Lab 4

To illustrate the importance of IT policies and also to get you familiar with using them in your organization, we are going to create a mock lab that will set the following IT policy rules and IT policy for all user accounts that belong to sales employees.

So far our lab has a sales group which has around six users, who have been activated with the default IT policy. It is good practice not to edit the default IT policy and to create a new one. We need to ensure that the following requirements are met for the BlackBerry devices, for all sales employees:

  • The user has to enter a new password every 45 days
  • The minimum password length should be eight characters
  • Company security policy states that a duress e-mail must be set up — so if the sales user is forced to unlock the device, the head admin at the organization is notified
  • Users cannot be allowed to use the BCC (Blind Carbon Copy) when sending messages from their devices
  • Must allow access to the third-party application SalesStock

Creating the Sales Team IT policy

  1. Log on to the BlackBerry Administration Service.
  2. Create an IT policy called Sales IT policy (see Creating a new IT policy section of this chapter for additional help).
  3. Click on Manage IT policies and select the Sales policy.
  4. Click on Edit policy and select the Device only tab.
    Creating the Sales Team IT policy
  5. For the rule Password Required, we must select Yes from the drop-down menu, as the default setting is No for this rule.
  6. For the rule Maximum Password Age enter 45.
  7. For the rule Minimum Password Length enter 8.
  8. For the rule User Can Disable Password select No; by default this is set to Yes.
  9. Scroll further down and change the drop-down menu for Allow BCC Recipients to NO.
    Creating the Sales Team IT policy
  10. Select Save all.
  11. Click on the Password tab and for the rule Duress Notification Address enter an e-mail address for the head admin so he is notified when the user is unlocking the device under duress.
    Creating the Sales Team IT policy
  12. Please note when we enable this rule by default the number of password attempts are halved. By default the number of password attempts are 10, so once we enable this rule they will become 5.
  13. For the user to enable the duress call of unlocking the BlackBerry, they would need to move the first character of the password to the end. For example, if the user's password was blackberry, then if they were unlocking the device under duress they would enter lackberryb. This would then send an e-mail message to the address above letting them know the device was unlocked under duress.
  14. Save this IT policy.
  15. For our final rule, we need to create a third-party application rule that has Boolean value, see Creating a new IT policy section of this chapter, give the policy name as SalesStock, choose a Boolean value, and for the Destination choose Handheld, as shown in the following screenshot:
    Creating the Sales Team IT policy
  16. Go back to the Sales IT policy and click on the User defined tab and select Yes for SalesStock and click on Save all, as shown in the following screenshot:
    Creating the Sales Team IT policy

Applying the IT policy to the sales group

  1. Click on Manage groups, select the Sales Team group.
    Applying the IT policy to the sales group
  2. Click on the Policies tab, and select Edit group.
    Applying the IT policy to the sales group
  3. From the drop-down select the Sales IT Policy and click on Save all.
    Applying the IT policy to the sales group

So we have successfully created the Sales IT Policy and applied it to our Sales Team group. From now on, any user created in that group will have the Sales IT Policy applied to them. We need to ensure that no member of our Sales Team has an IT policy directly applied to their user account, as doing so will mean that the directly applied policy will take priority.

We also need to make sure that if users belonging to the Sales Team are in different groups, we either set the IT policy priorities correctly, or we assign the user account a policy directly, so it is always used.

IT policy settings

As mentioned previously, we can resend an IT policy manually to a user account. This is shown next:

  1. Click on Manage users.
  2. Select or search for the user account which needs the policy sent to.
  3. Select the Policies tab, and click on View resolved IT policy data.
    IT policy settings
  4. Select Resend IT policy to a device.
    IT policy settings

Now this IT policy will be sent to the device within 15 minutes. We can also, as mentioned, program the BlackBerry Enterprise Server to resend IT policies out to devices every X hours even if there is no update or change in the IT policies.

Resending the IT policy automatically to devices

  1. Expand BlackBerry Solution topology, expand BlackBerry Domain and expand Component view.
  2. Expand Policy and select the instance and click on Edit instance.
    Resending the IT policy automatically to devices
  3. In the General section for the field Policy resend interval (hours) specify 3 to resend the IT policies every three hours automatically.
    Resending the IT policy automatically to devices
  4. Select Save all.

Deactivating devices that do not have an IT policy

We can deactivate devices in our BlackBerry Enterprise Solution that do not have a valid IT policy assigned to them.

In the General section, change the drop-down for Disable users with unapplied IT policy to True, as shown in the following screenshot:

Deactivating devices that do not have an IT policyIT policyresending automatically, to devices

Troubleshooting IT policies

Ensure that you have viewed IT policy settings for users that belong to different groups, to ensure that they have the right IT policy applied. If they don't, check the priority settings for the IT policies within the organization.

If the IT policy seems to be stuck on waiting to apply to the device, this usually indicates that the device already has an IT policy assigned to it. Best practice is to wipe the device, by following the procedure in Chapter 3, Activating Devices and Users; this will clear the IT policy on the Smartphone. If the policy is still enforced after the wipe then you will need to refer to RIM documentation on how to use the policy bin tool to remove the IT policy.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.223.237.29