barscaret-downcaret-leftcaret-rightcaret-upcheckchevron-leftchevron-rightfile-pdfinfosign-in-altsignin text-widthtimesyoutube

Android > Device Enrollment (Adding Devices)

Samsung Knox Mobile Enrollment

Updated on October 21st, 2020

Miradore is compatible with Samsung Knox Mobile Enrollment (KME) which provides IT administrators a streamlined way to enroll Samsung devices in an MDM/EMM solution without having to manually enroll and configure each device.

Benefits of using Samsung KME

  • KME simplifies the initial setup and enrollment of Samsung devices especially when a company requires bulk device enrollment with little configuration variance amongst the devices deployed.
  • KME makes device enrollment easy for device users, because they’re not required to do a thing. Once they receive the device and power it on, the device automatically configures itself according to the settings provisioned by the enterprise via Miradore.
  • KME-enrolled devices cannot be tampered with. Even if a KME-enrolled device is factory reset, the Miradore Client will be re-installed once the device is powered on and connected to a Wi-Fi or 3G/4G network again.

KME requirements

The following table is Samsung’s general guideline on Knox software support requirements.

Knox version2.42.4.12.52.62.72.7.12.82.9
KME enrollment via NFC
Out of box enrollment (Wi-Fi)
Out of box enrollment (4G/LTE)
Factory reset protection/Bypass skip setup wizard
Knox configure + Knox Mobile Enrollment same device compatibility
Knox Mobile Enrollment with Device Owner mode support

Here’s how to link Samsung KME with Miradore

Here’s how to connect the Samsung KNOX Mobile Enrollment to Miradore.

Note that devices enrolled to Miradore through KME can only be used in Device Owner Mode. If you wish to use Work Profile, there is a different way to enroll devices.

1. Log in to Miradore and go to the Enrollment > Android Enterprise page. Choose Actions > Download Knox Mobile Enrollment configuration from the page toolbar to download the Knox Enrollment JSON template to your computer.

KME1.png

2. Log in to the Samsung Knox Mobile Enrollment portal. Go to the MDM Profiles page and click Create profile to add an MDM profile.

Creating an MDM profile in Samsung Knox Mobile Enrollment portal

3. Select Android Enterprise as the profile type.

Select Android Enterprise when asked to choose the MDM profile type.

3. Next you are asked to fill in the Android Enterprise profile details.

    • Profile name: For example the name of the organization whose devices are managed.
    • MDM information: Choose “Force Device Owner enrollment”.
    • Pick your MDM: Choose “Miradore”.
    • MDM Agent APK: This field will be prefilled for you.
    • MDM Server URI: No need to fill this field.

Android Enterprise profile details

Click “Continue”.

4. Define Android Enterprise profile settings.

    • Custom JSON Data (as defined by MDM): Copy the contents of the JSON file you downloaded from Miradore and paste the contents into this field.
    • System applications
      • Disable all system applications: Select this checkbox to ensure all apps are disabled and unavailable to the device owner supported profile.
      • Leave all system apps enabled: Select this checkbox to ensure all pre-installed system apps are enabled and available to the profile. If this option is not selected, only a limited set of default system apps (My Files, Contacts, Google Play Store) display in the device’s apps tray. Systems apps reside within the device’s /system/app read-only folder and cannot be installed or removed by the device user.
    • Company name: Your organization’s name. This name will be shown to device users at the time of device enrollment.

Android Enterprise profile settings

5. Now you can assign this new MDM profile to those devices via “Devices” in the menu available on your KME account.

mceclip2.png

6. After you assign the MDM profile, everything is set up for enrolling the device to Miradore via KME, this is done from the “Welcome screen” before the device is set up if the device has been used already, it must be factory reset first.

The device must have access to the internet during enrollment, either via WiFi or unlocked SIM card with data, otherwise it will not be enrolled via KME.

7. Protip: On the Resellers page in Knox Mobile Enrollment portal, you can enable auto-assignment of MDM profile(s) to the devices bought from selected reseller(s).

This is a powerful feature if you always want to enroll devices bought from a certain reseller(s) to the same Miradore site.

Additional information

For more information about KME, check Samsung’s website.

Previous Article:
«

Next Article:
»

Get started with Miradore

Start securing your devices and data today with Miradore. Create a site in just a few minutes and start adding devices immediately. You can get started for free and try out the full features with our 14-day Enterprise trial.

No credit card needed.

SIGN UP FOR MIRADORESEE PLANS AND PRICING