Blackberry Enterprise IT Policies

Introduction

Companies/organisations commonly use Blackberry Enterprise Service (BES) for managing Blackberry devices. It is quite common for administrators to apply comprehensive IT policies which may inhibit Watchberry from running or making data connections to the outside world.

The list of BES IT policies below provides administrators with an indication of the policies that should be investigated to solve data connection issues. Note, you may not have all policy settings listed below.

The tables below can be printed as they have space to record your configuration. Please email us your configuration settings so we can advise configuration options.

MDS Policy Group

Policy RuleDescriptionYour Configuration
Disable activation with public MDSSSpecify whether or not the BlackBerry device can connect to public BlackBerry MDS Services. 
Disable user-initiated activation with MDSSSpecify whether or not the BlackBerry device user can initiate a connection with BlackBerry MDS Services. 
Disable MDS Runtime EnvironmentSpecify whether or not the BlackBerry Mobile Data System (MDS) Runtime™ environment is disabled on the BlackBerry device. 

Security Policy Group

Policy RuleDescriptionYour Configuration
Allow External ConnectionsSpecify whether or not applications, including third-party applications, on the BlackBerry device can initiate external connections (for example, to WAP, SMS, or other public gateways). 
Allow Internal ConnectionsSpecify whether or not applications, including third-party applications, on the BlackBerry device can initiate internal connections (for example, to the BlackBerry MDS Connection Service. 
Allow Split-Pipe ConnectionsSpecify whether or not applications, including third-party applications, can open internal and external connections simultaneously on the BlackBerry device. 
Disallow Third Party Application DownloadsSpecify whether or not applications that are not digitally signed by RIM are permitted on the BlackBerry device, whether the BlackBerry device user tries to download the applications from a web site or link, or the BlackBerry Enterprise Server or another party sends the applications to the BlackBerry device. 
Force Lock When HolsteredSpecify whether or not the BlackBerry device is security-locked when the user places it in the holster. 

Service Exclusivity policy group

Policy RuleDescriptionYour Configuration
Allow Other Browser ServicesSpecify whether or not the BlackBerry device permits other browser services. This IT policy rule forces browser traffic through your company’s BlackBerry Enterprise Server and prevents users from installing other browser services. 

TCP policy group

Policy RuleDescriptionYour Configuration
TCP APNSpecify whether or not a default Access Point Name (APN) can be imposed on the BlackBerry device when it uses the Transmission Control Protocol (TCP). 
TCP PasswordSpecify whether or not a default APN password can be imposed on the BlackBerry device when it uses the TCP. 
TCP UsernameSpecify whether or not a default APN user name can be imposed on the BlackBerry device when it uses the TCP. 

Application control policy rule descriptions

Policy RuleDescriptionYour Configuration
Internal DomainsSpecify the internal domain names to which the application can establish a connection. 
External DomainsSpecify the external domain names to which the application can establish a connection. 
Internal Network ConnectionsSpecify whether or not the application can make internal network connections. You can use this rule to permit or prevent the application from sending or receiving any data on the BlackBerry device using an internal protocol (for example, using corporate MDS, or to require the user to respond to a prompt on the BlackBerry device to permit internal connections through the BlackBerry device firewall. 
External Network ConnectionsSpecify whether or not the application can make external network connections. You can use this rule to permit or prevent the application from sending or receiving any data on the BlackBerry device using an external protocol (for example, using a WAP gateway, public MDS, or TCP), or to require the user to respond to a prompt on the BlackBerry device to permit external connections through the BlackBerry device firewall. 
Device GPSSpecify whether or not the application can access the BlackBerry device Global Positioning System (GPS) APIs. You can use this rule to permit or prevent the application from accessing the GPS APIs on the BlackBerry device or to require the user to respond to a prompt on the BlackBerry device to permit access to the GPS APIs. 

BlackBerry MDS Services policy rules

Policy RuleDescriptionYour Configuration
Allow Application Install by UserSpecify whether or not users can install BlackBerry MDS Studio applications on their BlackBerry devices. The following values are permitted: 0 = Users cannot install BlackBerry MDS Studio applications. 2 = Users can install BlackBerry MDS Studio applications. 
Allow Push Application InstallSpecify whether or not the BlackBerry Enterprise Server administrator can send BlackBerry MDS Studio applications to the BlackBerry device for installation. 

Once we’ve investigated your BES IT policies, we have a data connection BES Test Application we can share with you which can produce a report you can email to us to assist with other configurations.