Installation guide

BlackBerry Enterprise Solution Security
Controlling BlackBerry devices 38
You can add a new IT policy rule to, remove a new IT policy rule from, or change the assigned value of a new IT
policy rule in an IT policy the same way that you change a standard IT policy rule in an IT policy.
The BlackBerry Manager groups the IT policy rules by common properties or by application. Most IT policy rules
are intended to be assigned to more than one BlackBerry device. Some IT policy rules configure a unique value
and are intended to be assigned to one BlackBerry device and one user only. See the BlackBerry Enterprise
Server Implementation Guide for Wireless LAN for more information on those IT policy rules.
Reverting to the default behavior
To revert to the default behavior that an IT policy rule customizes or controls, you can set that IT policy rule to
Default, if that setting is available, or delete the value that you previously set.
If you assign users to a new IT policy, you can delete that IT policy to revert those users to the default behavior
for all functionality on the BlackBerry device and desktop software. The BlackBerry Enterprise Server
automatically reassigns the users to the Default IT policy and resends the Default IT policy to the BlackBerry
device, enforcing the default settings. You cannot delete the Default IT policy.
Creating new IT policy rules to control custom applications
Create new IT policy rules to control custom applications that your company develops to run in BlackBerry
environments. After you create a new IT policy rule, you can add it to and assign a value to it in any new or
existing IT policy. Only your own custom applications can use new IT policy rules that you create. You cannot
create new IT policy rules to control standard BlackBerry device functionality.
Enforcing IT policy changes wirelessly
Wireless IT policy enables you to immediately enforce IT policy rule additions, deletions, or modifications on C++-
enabled BlackBerry devices running BlackBerry device software version 2.5 or later and on Java-enabled
BlackBerry devices running BlackBerry device software version 3.6 or later. When the BlackBerry device receives
an updated Default IT policy or a new IT policy, the BlackBerry device and BlackBerry Desktop Software apply
the configuration changes.
The BlackBerry Enterprise Server must resend the IT policy to the BlackBerry device to update the BlackBerry
device and desktop software behavior wirelessly. By default, the BlackBerry Enterprise Server is designed to
resend the IT policy to the BlackBerry devices of users that are assigned to that IT policy within a short period of
time after you update the IT policy.
You can also resend an IT policy to the user account of a specific BlackBerry device manually, and you can
configure the BlackBerry Enterprise Server to resend IT policies to BlackBerry devices on that specific BlackBerry
Enterprise Server at a scheduled interval whether or not you have changed the IT policies.
Enforcing device and desktop security
The BlackBerry Enterprise Solution offers a user many different security settings for the BlackBerry device and
BlackBerry Desktop Software. For example, you can specify one or more IT policy rules to enforce the following
behaviour to meet your corporate security requirements:
Enforce encryption
Enforce strong encryption
Enforce password or passphrase use
Enforce a strong password or passphrase
Secure Bluetooth connections
Protect user data on the BlackBerry device
Protect master encryption keys on the BlackBerry device
Restrict application use on the BlackBerry device
www.blackberry.com