screen and access the BlackBerry Administration Service and BlackBerry Web Desktop Manager directly. The BlackBerry
Monitoring Service does not support single sign-on authentication.
Before you turn on single sign-on, you must configure constrained delegation for the Microsoft Active Directory account for
the BlackBerry Administration Service.
Configure constrained delegation for the Microsoft
Active Directory account to support single sign-on
authentication
1.
Use the Windows Server ADSI Edit tool to add the following SPNs for the BlackBerry Administration Service pool to
the Microsoft Active Directory account :
• HTTP/<
BAS_pool_FQDN
> (for example, HTTP/BASconsole104.example.com)
• BASPLUGIN111/<
BAS_pool_FQDN
> (for example, BASPLUGIN111/BASconsole104.example.com)
2.
If you create separate pools of BlackBerry Administration Service instances and BlackBerry Web Desktop Manager
instances in the BlackBerry Administration Service pool, add the HTTP/<BAS_pool_FQDN> SPN for each pool to the
Microsoft Active Directory account.
3.
Configure the Microsoft Active Directory account for constrained delegation using the following settings:
• trust this user for delegation to specific services only
• use Kerberos only
4.
In the Microsoft Active Directory account properties, on the
Delegation
tab, add BASPLUGIN111/
<BAS_pool_FQDN> to the list of services.
After you finish:
For more information about configuring constrained delegation for the Microsoft Active Directory account
so you can access the BlackBerry Administration Service, visit
www.blackberry.com/btsc
to read article KB22717.
Turn on single sign-on authentication for the
BlackBerry Administration Service
1.
In the BlackBerry Administration Service, on the
Servers and components
menu, expand
BlackBerry Solution
topology
>
BlackBerry Domain
>
Component view
.
2.
Click
BlackBerry Administration Service
.
3.
On the
Microsoft® Active Directory® authentication
tab, click
Edit component
.
Administration Guide
Changing the security settings of the BlackBerry Administration Service and BlackBerry Web Desktop
Manager
270