Specifications
5 Managing certificates on devices ................................................................................................... 38
Certificates that the BlackBerry Device Service and a device use to authenticate with each other ...................................... 38
Using SCEP to enroll client certificates to a device ............................................................................................................. 39
Managing certificates that a device enrolls using SCEP ............................................................................................... 39
Data flow: Enrolling a client certificate to a device using SCEP .................................................................................... 40
Sending CA certificates to devices .................................................................................................................................... 41
6 Using IT policies to manage BlackBerry Device Service security ..................................................... 43
Preconfigured IT policy ..................................................................................................................................................... 43
Resolving IT policy conflicts .............................................................................................................................................. 44
7 Using BlackBerry Balance to secure BlackBerry 10 devices in your organization’s environment
for work use and personal use ....................................................................................................... 45
Securing work and personal data and apps on devices ...................................................................................................... 46
How devices classify work and personal data and apps ............................................................................................... 47
How the BlackBerry Device Service and devices protect work and personal data and apps ......................................... 49
How the BlackBerry Device Service and devices manage work and personal data and apps ........................................ 52
Controlling how work and personal apps connect to your organization's network ................................................................ 57
Preventing personal apps on devices from using your organization’s networks to connect to the Internet ..................... 61
Preventing the BBM Video feature on devices from using your organization’s networks ............................................... 62
8 Using BlackBerry Balance to secure BlackBerry PlayBook tablets in your organization’s
environment for work use .............................................................................................................. 63
How BlackBerry PlayBook tablets distinguish between work data and personal data .......................................................... 63
How BlackBerry PlayBook tablets protect work data ................................................................................................... 64
Controlling when BlackBerry PlayBook tablets delete all data in the work space .......................................................... 66
How a BlackBerry PlayBook tablet protects personal data ................................................................................................. 67
What happens when a user updates or creates files on a BlackBerry PlayBook tablet ......................................................... 68
How a BlackBerry PlayBook tablet controls whether an app is a work or personal app ........................................................ 68
Determining which apps are work or personal apps .................................................................................................... 69
Comparison of work and personal apps ...................................................................................................................... 70
Access rights for work and personal data that the BlackBerry PlayBook OS grants to apps .......................................... 70
How a BlackBerry PlayBook tablet is designed to prevent BlackBerry Runtime for Android apps from accessing
work data or apps ...................................................................................................................................................... 71
Controlling the network connections that work and personal apps on BlackBerry PlayBook tablets can access ................... 71
Using the browser to connect a BlackBerry PlayBook tablet to web servers that support NTLM ................................... 71
How work apps are installed on a BlackBerry PlayBook tablet ........................................................................................... 72
When a BlackBerry PlayBook tablet prevents a user from accessing work data or apps ............................................... 72
9
Securing work space only devices .................................................................................................. 73
Securing data ................................................................................................................................................................... 73
Classifying data ......................................................................................................................................................... 74
Protecting data .......................................................................................................................................................... 74
Managing data .......................................................................................................................................................... 75