User guide

1. The BlackBerry device user navigates to a resource on your organization’s intranet or on a file share (for example, a
web page or shared file) using the BlackBerry Browser or Files application on the BlackBerry device.
2. The device encrypts and compresses an HTTP request for the resource and sends the encrypted HTTP request to the
BlackBerry Router using BlackBerry transport layer encryption.
3. The BlackBerry Router forwards the encrypted HTTP request to the BlackBerry Dispatcher.
4. The BlackBerry Dispatcher decrypts and decompresses the HTTP request and forwards the request to the BlackBerry
MDS Connection Service.
5. The BlackBerry MDS Connection Service performs the following actions:
verifies whether the resource is located in a Microsoft Active Directory domain that is configured for Integrated
Windows authentication
checks the pull rules assigned to the user accounts and verifies that the user must use Integrated Windows
authentication to access the resource
connects to the Microsoft Active Directory using its Microsoft Active Directory account that is configured for
constrained delegation
retrieves the Microsoft Active Directory user name for the user from Microsoft Active Directory
retrieves the Kerberos service ticket for the user from Microsoft Active Directory using the S4U2proxy extension
encodes the service ticket using Base-64 encoding and adds the service ticket to the header of the HTTP request
resends the request for the resource to the web server or file system that hosts the resource
6. The web server or file system returns the resource to BlackBerry MDS Connection Service.
7. The BlackBerry MDS Connection Service forwards the resource to the BlackBerry Dispatcher.
8. The BlackBerry Dispatcher encrypts and compresses the resource and splits it into packages and sends the packages
to the BlackBerry Router.
9. The BlackBerry Router sends the packages to the device using BlackBerry transport layer encryption.
10. The device decrypts and decompresses the packages and displays the resource to the user.
Security Technical Overview Protecting communications in your organization's environment
97