User guide

environment and authenticate and authorize users. The Kerberos protocol is designed to permit the BlackBerry MDS
Connection Service to verify user accounts in Microsoft Active Directory. Constrained delegation is designed to limit the
resources that the BlackBerry MDS Connection Service can provide authenticated users access to.
If you want to configure both BlackBerry Administration Service single sign-on and BlackBerry MDS Connection Service
integrated authentication, you should configure separate Microsoft Active Directory accounts for the BlackBerry
Administration Service
and BlackBerry MDS Connection Service.
Architecture: BlackBerry MDS Connection Service
integrated authentication
Component Description
BlackBerry MDS Connection Service The BlackBerry MDS Connection Service permits BlackBerry device users to
access web content, the Internet, or your organization's intranet. It also permits
applications on devices to connect to your organization's application servers or
content servers for application data and updates.
domain controller A domain controller is a server that authenticates and authorizes Windows users
and Windows servers with a Windows domain.
Microsoft Active Directory Microsoft Active Directory is an LDAP directory that stores user information.
Security Technical Overview Protecting communications in your organization's environment
95