01. Introduction
There is a general documentation available for the EBF Onboarder, where you can find information about its prerequisites and the whole migration project. It describes how you can setup a migration project, how you can setup invitation emails and reminders which guide your users through the migration. It also tells you how to initiate the migration process and how to track the migration status.
This documentation complements the general EBF Onboarder documentation and provides more detailed information about the prerequisites for the source system BlackBerry UEM V12 onPrem.
ATTENTION:
This documentation does not replace any BlackBerry documentation. It is only describing prerequisites for the EBF Onboarder. Please consult the BlackBerry documentation and support if necessary.
02. Prerequisites for the source system BlackBerry UEM v12
If your source system is BlackBerry UEM v12, it is recommended that you login to your BlackBerry UEM v12 console to make the changes which are described in the following chapters.
NOTE:
In single cases it was required to create a client app on the source system.
02.1. Source system selection for the source system BlackBerry UEM v12
When you setup a migration project with the EBF Onboarder, you will be asked to define the source system (please read the general documentation to learn more about this).
Select BlackBerry UEM v12 as target system. The EBF Onboarder will display a set of values which are required to connect to your BlackBerry UEM v12 system: Host, Proxy Url, Tenant Id, User, Password.
Please check the table below to find the parameters:
Host | The host must be the internal host name. |
Proxy Url | The Proxy URL needs to be: <region>.bbsecure.com (e.g. de.bbsecure.com for Germany). |
Tenant ID | The tenant ID must have the format ‘SNUMBER’ instead of ‘SRPNUMBER’, for example, S00000. |
User | This user needs to be ‘Enterprise Admin’. The username must not contain underscores (this is not supported by the Blackberry NOC). |
Password | The Password of the User |
02.2. Create a client app (possibly required)
NOTE:
In single cases the data from chapter 2.1 did not allow the EBF Onboarder to connect to the UEM v12 onPrem system. It was required to create a client app on the v12 OnPrem system as well. It seems that the authentication via API only works if a client-app is registered (and assigned to the corresponding SRP-ID). This additional step seems to be a requirement with Blackberry UEM Version 12.21.0 but might be required for other new versions as well.
NOTE:
Do not use an existing client app. To be able to have better control about the client apps, each topic should get its own client app.
Follow these steps to create the client app:
- Login to your account: https://myaccount.blackberry.com/myaccount.html.
- Go to ‘myAccount’ >> ‚BlackBerry Support Community‘ >> ‚My Organization‘ >> ‚Overview‘.
- Click on ‘Applications’ >> ‘Add Application’.
- Enter a name and select ‘BlackBerry Platform APIs’.
- Click on ‘Template’ >> ‘Add Template’.
- Enter the following details:
- Redirect URLs: Enter your internal Example: https://p1234.cp1.uem.blackberry.com.
- Type: Select ‘web’.
- Grant Type: Select ‘client_credentails’.
- Response Types: Select ‘none’.
- Token Endpoint Auth Method: Select ‘client_secret_basic’.
- API Scopes: Select ‘Mobile Device Management’.
- Click on ‘Register’.
- Click on ‘Client’ >> ‘Add Client’.
- Enter a name.
- Select your source system’s tenant SRP number (move it from the Available container to the Selected container).
- Leave ‘Post Logout Redirect URLs’
- Set ‘Id Token Signed Response Alg’ to ES256.
- Click on ‘Register’.
- You can review the required details for your EBF Onboarder setup under ‘Applications’ >> ’Application Name’ >> ‘BlackBerry Platform APIs’ >> ‘Client’.
- Assign the app to an admin in your source UEM V12 who has permission to ‘View users, devices’ and ‘Manage devices’, ‘Delete only work data, delete all device data, Delete device’. This can be found under ‘Settings’ >> ‘Administrators’ >> ‘Web service clients’. Add the apps also in OpenID Connect-Apps under Settings > BlackBerry Enterprise identity > Services to the OpenID Connect-Apps.
03. Device selection for the source system BlackBerry UEM v12
When you setup a migration project with the EBF Onboarder, you will be asked to select the devices you want to migrate (please read the general documentation to learn more about this).
A filter for the devices needs to be already existing or needs to be created in the source system before you setup the migration project. For the first tests you can use a test filter. For the real migration it is recommended to create filters like wave1, wave 2 etc. and to create single migration sets to have control over each wave.