# Enroll Knox Devices Enrolling devices is the first stage in managing a mobile device. This document explains the various steps involved in enrolling [Samsung Knox](https://www.manageengine.com/mobile-device-management/samsung-knox-management.html) devices. ## Enrolling Devices 1. On the web console, navigate to **Enrollment**. 2. Click **Enroll Device** and fill in the appropriate information. 3. **Domain Name:** Choose the domain name from the drop-down. If you do not have any domain name, select **Default Workgroup**. 4. **User Name:** Enter the user's name whose device needs to be enrolled. 5. **Email address:** Enter the email address of the user who will receive the enrollment request (mandatory). 6. **Platform:** Specify **Android** from the drop-down menu. 7. **Owned By:** Specify whether the device is **Corporate** or **Personal**. **Note:** Corporate Samsung devices running Android 11.0 or above cannot be enrolled using this method. 8. **Assign to Group:** Specify the group to which the device should be added. Selecting an existing group automatically distributes all previously assigned apps and profiles to the newly added device. 9. (Optional) Enable **Automatically distribute license if it is a Knox enabled device** to automate license distribution for future Knox enrollments. 10. Click **Enroll** to enroll the device. If you add a new group name, a new group will be created and the device will be added to it. **(Applicable only for MDM On-Premises)** Ensure that you configure your [Proxy settings](https://www.manageengine.com/mobile-device-management/help/configuring_mobile_device_manager/mdm_proxy_settings.html) and [mail server settings](https://www.manageengine.com/mobile-device-management/help/configuring_mobile_device_manager/mdm_mail_server_settings.html) so that users can receive the email with the OTP. End users will receive an email with enrollment instructions and a link to enroll their devices. Based on the authentication policy defined, users will receive an OTP if required. Users must manually install the MDM profile by clicking the enrollment request. All enrolled devices will be listed in the **Devices** tab under **Groups and Devices** in the Mobile Device Manager Plus console. ### Enrolling Additional Devices for the Same User You can enroll multiple devices for the same user. 1. On the web console, navigate to **Enrollment**. 2. Under the **Enrollment** tab, choose the **User Name** to whom you want to enroll the additional device. 3. Under **Actions**, click the add device button: ![](https://www.manageengine.com/mobile-device-management/help/images/add_device.png) 4. Specify the **Platform** as iOS or Android. 5. Specify the **Owned By** type as Corporate or Personal and click **Enroll**. An enrollment email will be sent to the specified user. ## Bulk Enrollment This option allows you to enroll multiple devices at the same time. Create a CSV file containing the following details: - User Name - Domain Name - Email - Platform - Owned By - Group Name - UDID Each entry must be on a separate line. ### Sample CSV Format ``` USER_NAME,DOMAIN_NAME,EMAIL_ADDRESS,PLATFORM_TYPE,OWNED_BY,GROUP_NAME,UDID ANDREW,,andrew@mobiledevicemanagerplus.com,iOS,Personal,IOS_Group,00f0ba8f7a6c41cca9cc5fd6b7ee666b ``` **Notes:** 1. The CSV file must contain the following fields: User Name, Domain Name, Email Address, Platform Type, Owned By, Group Name, and UDID. 2. UDID is applicable only for iOS devices. 3. User Name, Email Address, and Platform Type are mandatory. Other fields are optional and default values will be used if not provided. 4. Default values for non-mandatory fields: - Domain Name — MDM - Owned By — Corporate - Group Name — Default Group for the given Owned By and Platform Type 5. The first line must be the column header. Columns can be in any order. 6. Blank column values must be comma separated. 7. If a column value contains a comma, enclose it within quotes. ### Steps for Bulk Enrollment 1. On the web console, navigate to **Enrollment**. 2. Click **Bulk Enrollment**. 3. Click **Browse** to upload the CSV file and click **Import**. Enrollment emails will be sent to all users listed in the CSV file. ## Enrollment Process on Knox Devices After receiving the enrollment request, users can enroll their device as follows: Users must copy the Server Name, Port Number, and OTP provided in the email. An ME MDM App designed exclusively for SAFE and Knox devices will be downloaded. This app offers advanced management capabilities compared to standard Android devices. 1. Click the enrollment link in the email to begin the process. 2. Mobile Device Manager Plus detects whether the device is a normal Android, SAFE, or Knox device (Android 4.2 and above or below). The user is directed to the appropriate Play Store page to download the ME MDM App for Knox (Android 4.2 and above). If detection fails, a link to supported SAFE and Knox devices is provided. 3. Enter the certificate name as **ME MDM** and click **OK**. 4. Click **Download** to download the app. 5. Install the downloaded ME MDM App. 6. Open the app after installation. 7. Enter the OTP or Active Directory/Azure credentials based on the authentication type. If two-factor authentication is enabled, provide both OTP and AD/Azure credentials. 8. Accept the **Terms and Conditions** by clicking **Continue**. 9. Enable **Device Administrator** and click **Activate**. 10. The device will be enrolled successfully. Once enrolled: - Users receive an App Catalog to install distributed apps. - Administrators are notified of new enrollments. - Devices automatically receive profiles and apps assigned to their group. The ME MDM App icon appears on enrolled devices. Users can view distributed apps, policies, and restrictions within the app. Device details provide complete device information. An exclusive Knox container is created on the device. By selecting the Knox container icon: - Click **Create Knox Container** and accept the license agreement. - For Knox v1.0 devices, the container download begins, followed by password setup. - For other Knox devices, users are directed to set a container password directly. - This password is required to access corporate resources within the container. - Distributed enterprise apps can be accessed via the **Apps** icon inside the container. - Select **Personal home** to exit the Knox container and access personal apps and data. [![Samsung Knox enrollment video](https://www.manageengine.com/mobile-device-management/help/images/Samsung_knox_enrollment_video_thumbnail.png)](https://www.manageengine.com/mobile-device-management/demo/samsung-knox-enrollment-with-mdm-video.html) **We have made your job simpler!** Learn how to perform out-of-the-box Samsung Knox Mobile Enrollment using MDM, **in under 5 minutes**, through [this demo video](https://www.manageengine.com/mobile-device-management/demo/samsung-knox-enrollment-with-mdm-video.html). ## FAQs 1. What is Samsung Knox? Samsung Knox is a suite of enhancements designed to address security issues in the Android platform. It offers enhanced security compared to SAFE devices and is ideal for enterprises requiring high-level security. Knox enables separation of personal and corporate data using an exclusive container and provides application-level segregation. 2. What are the Knox supported devices? **Supported operating systems:** - 4.2.2+ Jelly Bean - 4.3 Jelly Bean - 4.4.X KitKat - 5.0.X Lollipop - 6.0.X Marshmallow - 7.0.X Nougat - 8.0.X Oreo - 9.0.X Pie In devices running Android 10.0 or later, a Harmonized Container replaces the Knox container by combining it with the Android work profile. **Supported smartphones and tablets:** - Galaxy S5 series - Galaxy S4 series - Galaxy S3 - Galaxy Note 3 series - Galaxy Note 2 - Galaxy Grand 2 - Galaxy Tab series For more details on supported devices, refer to [Samsung Knox supported devices](https://www.samsungknox.com/en/knox-platform/supported-devices). - **Do we need a special agent or plugin?** Knox devices can be managed using the ME MDM App designed for Android 4.2 and above. - **Can we install enterprise apps inside the container?** Yes. Only enterprise apps can be distributed and applied inside the Knox container. - **What happens to apps inside the container when it is removed?** When the Knox container is removed, all apps within the container are also removed.