration Manual

Enterprise server for microsoft exchange
Hide thumbs Also See for PRD-10459-016 - Enterprise Server For MS Exchange:
Table of Contents

Advertisement

Administration Guide
screen and access the BlackBerry Administration Service and BlackBerry Web Desktop Manager directly. The BlackBerry
Monitoring Service does not support single sign-on authentication.
Before you turn on single sign-on, you must configure constrained delegation for the Microsoft Active Directory account for
the BlackBerry Administration Service.
Configure constrained delegation for the Microsoft
Active Directory account to support single sign-on
authentication
1.
Use the Windows Server ADSI Edit tool to add the following SPNs for the BlackBerry Administration Service pool to
the Microsoft Active Directory account :
HTTP/<BAS_pool_FQDN> (for example, HTTP/BASconsole104.example.com)
BASPLUGIN111/<BAS_pool_FQDN> (for example, BASPLUGIN111/BASconsole104.example.com)
2.
If you create separate pools of BlackBerry Administration Service instances and BlackBerry Web Desktop Manager
instances in the BlackBerry Administration Service pool, add the HTTP/<BAS_pool_FQDN> SPN for each pool to the
Microsoft Active Directory account.
3.
Configure the Microsoft Active Directory account for constrained delegation using the following settings:
trust this user for delegation to specific services only
use Kerberos only
4.
In the Microsoft Active Directory account properties, on the Delegation tab, add BASPLUGIN111/
<BAS_pool_FQDN> to the list of services.
After you finish: For more information about configuring constrained delegation for the Microsoft Active Directory account
so you can access the BlackBerry Administration Service, visit
Turn on single sign-on authentication for the
BlackBerry Administration Service
1.
In the BlackBerry Administration Service, on the Servers and components menu, expand BlackBerry Solution
topology > BlackBerry Domain > Component view.
2.
Click BlackBerry Administration Service.
3.
On the Microsoft® Active Directory® authentication tab, click Edit component.
270
Changing the security settings of the BlackBerry Administration Service and BlackBerry Web Desktop
www.blackberry.com/btsc
to read article KB22717.
Manager

Advertisement

Table of Contents
loading

Table of Contents