Secure Samsung Knox with AirDroid Business MDM Integration
Is your company deploying a large number of devices and finding the enrollment process a bit challenging? Knox Enrollment Service simplifies bulk device setup, making it an essential tool for enterprises looking to save time and effort.
However, setting it up can be a little bit tricky. This article will provide an in-depth look at Knox Enrollment, outlining its key features and how it can transform your device management process.
1. What is Knox Enrollment Service?
Knox Enrollment Service is a solution from Samsung that allows businesses to quickly and automatically deploy large numbers of corporate-owned Samsung devices. It enables IT administrators to enroll devices into their management system (EMM/MDM) right out of the box, applying security policies and configurations without manual setup.
2. Processes of Bulk Device Enrollment with KME:
Requirements
Samsung Knox Mobile Enrollment streamlines the setup of Samsung Galaxy devices across large organizations. To use the service, the devices must meet certain requirements:
- Samsung Galaxy with Knox version 3.0 or higher, and must be purchased from a reseller participating in the Knox Deployment Program.
- IT administrators are key in Knox Enrollment by creating and managing device profiles, including configuring settings and restrictions that can be applied to multiple devices.
- To facilitate the process, they work closely with approved resellers, who upload device IDs to the Knox Reseller Portal for integration into Knox Mobile Enrollment. These IDs allow for the automatic enrollment of devices when they power on and connect to a network, enabling secure, hands-free setup.
- For devices not purchased through a reseller, the Knox Deployment App can still be used to manually enroll them into the system.
How Does It Work?
Knox Mobile Enrollment (KME) simplifies the bulk enrollment of Samsung devices into enterprise mobility management (EMM) systems through an automated process.
1: It starts with the IT administrator collaborating with a Samsung-approved reseller.
2: The reseller uploads the device IDs of the purchased devices to the Knox Reseller Portal, ensuring that only verified devices are enrolled.
3: Once the device list is uploaded, the IT admin receives a notification and approves the enrollment in the Knox Mobile Enrollment Portal.
4: From there, the IT admin assigns a configuration profile to the devices, which includes specific settings, restrictions, and apps that need to be preloaded.
5: If reseller preferences are configured, future device uploads can be automatically approved and assigned profiles, further automating the process.
6: Once the profile is assigned, the devices are enrolled into the EMM system. Users simply unbox their devices, and upon booting, the configurations are automatically applied without any manual input required, ensuring a seamless user experience.
How to Use Knox Enrollment Service? (Full Guide):
Knox Enrollment Service is available to enroll Samsung smartphones, phablets, tablets, rugged devices, and wearable devices.
Step 1: Sign up for Knox Mobile Enrollment and access the admin console.
If you're completely new to Samsung Knox, you should get a Samsung account first. You can get one via this link.
Then, use your account to log into the Samsung Knox Admin Portal so that you can further access Knox Mobile Enrollment. Here is the official entrance: Knox Admin Portal.
Step 2 : Create a profile with MDM/EMM details to configure out-of-box device settings.
On the left navigation bar, you can see Knox Mobile Enrollment. Drop it down and click 'Profiles' > 'CREATE PROFILE.'
You need to select profile types between 'ANDROID ENTERPRISE' and 'ANDROID ENTERPRISE (ADVANCED)'.
Both are methods to obtain enrollment and management permissions for devices but with differences in features. The advanced type has more controls for locking, such as auto-lock, remote lock, or unlock.
Method 2: Removal on Samsung Device
- Step 1: Open Settings on your Samsung device.
- Step 2: Go to Apps or Application Manager.
- Step 3: Find and select Knox Enrollment Service.
- Step 4: Tap Disable or Uninstall.
- Step 5: If greyed out:Go back to Settings > Security (or Biometrics and security) > Other security settings > Device admin apps (or Device administrators).
- Step 6: Deactivate Knox Enrollment Service or any related admin profile.
- Step 7: Return to the app info and try disabling again.
Method 3: Using Third-Party Tools
Some third-party tools claim they can bypass Knox lock (often using technology that forcibly triggers a factory reset), which may seem like a workaround. However, in most cases, Knox-enrolled devices will still be under organizational control after the reset due to built-in security features.
Given the risks, we strongly advise against using these tools. Sticking with the official method is always the safest and most reliable route:
-
If the bypass fails, your device could become permanently locked or even bricked.
-
The results are often unpredictable and may void your device's warranty or render it unusable.
What are Knox Deployment App and Knox Mobile Enrollment Direct?
The Knox Deployment app is a mobile app to enroll Samsung phones and tablets not eligible for KME in Knox Manage or Knox Configure. It has three enrollment methods—NFC deployment, Bluetooth deployment, and Wi-Fi Direct deployment. To use the app, you need to have it installed on an IT admin's device and use a Samsung Knox Admin Portal account.
Knox Mobile Enrollment Direct is an on-premise software to install on a laptop or PC running Windows 10. KME and KME Direct are the same in function. It's just that KME Direct requires more steps in the setup.
How Much Does Knox Mobile Enrollment/Knox Enrollment Service Cost?
Free. You don't have to pay to use the Samsung enrollment services. Moreover, no license is required.
As you can see, some other Knox Suite tools, like Knox Manage and Knox Platform for Enterprise, will require a license, which you need to purchase to get the right to use the service. But Knox Mobile Enrollment is allowed to use all features without a license.