Welcome to the official BlackBerry Support Community Forums.

This is your resource to discuss support topics with your peers, and learn from each other.

inside custom component

BlackBerry® Enterprise Service 10

Posts: 23
Registered: ‎12-14-2008
My Device: Z10, 9900 & Playbook 64GB
My Carrier: Bell Mobility

Question about Implementing Network Device Enrollment Service (SCEP) in a User Forest / Resource Forest environment for Blackberry Device Service


We have a Windows 2008 R2 User Forest / Resource Forest configuration, where users authenticate to Domain Controllers in the User Forest, but access resources such as Lync and Exchange in the Resource Forest.

We would like to install the Network Device Enrollment Service role in order to make Simple Certificate Enrollment Protocol (SCEP) available to our Blackberry Device Service 10 server.  BDS10 supports SCEP to be used for authentication to ActiveSync, WiFi and VPN profiles.

My question is really just a confirmation.  Where should we install NDES?  In the User Forest, or the Resource Forest? 

From what I have researched and what I think, NDES should be installed in the User Forest because that is where the user is authenticating.

Thanks in advance for your answer(s).