barscaret-downcaret-leftcaret-rightcaret-upcheckchevron-leftchevron-rightfile-pdfinfoinfo-circlesign-in-altsignin text-widthtimesyoutube

Android > App Management

Deny sending SMS messages on Samsung devices using Knox Service Plugin

Updated on June 8th, 2026

Learn how to deny sending SMS messages on Samsung devices using managed configurations for the Knox Service Plugin app.

Requirements

  • You must have a Miradore Premium or Premium+ subscription, or an active trial.
  • Managed Google Play Enterprise must be configured for your Miradore site.

Configure denying sending SMS messages

The Knox Service Plugin application allows you to control incoming and outgoing SMS messages. This guide helps you to configure the Knox Service Plugin to allow incoming SMS messages while denying sending them.

For this restriction to work, Rich Communication Services (RCS) messaging must be disabled for the device to fall back to using SMS. This is because devices using the Samsung Messages or Google Messages app use the RCS protocol for messaging instead of SMS.

  1. Navigate to Management > Applications and select Add > Android application.
  2. Select Managed Google Play store, then select Next.
  3. Search for Knox Service Plugin and select its tile from the results.
  4. Click Select.
    Result: The application's page opens. The same page can be opened by navigating to Management > Applications and double-clicking the application's row in the table.
  5. On the Configurations tab, click Select configuration > Add configuration.
  6. Enter a name for your configuration in the text box and press Enter.
    Note: You can make the configuration default for the application by ticking the Default checkbox.
    Result: The newly created configuration is open on the Configurations tab.
  7. Optional: Add the Debug Mode setting to the configuration by selecting the Plus sign icon on the right.
    Tip: Debug Mode shows policy results and errors on the device; use it only during testing and disable it before final deployment.
    Configuration settings list showing options including Add applications for accessing the Knox SDK, Advanced Wi-Fi Configurations (Premium), Allowed apps for reading private keys Configurations (Premium), Allowed USB devices for Applications Configurations, APN configurations, Certificate provisioning configurations, and Certificates (Premium), with the 'Debug Mode' row set to False and highlighted by a red border.

    1. In the Add managed property to application configuration wizard, select the Value checkbox.
    2. Select Add, then Close to exit the wizard.
  8. Add the Device-wide policies (Selectively applicable to Fully Manage Device (DO) or Work Profile-on company owned devices (WP-C) mode as noted) setting to the configuration by selecting the Miradore - plus icon config table icon on the right.
    Configuration settings list showing various options including Add applications for accessing the Knox SDK, Advanced Wi-Fi Configurations (Premium), APN configurations, Certificate provisioning configurations, Debug Mode (False), Device Account Policy Configurations, Device and Settings customization profile (Premium), and Device Key Mapping to Launch application Configurations, with the 'Device-wide policies (Selectively applicable to Fully Manage Device (DO) or Work Profile on company owned devices (WP-C) mode as noted)' row highlighted by a red border.

    1. Select Add in the Add managed property to application configuration wizard.
    2. Select Close to exit the wizard.
  9. Expand the Device-wide policies (Selectively applicable to Fully Manage Device (DO) or Work Profile-on company owned devices (WP-C) mode as noted) setting and add the Enable device policy controls setting to the configuration by selecting the Miradore - plus icon config table icon on the right.
    Configuration settings list under 'Device-wide policies (Selectively applicable to Fully Manage Device (DO) or Work Profile on company owned devices (WP-C) mode as noted)' showing various options including Advanced Restriction policies (Premium), Application management policies, Call and Messaging control, Device Controls, Device Restrictions, DeX policy, and Dual Data-at-rest (DAR) Encryption, with the 'Enable device policy controls' row set to False and highlighted by a red border.

    1. In the Add managed property to application configuration wizard, select the Value checkbox.
    2. Select Add, then Close to exit the wizard.
  10. Expand the Device-wide policies (Selectively applicable to Fully Manage Device (DO) or Work Profile-on company owned devices (WP-C) mode as noted) setting and add the Call and Messaging control setting to the configuration by selecting the Miradore - plus icon config table icon on the right.
    Configuration settings list under 'Device-wide policies (Selectively applicable to Fully Manage Device (DO) or Work Profile on company owned devices (WP-C) mode as noted)' showing Enable device policy controls (True), Advanced Restriction policies (Premium), Application management policies, and Audit Log (Premium), with the 'Call and Messaging control' row highlighted by a red border.

    1. Select Add in the Add managed property to application configuration wizard.
    2. Select Close to exit the wizard.
  11. Expand the Call and Messaging control setting and add the Enable call and messaging controls setting to the configuration by selecting the Miradore - plus icon config table icon on the right.
    Configuration settings list under 'Device-wide policies' with 'Call and Messaging control' expanded, showing Call Controls, Enable call and messaging controls (False), Manage RCS messaging (False), Set disclaimer text for messages, SMS Controls, and Enable device policy controls (True), with the 'Enable call and messaging controls' row highlighted by a red border.

    1. In the Add managed property to application configuration wizard, select the Value checkbox.
    2. Select Add, then Close to exit the wizard.
  12. Expand the Call and Messaging control setting and add the Manage RCS messaging setting to the configuration by selecting the Miradore - plus icon config table icon on the right.
    Configuration settings list under 'Device-wide policies' with 'Call and Messaging control' expanded, showing Call Controls, Enable call and messaging controls (False), Manage RCS messaging (False), Set disclaimer text for messages, and SMS Controls, with the 'Manage RCS messaging' row highlighted by a red border.

    1. In the Add managed property to application configuration wizard, select the Value checkbox to disable RCS messaging.
      Result: The Value column of the Configuration table shows True.
    2. Select Add, then Close to exit the wizard.
  13. Expand the Call and Messaging control setting and add the SMS Controls setting to the configuration by selecting the Miradore - plus icon config table icon on the right.
    Configuration settings list under 'Device-wide policies' with 'Call and Messaging control' expanded, showing Manage RCS messaging (True), Call Controls, Enable call and messaging controls (False), and Set disclaimer text for messages, with the 'SMS Controls' row highlighted by a red border.

    1. Select Add in the Add managed property to application configuration wizard.
    2. Select Close to exit the wizard.
  14. Expand the SMS Controls setting and add the Blocklist Outgoing SMS restriction setting to the configuration by selecting the Miradore - plus icon config table icon on the right.
    Configuration settings list under 'Device-wide policies' with 'Call and Messaging control' and 'SMS Controls' expanded, showing Manage RCS messaging (True), Blocklist Incoming SMS exception, Blocklist Incoming SMS restriction, Blocklist Outgoing SMS exception, and Blocklist Outgoing SMS restriction, with the 'Blocklist Outgoing SMS restriction' row highlighted by a red border.

    1. In the Add managed property to application configuration wizard, enter .* in the Value field to block sending SMS messages from all numbers associated with the device.
    2. Select Add, then Close to exit the wizard.
  15. Optional: Add the Profile name(version) setting to the configuration by selecting the Plus sign icon on the right.
    Tip: The Profile name(version) setting can help with tracking and debugging during the testing of the configuration.

    1. In the Add managed property to application configuration wizard, enter a unique profile name and version in the text box, then select Add.
  16. Deploy the configured application to the managed devices.
    Tip: It is recommended to deploy the configuration to a test device first. If the test is successful, remove the Debug Mode setting from the configuration before deploying it to your managed devices.

Results: Sending SMS messages from the managed device is denied. The device can still receive incoming SMS messages.

Previous Article:
«