Enroll Aurora Protect Mobile and Gateway users

You assign an enrollment policy to users to allow them to activate the Aurora Protect Mobile app on mobile devices and Gateway agent on Windows and macOS devices.

The enrollment policy includes separate settings for mobile and desktop devices. You can specify the supported device types and the text for email messages to be sent to users to provide activation instructions and a password or QR Code required to begin the activation process. You can specify the number of days that the activation password or QR Code is valid under Settings > Activation. The setting applies to all enrollment policies.

Users must have these policies assigned to them before they can activate the Aurora Protect Mobile app or the Gateway agent.

User type Required policies

Aurora Protect Mobile app user without Gateway support

  • Enrollment policy
  • Aurora Protect Mobile policy

Aurora Protect Mobile app user with only Gateway support

  • Enrollment policy
  • Gateway Service policy

Aurora Protect Mobile app user with both Aurora Protect Mobile and Gateway support

  • Enrollment policy
  • Aurora Protect Mobile policy
  • Gateway Service policy

Desktop user with Gateway agent

  • Enrollment policy
  • Gateway Service policy
Note: The Gateway agent communicates over HTTPS with the management console and must be able to establish this connection directly. You must configure your organization's network to allow connections to the appropriate domains. For example, to allow the Gateway agent to activate and periodically authenticate, you must allow access to idp.blackberry.com and the domain for your region. If your environment uses an authentication proxy, you must allow the traffic on the proxy server. If the appropriate domains are not allowed, the Gateway agent will not be able to open the browser to complete the authentication process. For more information on the domains that must be allowed for Gateway, see KB 42221223173659. For information on the network requirements for Aurora Endpoint Security, see Aurora Endpoint Security network prerequisites.