Specifications
Device type Conditions Result
• Device has a work space
password
• You enforce the work space
password as the full device
password using the "Apply
Work Space Password to
Full Device" IT policy rule
• The command changes the work space password
• The command changes the full device password
• The entire device locks, both passwords are
synchronized, and the new password is the
password for the entire device
• Device has a work space
password
• The user enforces the work
space password as the full
device password using the
"Use as my device
password" option
• The command changes the work space password
• The full device password is not affected
• The work space locks and the new password is the
work space password
Work space only
• These devices only have a
device password and that
password is mandatory
• The entire device locks and the new password is
the password for the entire device
If the BlackBerry Device Service cannot connect to a device because the device is off or not connected to a network, the
command is sent after the device connects to a network. You can communicate the new password to the user verbally
when the user locates the device. When the user unlocks the device, the device prompts the user to accept or reject the
new password.
You can also control how often a user must change their password by specifying the time that can elapse before a device
password expires using the "Maximum Password Age" IT policy rule.
BlackBerry Balance device users can change the work space password in the BlackBerry Balance settings on the device. If
the "Apply Work Space Password to Full Device" IT policy rule is set to No, a user can choose to use the same password for
the entire device.
For more information about sending the “Specify new device password and lock device” IT administration command to a
device, see the BlackBerry Device Service Advanced Administration Guide.
Data flow: When you change the work space password on a BlackBerry
Balance device running BlackBerry 10 OS
1. You send the "Specify new device password and lock device" IT administration command to the device.
2. The device sends the encrypted intermediate key to the Enterprise Management Web Service.
3. The Enterprise Management Web Service uses the private key that is associated with the device to decrypt the
intermediate key and sends the intermediate key back to the device.
Security Technical Overview Protecting data
95