Configuring the UEM Connector in the Lookout MES Console
- Log in to the Lookout MES Console at https://app.lookout.com.
- In the left sidebar, click Integrations.
- Under Choose a product to set up, click the BlackBerry tile.The BlackBerry UEM connector page opens.
- Under Connector Settings, enter the following:
Field Value Label for this MDM connection (Optional) A user friendly name for the connector.
If you have multiple connectors configured, this label displays in the MDM column of the Lookout MES Console Devices list so that you can determine which connector and MDM instance a device belongs to.
Server address The public, fully qualified domain name of your BlackBerry UEM server.
This must be a public URL in order for the Lookout MES Console to successfully communicate with your UEM server.
Username The API User username and password from Creating an API User. Password SRP ID The SRP ID from Retrieving the BlackBerry SRP ID. BlackBerry UEM API port By default, the SOAP API port is 18084. Ensure the ports is not blocked by your firewall.
For additional information, see BlackBerry UEM listening ports in the BlackBerry documentation.
- (Mandatory if BB Web Services is configured.) To route Lookout traffic through a proxy, enter the proxy address and credentials in the Proxy Settings fields.
- Click Create Integration in the top right corner.
If creation is successful, a banner notification appears and additional sections become enabled. If you get a certificate error, click Certificate Details. Otherwise continue with Step 7.
- Look for errors on the certificate details screen.Typical errors include expired or broken certificates as shown here:
Error How to Fix the Error Expired certificate The certificate expiration date is in the past. Replace the MDM certificate with a new certificate. Broken certificate. One or more intermediate certificates do not validate correctly. Replace the MDM certificate with a valid certificate. - Retry entering all required information into the Integration connector.
- Look for errors on the certificate details screen.
- Scroll down to Enrollment Management and enter the following:
Field Value Automatically drive Lookout for Work enrollment on Blackberry UEM managed devices ON Use the following group to identify devices that should have the Lookout for Work app activated Select your enrollment User Group from Creating User Groups for Enrollment and Device State Sync. This should be Lookout for Work. How often should Lookout check for new devices? Lookout recommends using the default 5 minute interval. Automatically send activation emails to Blackberry UEM managed devices Toggle this ON if you are using MAM enrollment, otherwise leave it OFF.
This toggle is unavailable if Privacy Controls are enabled for your tenant. If you are using MAM enrollment and do not see this toggle, contact Lookout Enterprise Support to disable the additional privacy controls. Lookout requires the device email information to send enrollment requests to MAM users.
Delete device on unenrollment ON - Scroll down to State Sync and enable Synchronize device status to Blackberry UEM.
- Select the user groups you created in Creating User Groups for Enrollment and Device State Sync.
If you choose not to synchronize a specific state to BES UEM, leave the corresponding toggle off.
- Device Status:
Field Value Devices that have not activated Lookout yet Lookout MES - Pending Devices with Lookout activated Lookout MES - Activated Devices with Lookout deactivated Lookout MES - Deactivated - Connection Status:
Field Value Devices that are unreachable by Lookout Lookout MES - Unreachable Devices that have lost connectivity with Lookout Lookout MES - Disconnected - Risk Status:
Field Value Devices with any issues present Lookout MES - Threats Present Devices with low risk issues present Lookout MES - Low Risk Devices with medium risk issues present Lookout MES - Moderate Risk Devices with high risk issues present Lookout MES - High Risk Devices with no issues present Lookout MES - Secured
- Device Status:
- If you have purchased the feature to add specific Risk Classifications to synchronize with your MDM you can add them using this procedure. a Risk Classification section is visible in the Lookout connector.Otherwise continue on to step 11.
- In your MDM, follow the steps in Creating User Groups for Device State Sync and Enrollment to define an additional unique group name for each risk classification you want to synchronize with your MDM.Here are some examples:
Example Risk Classification Example Group Example Description Phishing and Content Protection Disabled Lookout MES - PCP Disabled Devices with PCP disabled VPN Permission Not Accepted Lookout MES - VPN Prohibited Devices with VPN Permission not accepted - In the Lookout connector Risk Classification section (visible only if you purchased this feature), follow these substeps:
- Click Add Risk Classification.
- Set to Enable.
- Choose the desired risk classification from the dropdown to synchronize with your MDM.
Risk classification synchronization occurs only if a state sync event occurs.
- Choose the group name for the selected risk classification from the dropdown to synchronize with your MDM.
If you choose not to synchronize a specific state to your MDM, leave the corresponding toggle off.
- Repeat steps i - iv for each additional risk classification you want to synchronize with your MDM.
Each risk classification you add here must have a corresponding unique group name defined in your MDM.
- In your MDM, follow the steps in Creating User Groups for Device State Sync and Enrollment to define an additional unique group name for each risk classification you want to synchronize with your MDM.
- If you are using MAM enrollment, configure Application Blocking:
Configure this section based on the needs of your organization. Lookout recommends the following settings:
Block all Dynamics applications on devices... Recommended Setting … in a pending state ON so that pending users activate Lookout for Work. … in a deactivated state ON so users do not deactivate Lookout for Work. … in a disconnected state OFF so users aren't blocked from Dynamics apps when they don't have connectivity to Lookout. … with low risk issues present OFF so users aren't blocked from Dynamics apps for low risk issues. … with medium risk issues present ON … with high risk issues present ON - Scroll down to Error Management and enter an email address for error reporting.
- (Optional) Scroll down to Group Management and enter a Lookout MES Console Device Group for new devices from this connector.
By default, new devices are added to the Default Group in the Lookout MES Console. For more information about Device Groups, see the Lookout MES Console Administrator's Guide.
- Scroll up and click Save Changes in the top right corner.
You can review connector settings from the Integrations module at any time.
- If you are running multiple BlackBerry UEM tenants, repeat these steps to create one connector per tenant.