
BlackBerry Enterprise Solution
64
IT policy rule
Description
Secure Wipe Delay After Lock
Set this IT policy rule to a period of time, in hours, after which, if the user has
not unlocked the BlackBerry device, the BlackBerry device permanently
deletes its user and application data.
Secure Wipe if Low Battery
Set this IT policy rule to require that, if the BlackBerry device battery power
is insufficient to receive IT policy updates or IT administration commands,
the BlackBerry device permanently deletes its user and application data.
Remotely resetting a BlackBerry device to factory default settings
The BlackBerry Enterprise Server administrator can use the Remote Wipe Reset to Factory Defaults IT policy rule
to require the BlackBerry device to return to factory default settings when it receives the Erase Data and Disable
Handheld IT administration command over the wireless network. When the BlackBerry Enterprise Server
administrator sets this rule to True and sends the Erase Data and Disable Handheld IT administration command
to the BlackBerry device from the BlackBerry Manager, the BlackBerry device reverts to its factory default
settings and permanently deletes all of the following items:
•
user data
•
corporate PIN-to-PIN encryption key
•
master encryption key
•
smart card binding information
•
password history
•
stored BlackBerry MDS device policy
•
record of time elapsed since the BlackBerry device was last turned on
•
stored IT policy
•
third-party applications and application data
When the BlackBerry device reverts to its factory default settings, it overwrites BlackBerry device internal
memory and, if content protection is turned on, performs a scrub of BlackBerry device memory.
Erasing data from BlackBerry device memory and making the BlackBerry device
unavailable (standard security wipe)
A BlackBerry device that is not physically connected to a computer is designed to permanently delete its user
and application data when any of the following events occur:
•
The user clicks
Wipe Handheld (in the Security Options) on the BlackBerry device.
•
The user types the password incorrectly more times than the Set Maximum Password Attempts IT policy rule
allows on the BlackBerry device. (The default is ten attempts.)
•
The BlackBerry Enterprise Server administrator sends the Erase Data and Disable Handheld IT
administration command to the BlackBerry device from the BlackBerry Manager.
•
The BlackBerry Enterprise Server administrator sends the Erase Data and Disable Handheld IT
administration command with a delay (in hours, up to 168 hours) to the BlackBerry device from the
BlackBerry Manager.
A BlackBerry device is designed to erase its user and application data and all applications when it is physically
connected to a computer and any of the following events occur:
•
The BlackBerry device user runs the application loader tool in the BlackBerry Desktop Software and types
the password incorrectly more times than the Set Maximum Password Attempts IT policy rule allows in the
application loader tool prompt. (The default is ten attempts.)
www.blackberry.com