INTRODUCING BLACKBERRY SPARK - ZERO TRUST SECURITY AND ZERO TRUST ACCESS JANUARY 2021 - BLACKBERRY DOCS

Page created by Gordon Alexander
 
CONTINUE READING
Introducing BlackBerry Spark
Zero Trust security and Zero Trust access

January 2021
2021-01-13Z

       | |2
Contents

What is BlackBerry Spark..................................................................................4

What is Unified Endpoint Security?................................................................... 5

BlackBerry Spark Suites....................................................................................6
      BlackBerry   Spark   Suite...........................................................................................................................................6
      BlackBerry   Cyber   Suite...........................................................................................................................................7
      BlackBerry   Spark   UEM Suite..................................................................................................................................9
      BlackBerry   Spark   UEM Express Suite................................................................................................................. 12

How UES products work together....................................................................14

How UEM products work together...................................................................16

Legal notice.................................................................................................... 18

                                                                                                                                                                               | | iii
What is BlackBerry Spark
BlackBerry Spark combines our trusted UEM solution with the latest UES technology so you can give your
employees all the tools they need to be productive when working outside of the office while protecting your
users, devices, and data from security threats. BlackBerry Spark offers several suites of products that will protect
your valuable assets and improve productivity. Achieving both high security and high productivity requires Zero
Trust security with a Zero Touch experience.
For many years, BlackBerry Unified Endpoint Management (UEM) and its predecessors, including BES5 and
BES12, have been recognized by governments, corporations, and other organizations as the leading solution
to manage employees' mobile devices and secure the important data on them. Today, organizations face a
complex IT environment where employees use their own laptops, smartphones, and tablets to work remotely and
organizations rely on cloud-based Software-as-a-Service (SaaS) solutions where vital applications and data are
outside the firewall. At the same time, cyber threats are ever-more sophisticated and pervasive. Along with UEM,
many organizations need advanced Unified Endpoint Security (UES) to detect and prevent cyber attacks.
Zero Trust means that users can't access anything on any device until they prove who they are, that their access
is authorized, and that they, or malware apps on their device, are not acting maliciously. Users must continually
earn this trust; entering a password or using two-factor authentication once is no longer enough. However, the
true value of Zero Trust depends on whether it can also provide a positive experience for users. Organizations
must find a balance between continuous threat protection and user productivity. If a Zero Trust environment
produces excessive security hurdles and inconvenience for users, they will try to circumvent the system and
render it useless.
Zero Touch delivers immediate productivity with instant access to your organization's resources without the
regular interruptions caused by passwords, timeouts, special permissions, or multiple authentications. When
Zero Trust solutions provide a path to Zero Touch, organizations get both the security they can trust to defend
against cyber threats and a positive user experience that fosters productivity.

                                                                                                 | What is BlackBerry Spark | 4
What is Unified Endpoint Security?
Unified Endpoint Security (UES) is a security solution designed for the new reality. It
consolidates the best available AI-driven tools for detecting, protecting against, and remediating threats to every
endpoint. Today’s cyber criminals use artificial intelligence (AI) to create increasingly advanced threats
that maximize the reach and impact of their attacks. Today’s solutions must also exploit the power of machine
learning and AI. UES provides an AI-powered solution for Zero Trust across the spectrum of devices, networks,
apps, and people. UES offers a broad set of security capabilities through several interconnected technologies:

 Technology                       Description

 Endpoint Protection              Endpoint protection predicts and prevents cyber attacks by blocking malware
                                  before it can affect a device. BlackBerry uses machine learning techniques
                                  to analyze potential file executions for malware in the operating system and
                                  memory layers to prevent the delivery of malicious payloads. This approach
                                  renders new malware, viruses, and bots useless.

 Endpoint Detection and           EDR collects information from endpoints in your organization and aggregates
 Response (EDR)                   it using AI to track, alert upon, and respond to malicious situations as they
                                  unfold. AI-based endpoint detection and response stops attacks before they
                                  can execute and automates investigation and response to attacks.

 Mobile Threat Defense (MTD)      MTD uses AI and machine learning to monitor mobile devices and the apps
                                  running on them to proactively identify and prevent cyber threats by providing
                                  recommendations or taking appropriate actions to remediate potentially
                                  dangerous situations.

 User and Entity Behavior         UEBA continuously assesses users' ongoing behavior, including network
 Analytics (UEBA)                 connections, app usage, and user actions across mobile and desktop devices
                                  and compares current behavior to established patterns to assess risk level
                                  and dynamically adjust security and authentication requirements for users
                                  accordingly.

 Secure Access Service Edge       A SASE combines network security functions such as a secure web gateway,
 (SASE)                           which uses malware detection, URL filtering, and other mechanisms to
                                  block unsafe access to internet destinations, and a cloud access security
                                  broker (CASB), which acts as a go-between for devices that access SaaS
                                  applications and other cloud services, to provide network security-as-a-service
                                  that both gives your users access to cloud-based applications outside your
                                  firewall and protects your extended network from threats.

                                                                                       | What is Unified Endpoint Security? | 5
BlackBerry Spark Suites
BlackBerry Spark Suites offer unified endpoint management and endpoint security solutions to meet the needs of
businesses and organizations.

 Suite                         Description

 BlackBerry Spark Suite        The BlackBerry Spark Suite is the gold standard for unified endpoint security and
                               unified endpoint management. It combines the BlackBerry Spark UEM Suite and
                               BlackBerry Cyber Suite into one package that provides the utmost in endpoint
                               management and security to protect your organization against multiple threats.

 BlackBerry Cyber Suite        The BlackBerry Cyber Suite provides unified endpoint security for your
                               organization to monitor and prevent malicious attacks using AI-driven intelligence
                               and response mechanisms. BlackBerry Cyber Suite works with all MDM providers
                               to meet your security needs, even when your device management needs don't
                               require the sophistication of BlackBerry UEM.

 BlackBerry Spark UEM          The BlackBerry Spark UEM Suite provides best-in-class unified endpoint
 Suite                         management. It includes full-featured BlackBerry UEM, which has long been
                               trusted by governments, corporations, and other organizations to manage and
                               secure communication with mobile devices, plus identity management, two-factor
                               authentication, and digital rights management so that users can securely access
                               work resources and work from anywhere.

 BlackBerry Spark UEM          The BlackBerry Spark UEM Express Suite is an ideal device management and
 Express Suite                 productivity solution for smaller business and organizations. It includes the
                               essential features to manage users' devices, whether devices are provided
                               by your organization or owned by your employees, while protecting your data.
                               You can equip users to be productive with work apps that provide secure work
                               email, secure Web browsing and intranet access, task management, and instant
                               messaging.

For a visual overview of the BlackBerry Spark Suites, see the visual introduction.
For a full list of the products and features available in each suite, see the BlackBerry Enterprise Licensing Guide.

BlackBerry Spark Suite
Security-conscious organizations are moving to a Zero Trust approach to modernize network security while
simultaneously enhancing and improving the network experience for end users. The Zero Trust security model
trusts nothing and no one by default, including users inside the work network. Every user, endpoint, and network
are assumed to be potentially hostile. In Zero Trust security, no user can access anything until they prove who
they are, that their access is authorized, that the network they are connected to is not compromised, and that they,
or malware hiding on their device, are not acting maliciously.
TheBlackBerry Spark Suite combines the Zero Trust Unified Endpoint Security model offered by BlackBerry Cyber
Suite and the proven BlackBerry Spark UEM Suite for endpoint management to provide the full range of BlackBerry
enterprise products to manage and secure all of your endpoints and the communications between them. With this
suite you get all of the products in the Cyber Suite and the Spark UEM Suite plus the ability to manage BlackBerry
Protect Mobile from the management console of either suite.

                                                                                                   | BlackBerry Spark Suites | 6
See a visual introduction to the BlackBerry Spark Suite.

BlackBerry Cyber Suite
The BlackBerry Cyber Suite provides Unified Endpoint Security that works with any MDM platform. It allows
you to monitor and prevent malicious attacks on your resources and endpoints using AI-driven intelligence and
response mechanisms. It includes the latest endpoint security features to provide endpoint protection, mobile
threat defense, and continuous user authentication, managed through a single console.
BlackBerry Cyber Suite offers these advantages:
•    Provides a path from Zero Trust architecture to Zero Touch experience powered by strong AI
•    Works with any Unified Endpoint Management (UEM) or Mobile Device Management (MDM) platform
•    Provides continuous monitoring and threat detection
•    Provides contextual and continuous authentication that spans endpoints, networks, apps, and people
Learn how the products in the BlackBerry Cyber Suite work together.
See a visual introduction to the BlackBerry Cyber Suite.
The BlackBerry Cyber Suite includes the following products:

    Product                             Description

                                        BlackBerry Protect detects and blocks malware and other threats before
                                        they can affect devices.
                                        BlackBerry Protect Desktop provides endpoint detection and response
                                        for Windows 10, macOS, and Linux devices, using a mathematical
                                        approach to malware identification. It uses machine learning techniques
                                        instead of reactive signatures, trust-based systems, or sandboxes.
                                        This approach renders new malware, viruses, bots, and future variants
                                        useless. BlackBerry Protect Desktop analyzes potential file executions
                                        for malware in the operating system and memory layers to prevent the
                 BlackBerry Protect     delivery of malicious payloads.
                                        For more information, see the BlackBerry Protect Desktop
                                        documentation.
                                        BlackBerry Protect Mobile provides mobile threat defense for iOS
                                        and Android devices. In addition to malware identification, BlackBerry
                                        Protect Mobile also detects sideloaded apps, malicious URLs in text
                                        messages, and other security risks and recommends or takes action to
                                        eliminate the threat.
                                        For more information, see the BlackBerry Protect Mobile documentation.

                                                                                                | BlackBerry Spark Suites | 7
Product                         Description

                                BlackBerry Persona collects and analyzes data from devices and uses
                                machine learning to determine a user's risk level by dynamically
                                analyzing the user's real-world context, such as the user's location and
                                consistency with normal behavior patterns. The service can adapt device
                                and app behavior to the user's current level of risk. For example, if a
                                user's current risk level is high, BlackBerry Persona can limit the user's
          BlackBerry Persona
                                access to work apps and disable certain device features.
                                BlackBerry Persona Mobile is supported on iOS and Android devices. For
                                more information, see the BlackBerry Persona Mobile documentation.
                                BlackBerry Persona Desktop is supported on Windows 10 devices. For
                                more information, see the BlackBerry Persona Desktop documentation.

                                BlackBerry Optics monitors your Windows 10, macOS, and Linux
                                endpoints and lets you know when your organization may be under
                                attack. ptics collects information from endpoints in your organization
          BlackBerry Optics     and aggregates it using AI to track, alert upon, and respond to
                                malicious events as soon as they occur. ptics can stop attacks before
                                they execute and automate investigation and response to attacks.
                                For more information, see the BlackBerry Optics documentation.

                                BlackBerry Gateway provides network security-as-a-service . It is a new
                                product in development that is designed to provide a secure access
                                service edge (SASE) framework. SASE combines network security
                                functions such as Zero Trust network access, secure web gateways, and
          BlackBerry Gateway    cloud access security brokers (CASB) to provide network security that
                                both gives your users access to SaaS applications outside your network
                                perimeter and protects your extended network from threats.
                                BlackBerry Gateway is currently available as a beta and will be added to
                                the BlackBerry Cyber Suite for existing and new customers in 2021.

                                BlackBerry Enterprise Identity gives users single sign-on access to
                                software services, such as Microsoft SharePoint, Salesforce, Cisco
          BlackBerry            Webex, Box, Workday, and more.
          Enterprise Identity
                                For more information, see the BlackBerry Enterprise Identity
                                documentation.

                                BlackBerry 2FA protects access to your organization’s resources by
                                allowing users to respond to a prompt on their iOS or Android device as
          BlackBerry 2FA        a second factor of authentication in addition to their password when
                                logging into your network, your VPN, or SaaS applications.
                                For more information, see the BlackBerry 2FA documentation.

                                                                                         | BlackBerry Spark Suites | 8
Product                                Description

                                        The BlackBerry Spark SDK is a development tool that allows you to
                                        build Android and iOS apps that detect, evaluate, and respond to
                                        environmental risks and cyber threats in real time. With the Spark SDK,
                  BlackBerry Spark      you can build apps that are resistant to sophisticated mobile attacks and
                  SDK                   provide protection for your organization’s users and data.
                                        The BlackBerry Spark SDK is currently available as a public beta
                                        release that is available for early testing and evaluation purposes. For
                                        more information, see the BlackBerry Spark SDK documentation.

BlackBerry Spark UEM Suite
The BlackBerry Spark UEM Suite offers a full slate of products designed to provide best-in-class unified endpoint
management that meets the needs of medium and large organizations and organizations with enhanced security
needs. For many years, BlackBerry UEM and its predecessors have been trusted by governments, corporations,
and other organizations to manage and secure communication with mobile devices and other endpoints. The
Spark UEM Suite goes beyond mobile device management to provide productivity apps, identity management,
two-factor authentication, and document rights management. The Spark UEM Suite also offers SDKs to customize
your solution to meet the specific needs of your organization.
Learn how the products in the BlackBerry Spark UEM Suite work together.
See a visual introduction to the BlackBerry Spark UEM Suite.
The BlackBerry Spark UEM Suite includes the following products:
Server products

 Product                                Description

                                        BlackBerry UEM provides comprehensive device, app, and content
                                        management with integrated security and connectivity. It helps you
                                        manage iOS, Android, Windows 10, and macOS devices and keeps your
                  BlackBerry UEM        data safe on those devices. BlackBerry UEM is available as a cloud-
                                        based solution or can be installed on-premises.
                                        For more information, see the BlackBerry UEM documentation.

                                        BlackBerry Enterprise Identity gives users single sign-on access to
                                        software services, such as Microsoft SharePoint, Salesforce, Cisco
                  BlackBerry            Webex, Box, Workday, and more.
                  Enterprise Identity
                                        For more information, see the BlackBerry Enterprise Identity
                                        documentation.

                                        BlackBerry 2FA protects access to your organization’s resources by
                                        allowing users to respond to a prompt on their iOS or Android device as
                  BlackBerry 2FA        a second factor of authentication in addition to their password when
                                        logging into your network, your VPN, or SaaS applications.
                                        For more information, see the BlackBerry 2FA documentation.

                                                                                                  | BlackBerry Spark Suites | 9
Product                              Description

                                      BlackBerry Workspaces allows users to securely access, synchronize,
                                      edit, and share files and folders from their computers and mobile
                BlackBerry            devices. BlackBerry Workspaces protects files by applying digital rights
                Workspaces            management controls to limit access, even after they are shared with
                                      someone outside of your organization
                                      For more information, see the BlackBerry Workspaces documentation.

                                      BlackBerry UEM Notifications allows administrators to send critical
                                      messages and notifications to users and groups from the UEM
                                      management console via Text-To-Speech voice calls, SMS, and email.
                BlackBerry UEM        UEM Notifications is available for use with BlackBerry UEM on-premises
                Notifications         only.
                                      For more information, see the BlackBerry UEM Notifications
                                      documentation.

BlackBerry Dynamics Apps
BlackBerry Dynamics apps are collection of secure apps that allow you to boost productivity while safeguarding
valuable corporate data. They allow for encrypted communication between devices and application servers
behind the firewall with no need for a corporate VPN or ports to be opened through the firewall.

 Product                              Description

                                      BlackBerry Access is a secure web browser that gives users secure
                                      remote access to your organization's intranet and web-based
                                      applications.
                BlackBerry Access     BlackBerry Desktop combines BlackBerry Access and BlackBerry Work
                and BlackBerry        into a single package for Windows 10 and macOS devices to provide
                Desktop               both secure access to work email and secure access to web-based
                                      applications, including Cisco Webex, Zoom, and Salesforce, even from a
                                      user's personal computer without a VPN.
                                      For more information, see the BlackBerry Access documentation.

                                      BlackBerry Work gives users secure access to work email, contacts, and
                                      calendar events.
                BlackBerry Work
                                      For more information, see the BlackBerry Work documentation.

                                      BlackBerry Notes allows users to create, edit, and manage notes on iOS
                                      and Android devices. Like email, notes sync with Microsoft Exchange,
                BlackBerry Notes      allowing users to manage them seamlessly between their mobile devices
                                      and the email application on their computer.
                                      For more information, see the BlackBerry Notes documentation.

                                                                                              | BlackBerry Spark Suites | 10
Product                           Description

                                   BlackBerry Tasks allows users to create, edit, and manage tasks on iOS
                                   and Android devices. Like email, tasks sync with Microsoft Exchange,
              BlackBerry Tasks     allowing users to manage them seamlessly between their mobile devices
                                   and the email application on their computer.
                                   For more information, see the BlackBerry Tasks documentation.

                                   BlackBerry Connect allows users to securely send instant messages,
                                   share files, edit documents, and view coworkers' presence information.
                                   It has similar features to consumer instant messaging apps but instead
              BlackBerry Connect   of connecting to consumer services, it connects to your organization's
                                   instant messaging server, such as Microsoft Skype for Business.
                                   For more information, see the BlackBerry Connect documentation.

                                   BlackBerry Edit allows users to view, edit, create, print, present, and share
                                   Microsoft Word, Microsoft Excel, and Microsoft PowerPoint documents
              BlackBerry Edit      using their mobile devices.
                                   For more information, see the BlackBerry Edit documentation.

                                   BlackBerry Enterprise BRIDGE allows users to use Intune-managed
                                   Microsoft apps to view, edit, and save documents from within BlackBerry
                                   Dynamics apps such as BlackBerry Work and BlackBerry Access. If your
                                   organization uses Microsoft Intune to deploy and manage apps such as
              BlackBerry           Microsoft Word, Microsoft Excel, and Microsoft PowerPoint for users,
              Enterprise BRIDGE    BlackBerry Enterprise BRIDGE makes it easier for users to work with files
                                   using the other apps in this suite.
                                   For more information, see the BlackBerry Enterprise BRIDGE
                                   documentation.

Development tools

 Product                           Description

              BlackBerry           The BlackBerry Dynamics SDK provides a powerful set of tools to
              Dynamics SDK         software vendors and enterprise developers that can be used to develop
                                   native, hybrid, and web apps for iOS, Android, Windows, and macOS
                                   devices, with services such as the following:
                                   •   Security services (secure communications and interapp data
                                       exchange APIs)
                                   •   Mobile services (presence, email, push, directory lookup)
                                   •   Platform services (single sign-on authentication, identity and access
                                       management, app-level controls for administrators)
                                   For more information, see the BlackBerry Dynamics SDK documentation.

                                                                                             | BlackBerry Spark Suites | 11
Product                               Description

                BlackBerry Web         The BlackBerry Web Services are a collection of REST web services
                Services               that you can use to create applications to manage your organization's
                                       BlackBerry UEM domain, user accounts, and all supported devices.
                                       You can use the BlackBerry Web Services to automate many tasks that
                                       administrators typically perform using the management console. For
                                       example, you can create an application that automates the process of
                                       creating user accounts, adds users to multiple groups, and manages
                                       users' devices.
                                       For more information, see the BlackBerry Web Services documentation.

BlackBerry Spark UEM Express Suite
The BlackBerry Spark UEM Express Suite provides essential tools to mobilize your workforce and help your
employees securely access work email and and internal data while working outside of the office. The Spark UEM
Express Suite is an ideal solution for smaller business and organizations. It includes BlackBerry UEM and the
most popular BlackBerry Dynamics apps to meet common business needs.
See a visual introduction to the BlackBerry Spark UEM Express Suite.
The BlackBerry Spark UEM Express Suite includes the following products:

 Product                               Description

                                       BlackBerry UEM is an endpoint management solution that provides
                                       comprehensive device, app, and content management with integrated
                                       security and connectivity. It helps you manage iOS, Android, Windows 10,
                                       and macOS devices for your organization and keeps your data safe on
                                       those devices. BlackBerry UEM is available as a cloud-based solution or
                BlackBerry UEM         can be installed on-premises.
                                       Smaller organizations interested in the UEM Express Suite usually opt for
                                       BlackBerry UEM Cloud, which is easy to deploy and gets your users up
                                       and running quickly.
                                       For more information, see the BlackBerry UEM documentation.

                                       BlackBerry Access is a secure web browser that gives users secure
                                       remote access to your organization's intranet and web-based
                                       applications.
                BlackBerry Access      BlackBerry Desktop combines BlackBerry Access and BlackBerry Work
                and BlackBerry         into a single package for Windows 10 and macOS devices to provide
                Desktop                both secure access to work email and secure access to web-based
                                       applications, including Cisco Webex, Zoom, and Salesforce, even from a
                                       user's personal computer without a VPN.
                                       For more information, see the BlackBerry Access documentation.

                                                                                              | BlackBerry Spark Suites | 12
Product                        Description

                               BlackBerry Work is an app that gives users secure access to work email,
                               contacts, and calendar events.
          BlackBerry Work
                               For more information, see the BlackBerry Work documentation.

                               BlackBerry Tasks is an app that allows users to create, edit, and manage
                               tasks on iOS and Android devices. Like email, tasks sync with Microsoft
          BlackBerry Tasks     Exchange, allowing users to manage them seamlessly between their
                               mobile devices and the email application on their computer.
                               For more information, see the BlackBerry Tasks documentation.

                               BlackBerry Connect is an app that allows users to securely send instant
                               messages, share files, edit documents, and view coworkers' presence
                               information. It has similar features to consumer instant messaging apps
          BlackBerry Connect   but instead of connecting to consumer services, it connects to your
                               organization's instant messaging server, such as Microsoft Skype for
                               Business.
                               For more information, see the BlackBerry Connect documentation.

                               BlackBerry Enterprise BRIDGE is an app that allows users to use Intune-
                               managed Microsoft apps to view, edit, and save documents from within
                               BlackBerry Dynamics apps such as BlackBerry Work and BlackBerry
                               Access. If your organization uses Microsoft Intune to deploy and
          BlackBerry           manage apps such as Microsoft Word, Microsoft Excel, and Microsoft
          Enterprise BRIDGE    PowerPoint for users, BlackBerry Enterprise BRIDGE makes it easier for
                               users to work with files using the other apps in this suite.
                               For more information, see the BlackBerry Enterprise BRIDGE
                               documentation.

                                                                                      | BlackBerry Spark Suites | 13
How UES products work together
The components in the BlackBerry Cyber Suite work together to monitor and prevent malicious attacks on your
resources and endpoints using AI-driven intelligence and response mechanisms.

 Item                        Description

 BlackBerry Infrastructure   The BlackBerry Infrastructure hosts the cloud-based components of the Cyber
                             Suite, validates licensing information, and provides a trusted communication path
                             between the organization and every user based on strong, cryptographic, mutual
                             authentication

 BlackBerry Protect          BlackBerry Protect detects and blocks malware using machine learning
                             techniques to render new malware, viruses, bots, and future variants useless. In
                             addition to malware identification, BlackBerry Protect Mobile also detects
                             sideloaded apps, malicious URLs in text messages, and other security risks and
                             recommends or takes action to eliminate the threat.

                                                                                     | How UES products work together | 14
Item                    Description

BlackBerry Optics       BlackBerry Optics monitors Windows, macOS, and Linux endpoints and
                        aggregates collected information using AI to detect, track, alert upon, and respond
                        to malicious events as soon as they occur. ptics can stop attacks before they
                        execute and automate investigation and response to attacks.

BlackBerry Persona      BlackBerry Persona collects data from devices and uses machine learning to
                        determine a user's risk level by dynamically analyzing the user's real-world context,
                        such as the user's location and consistency with normal behavior patters. The
                        service can adapt device and app behavior and authentication requirements to the
                        user's current level of risk.

BlackBerry Gateway      BlackBerry Gateway provides network security-as-a-service . It combines network
                        security functions such as Zero Trust network access, secure web gateways,
                        and cloud access security brokers (CASB) to provide network security that both
                        gives your users access to SaaS applications outside your network perimeter and
                        protects your extended network from threats.

BlackBerry Enterprise   BlackBerry Enterprise Identity gives users single sign-on access to third-party
Identity                software services and the management console.

BlackBerry 2FA          BlackBerry 2FA allows users to respond to a prompt on their iOS or Android device
                        as a second factor of authentication when logging into your network, your VPN,
                        or SaaS applications. The device functionality is included in the BlackBerry UEM
                        Client app installed when users activate iOS and Android devices and no additional
                        apps are required.

Management console      The management console allows administrators to manage UES features and
                        analyze collected security data.

Devices                 BlackBerry Cyber Suite provides protection to to your users devices whether they
                        are connected to your internal Wi-Fi network or to an external network.

External SaaS           BlackBerry Gateway can limit access only to authorized users of your SaaS
applications            applications.
                        BlackBerry Enterprise Identity can manage authentication for your users to a most
                        common cloud-based SaaS applications.

                                                                                 | How UES products work together | 15
How UEM products work together
The components in the BlackBerry Spark UEM Suite work together to manage devices and secure data in transit
between your users' devices, your internal network, and your external SaaS applications.

 Item                        Description

 BlackBerry Infrastructure   The BlackBerry Infrastructure hosts BlackBerry UEM Cloud, BlackBerry Enterprise
                             Identity, and cloud-based components for the UEM and UES services, registers
                             user information for device activation, validates licensing information, and
                             provides a trusted communication path between the organization and every user
                             based on strong, cryptographic, mutual authentication.

 BlackBerry UEM              BlackBerry UEM provides endpoint management features and the administration
                             console for all products in the BlackBerry Spark UEM suite. You can install UEM
                             on-premises behind your firewall or use BlackBerry UEM Cloud.

                                                                                  | How UEM products work together | 16
Item                      Description

BlackBerry Connectivity   The BlackBerry Connectivity Node is a component installed inside your
Node                      organization's firewall that adds the following functionality to BlackBerry UEM
                          Cloud:
                          •   Connects BlackBerry UEM Cloud to your company directory to allow basic
                              attribute synchronization, search functionality, and user authentication services
                          •   Communicates with Exchange ActiveSync to add devices to an allowed list
                              when devices are activated on BlackBerry UEM Cloud
                          •   Maintains secure connections through the BlackBerry Infrastructure between
                              BlackBerry Dynamics apps and other work apps on devices and your
                              organization's network

BlackBerry Enterprise     BlackBerry Enterprise Identity gives users single sign-on access to third-party
Identity                  software services and to BlackBerry UEM Cloud. You manage it using the
                          BlackBerry UEM management console.

BlackBerry 2FA            BlackBerry 2FA allows users to respond to a prompt on their iOS or Android device
                          as a second factor of authentication when logging into your network, your VPN,
                          or SaaS applications. The device functionality is included in the BlackBerry UEM
                          Client app installed when users activate iOS and Android devices and no additional
                          apps are required.

BlackBerry Workspaces     BlackBerry Workspaces allows users to securely access, synchronize, edit, and
                          share files and folders from their computers and mobile devices. BlackBerry
                          Workspaces protects files by applying digital rights management controls to limit
                          access, even after they are shared with someone outside of your organization.
                          You can install a BlackBerry Workspaces server on-premises to store protected
                          files and manage access to BlackBerry Workspaces from the UEM management
                          console.

BlackBerry UEM            BlackBerry UEM Notifications allows you to send critical messages and
Notifications             notifications to users and groups from the UEM management console using Text-
                          To-Speech voice calls, SMS, and email. UEM Notifications is available for use with
                          BlackBerry UEM on-premises only.

Company directory         BlackBerry UEM can connect to your organization's Microsoft Active Directory or
                          LDAP company directory.

Mail, content, and        Devices can connect to your organization's servers without requiring you to open
application servers       a direct connection between the server and the Internet. Work data in transit
                          between your servers and devices is sent through the BlackBerry Infrastructure.

External SaaS             BlackBerry Enterprise Identity can manage access for your users to a most
applications              common cloud-based SaaS applications.

Devices connected to      Users who have devices activated with BlackBerry UEM can use BlackBerry
external networks         Dynamics apps, the BlackBerry Workspaces app, and other work apps to work
                          productively while keeping your data safe. Users with iOS or Android devices can
                          also use their device for two-factor authentication.

                                                                                  | How UEM products work together | 17
Legal notice
©2021 BlackBerry Limited. Trademarks, including but not limited to BLACKBERRY, BBM, BES, EMBLEM Design,
ATHOC, CYLANCE and SECUSMART are the trademarks or registered trademarks of BlackBerry Limited, its
subsidiaries and/or affiliates, used under license, and the exclusive rights to such trademarks are expressly
reserved. All other trademarks are the property of their respective owners.
 This documentation including all documentation incorporated by reference herein such as documentation
provided or made available on the BlackBerry website provided or made accessible "AS IS" and "AS AVAILABLE"
and without condition, endorsement, guarantee, representation, or warranty of any kind by BlackBerry Limited and
its affiliated companies ("BlackBerry") and BlackBerry assumes no responsibility for any typographical, technical,
or other inaccuracies, errors, or omissions in this documentation. In order to protect BlackBerry proprietary and
confidential information and/or trade secrets, this documentation may describe some aspects of BlackBerry
technology in generalized terms. BlackBerry reserves the right to periodically change information that is contained
in this documentation; however, BlackBerry makes no commitment to provide any such changes, updates,
enhancements, or other additions to this documentation to you in a timely manner or at all.
This documentation might contain references to third-party sources of information, hardware or software,
products or services including components and content such as content protected by copyright and/or third-
party websites (collectively the "Third Party Products and Services"). BlackBerry does not control, and is not
responsible for, any Third Party Products and Services including, without limitation the content, accuracy,
copyright compliance, compatibility, performance, trustworthiness, legality, decency, links, or any other aspect
of Third Party Products and Services. The inclusion of a reference to Third Party Products and Services in this
documentation does not imply endorsement by BlackBerry of the Third Party Products and Services or the third
party in any way.
EXCEPT TO THE EXTENT SPECIFICALLY PROHIBITED BY APPLICABLE LAW IN YOUR JURISDICTION, ALL
CONDITIONS, ENDORSEMENTS, GUARANTEES, REPRESENTATIONS, OR WARRANTIES OF ANY KIND, EXPRESS
OR IMPLIED, INCLUDING WITHOUT LIMITATION, ANY CONDITIONS, ENDORSEMENTS, GUARANTEES,
REPRESENTATIONS OR WARRANTIES OF DURABILITY, FITNESS FOR A PARTICULAR PURPOSE OR USE,
MERCHANTABILITY, MERCHANTABLE QUALITY, NON-INFRINGEMENT, SATISFACTORY QUALITY, OR TITLE, OR
ARISING FROM A STATUTE OR CUSTOM OR A COURSE OF DEALING OR USAGE OF TRADE, OR RELATED TO THE
DOCUMENTATION OR ITS USE, OR PERFORMANCE OR NON-PERFORMANCE OF ANY SOFTWARE, HARDWARE,
SERVICE, OR ANY THIRD PARTY PRODUCTS AND SERVICES REFERENCED HEREIN, ARE HEREBY EXCLUDED.
YOU MAY ALSO HAVE OTHER RIGHTS THAT VARY BY STATE OR PROVINCE. SOME JURISDICTIONS MAY
NOT ALLOW THE EXCLUSION OR LIMITATION OF IMPLIED WARRANTIES AND CONDITIONS. TO THE EXTENT
PERMITTED BY LAW, ANY IMPLIED WARRANTIES OR CONDITIONS RELATING TO THE DOCUMENTATION TO
THE EXTENT THEY CANNOT BE EXCLUDED AS SET OUT ABOVE, BUT CAN BE LIMITED, ARE HEREBY LIMITED TO
NINETY (90) DAYS FROM THE DATE YOU FIRST ACQUIRED THE DOCUMENTATION OR THE ITEM THAT IS THE
SUBJECT OF THE CLAIM.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW IN YOUR JURISDICTION, IN NO EVENT SHALL
BLACKBERRY BE LIABLE FOR ANY TYPE OF DAMAGES RELATED TO THIS DOCUMENTATION OR ITS USE,
OR PERFORMANCE OR NON-PERFORMANCE OF ANY SOFTWARE, HARDWARE, SERVICE, OR ANY THIRD
PARTY PRODUCTS AND SERVICES REFERENCED HEREIN INCLUDING WITHOUT LIMITATION ANY OF THE
FOLLOWING DAMAGES: DIRECT, CONSEQUENTIAL, EXEMPLARY, INCIDENTAL, INDIRECT, SPECIAL, PUNITIVE,
OR AGGRAVATED DAMAGES, DAMAGES FOR LOSS OF PROFITS OR REVENUES, FAILURE TO REALIZE ANY
EXPECTED SAVINGS, BUSINESS INTERRUPTION, LOSS OF BUSINESS INFORMATION, LOSS OF BUSINESS
OPPORTUNITY, OR CORRUPTION OR LOSS OF DATA, FAILURES TO TRANSMIT OR RECEIVE ANY DATA,
PROBLEMS ASSOCIATED WITH ANY APPLICATIONS USED IN CONJUNCTION WITH BLACKBERRY PRODUCTS OR
SERVICES, DOWNTIME COSTS, LOSS OF THE USE OF BLACKBERRY PRODUCTS OR SERVICES OR ANY PORTION
THEREOF OR OF ANY AIRTIME SERVICES, COST OF SUBSTITUTE GOODS, COSTS OF COVER, FACILITIES OR
SERVICES, COST OF CAPITAL, OR OTHER SIMILAR PECUNIARY LOSSES, WHETHER OR NOT SUCH DAMAGES

                                                                                                            | Legal notice | 18
WERE FORESEEN OR UNFORESEEN, AND EVEN IF BLACKBERRY HAS BEEN ADVISED OF THE POSSIBILITY OF
SUCH DAMAGES.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW IN YOUR JURISDICTION, BLACKBERRY SHALL
HAVE NO OTHER OBLIGATION, DUTY, OR LIABILITY WHATSOEVER IN CONTRACT, TORT, OR OTHERWISE TO
YOU INCLUDING ANY LIABILITY FOR NEGLIGENCE OR STRICT LIABILITY.
THE LIMITATIONS, EXCLUSIONS, AND DISCLAIMERS HEREIN SHALL APPLY: (A) IRRESPECTIVE OF THE NATURE
OF THE CAUSE OF ACTION, DEMAND, OR ACTION BY YOU INCLUDING BUT NOT LIMITED TO BREACH OF
CONTRACT, NEGLIGENCE, TORT, STRICT LIABILITY OR ANY OTHER LEGAL THEORY AND SHALL SURVIVE A
FUNDAMENTAL BREACH OR BREACHES OR THE FAILURE OF THE ESSENTIAL PURPOSE OF THIS AGREEMENT
OR OF ANY REMEDY CONTAINED HEREIN; AND (B) TO BLACKBERRY AND ITS AFFILIATED COMPANIES, THEIR
SUCCESSORS, ASSIGNS, AGENTS, SUPPLIERS (INCLUDING AIRTIME SERVICE PROVIDERS), AUTHORIZED
BLACKBERRY DISTRIBUTORS (ALSO INCLUDING AIRTIME SERVICE PROVIDERS) AND THEIR RESPECTIVE
DIRECTORS, EMPLOYEES, AND INDEPENDENT CONTRACTORS.
IN ADDITION TO THE LIMITATIONS AND EXCLUSIONS SET OUT ABOVE, IN NO EVENT SHALL ANY DIRECTOR,
EMPLOYEE, AGENT, DISTRIBUTOR, SUPPLIER, INDEPENDENT CONTRACTOR OF BLACKBERRY OR ANY
AFFILIATES OF BLACKBERRY HAVE ANY LIABILITY ARISING FROM OR RELATED TO THE DOCUMENTATION.
Prior to subscribing for, installing, or using any Third Party Products and Services, it is your responsibility to
ensure that your airtime service provider has agreed to support all of their features. Some airtime service
providers might not offer Internet browsing functionality with a subscription to the BlackBerry® Internet Service.
Check with your service provider for availability, roaming arrangements, service plans and features. Installation
or use of Third Party Products and Services with BlackBerry's products and services may require one or more
patent, trademark, copyright, or other licenses in order to avoid infringement or violation of third party rights. You
are solely responsible for determining whether to use Third Party Products and Services and if any third party
licenses are required to do so. If required you are responsible for acquiring them. You should not install or use
Third Party Products and Services until all necessary licenses have been acquired. Any Third Party Products and
Services that are provided with BlackBerry's products and services are provided as a convenience to you and are
provided "AS IS" with no express or implied conditions, endorsements, guarantees, representations, or warranties
of any kind by BlackBerry and BlackBerry assumes no liability whatsoever, in relation thereto. Your use of Third
Party Products and Services shall be governed by and subject to you agreeing to the terms of separate licenses
and other agreements applicable thereto with third parties, except to the extent expressly covered by a license or
other agreement with BlackBerry.
The terms of use of any BlackBerry product or service are set out in a separate license or other agreement with
BlackBerry applicable thereto. NOTHING IN THIS DOCUMENTATION IS INTENDED TO SUPERSEDE ANY EXPRESS
WRITTEN AGREEMENTS OR WARRANTIES PROVIDED BY BLACKBERRY FOR PORTIONS OF ANY BLACKBERRY
PRODUCT OR SERVICE OTHER THAN THIS DOCUMENTATION.
BlackBerry Enterprise Software incorporates certain third-party software. The license and copyright information
associated with this software is available at http://worldwide.blackberry.com/legal/thirdpartysoftware.jsp.

BlackBerry Limited
2200 University Avenue East
Waterloo, Ontario
Canada N2K 0A7

BlackBerry UK Limited
Ground Floor, The Pearce Building, West Street,
Maidenhead, Berkshire SL6 1RL
United Kingdom

Published in Canada

                                                                                                               | Legal notice | 19
You can also read