Installation guide
BlackBerry Enterprise Solution Security
Controlling BlackBerry devices 39
• Restrict device resources available to third-party applications
See the Policy Reference Guide for more information.
Controlling BlackBerry device access to the BlackBerry Enterprise Server
Turn on the Enterprise Service Policy to control which BlackBerry devices can connect to the BlackBerry
Enterprise Server. After you turn on the Enterprise Service Policy, the BlackBerry Enterprise Server still permits
connections from BlackBerry devices and BlackBerry-enabled devices that you previously added to the
BlackBerry Enterprise Server, but it prevents connections from newly-added BlackBerry devices by default.
Define BlackBerry device criteria in an approval list to turn on and turn off BlackBerry Enterprise Server access
for BlackBerry devices. BlackBerry devices that meet the approval list criteria can complete wireless enterprise
activation on that BlackBerry Enterprise Server.
You can define the following types of criteria:
• specific, permitted BlackBerry device PINs as a string
• a permitted range of BlackBerry device PINs
You can also control access based on specific manufacturers and models of BlackBerry devices. The BlackBerry
Manager includes lists of permitted manufacturers and models based on the properties of BlackBerry devices
already added to the BlackBerry Enterprise Server. You can uncheck items on these lists to prevent further
connections from BlackBerry devices of a specific manufacturer or model.
You can permit a specific user to override the Enterprise Service Policy. If you then configure the approval list
with criteria that excludes that user’s BlackBerry device or BlackBerry-enabled device, the user can still connect
to the BlackBerry Enterprise Server.
See the BlackBerry Enterprise Server System Administration Guide for more information.
Protecting Bluetooth connections on BlackBerry devices
Bluetooth® wireless technology enables Bluetooth-enabled BlackBerry devices to establish a wireless connection
with devices that are within a 10-meter range. Bluetooth-enabled BlackBerry devices can connect to other
Bluetooth-enabled devices such as a hands-free car kit or wireless headset.
Bluetooth profiles specify how applications on Bluetooth-enabled BlackBerry devices and on other Bluetooth
devices connect and are interoperable. Bluetooth-enabled BlackBerry devices implement their Bluetooth serial
port profiles to establish serial connections to Bluetooth peripherals using virtual serial ports. The Bluetooth
software on the BlackBerry device accesses the serial port through the BlackBerry Software Development Kit.
You can use IT policies to simultaneously manage all Bluetooth-enabled BlackBerry devices. By default,
Bluetooth-enabled BlackBerry devices that are running BlackBerry Device Software version 4.0 or later include
the following security measures:
• The Bluetooth radio is turned off on the BlackBerry device.
• Users must request a connection or pairing on the BlackBerry device with another Bluetooth device. Users
must also type a shared secret key (called a passkey) to complete the pairing.
• Users can specify whether to encrypt data traffic to and from the BlackBerry device over Bluetooth
connections. The BlackBerry Enterprise Solution uses the passkey to generate encryption keys.
• The BlackBerry device prompts the user each time a Bluetooth device attempts to connect to the BlackBerry
device.
See Security for BlackBerry Devices with Bluetooth Wireless Technology for more information.
www.blackberry.com