# Enroll Knox Devices Last updated: August 13, 2026 This page guides MDM administrators through enrolling Samsung Knox devices in Mobile Device Manager Plus. It covers single device enrollment via the web console, adding multiple devices for the same user, and bulk enrollment using a CSV file. The page also details the end-user enrollment process using the ManageEngine MDM Self Service app, including Knox container creation for securing corporate data. FAQs explain Knox-supported devices, OS versions, and enterprise app distribution within the Knox container. Enrolling Devices is the first stage in managing a mobile device. This document explains in detail the various steps involved in enrolling [Samsung Knox](https://www.manageengine.com/mobile-device-management/samsung-knox-management.html) devices. ## Enrolling devices 1. On the web console, navigate to **Enrollment**. 2. Click **Enroll Device** and fill in the appropriate information. 3. **Domain Name:** Choose the Domain Name from the drop-down. If you do not have any domain name, select **Default Workgroup**. 4. **User Name:** Enter the user's name whose device needs to be enrolled. 5. **Email address:** It is mandatory to enter the email address of the user who will receive the enrollment request. 6. **Platform:** Specify the platform from the drop-down menu as Android. 7. **Owned By:** Specify the owner of the device as either **Corporate** or **Personal**. **Note:** Corporate Samsung devices running Android 11.0 or above cannot be enrolled using this method. 8. **Assign to Group:** Specify the group to which the device should be added. If you select an existing group from the drop-down, the newly added device automatically gets all the apps and profiles already distributed to the group. This automates the process of imposing the minimum required restrictions and apps on newly added devices. 9. If required, enable the checkbox stating "**Automatically distribute license if it is a Knox enabled device**." This makes license distribution automatic for Knox devices enrolled henceforth. 10. Click **Enroll** to enroll the device. If you add a new group name, a new group is created and the device is added to it. **Applicable only for MDM On-Premises:** Ensure that you configure your [Proxy settings](https://www.manageengine.com/mobile-device-management/help/configuring_mobile_device_manager/mdm_proxy_settings.html) and [mail server settings](https://www.manageengine.com/mobile-device-management/help/configuring_mobile_device_manager/mdm_mail_server_settings.html) so that the user can receive the email with the OTP. End users receive an email with enrollment instructions and a link to enroll the devices. Based on the authentication policy defined for enrollment, users receive the OTP. Users need to manually install the MDM profile by clicking the enrollment request. All enrolled devices are listed in the **Devices** tab in the Mobile Device Manager Plus console under **Groups and Devices**. ### Enrolling additional devices for same user You can enroll multiple devices for the same user. If a user has more than one mobile device that needs to be managed, enroll those devices by following these steps: 1. On the web console, navigate to **Enrollment**. 2. Under the **Enrollment** tab, choose the **User Name** for whom you want to enroll the additional device. 3. Under Actions, click the ![Adding a new device in ManageEngine MDM console](https://www.manageengine.com/mobile-device-management/help/images/add_device.png) button. 4. Specify the **Platform** as iOS or Android. 5. Specify the **Owned By** type as Corporate or Personal and click **Enroll**. The email to enroll the additional device is sent to the specified user. ### Bulk Enrollment This option enables you to enroll many devices at the same time. Create a CSV file with the User Name, Domain Name, Email, Platform, and Owned By details, and upload it. Multiple entries should be on separate lines. ### Sample CSV Format ```csv USER_NAME,DOMAIN_NAME,EMAIL_ADDRESS,PLATFORM_TYPE,OWNED_BY,GROUP_NAME,UDID ANDREW,,andrew@mobiledevicemanagerplus.com,iOS,Personal,IOS_Group,00f0ba8f7a6c41cca9cc5fd6b7ee666b ``` Note: 1. The CSV file should contain the following fields: User Name, Domain Name, Email Address, Platform Type, Owned By, Group Name, and UDID. 2. UDID is applicable only for iOS devices. 3. The fields User Name, Email Address, and Platform Type are mandatory. All other fields are optional. If not provided, default values are used. 4. The default values for non-mandatory fields are: - Domain Name -- MDM - Owned By -- Corporate - Group Name -- Default Group for the given Owned By and Platform Type. 5. The first line of the CSV is the column header, and the columns can be in any order. 6. Blank column values should be comma-separated. 7. If a column value contains a comma, it should be specified within quotes. Follow these steps to enroll devices through Bulk Enrollment: 1. On the web console, navigate to **Enrollment**. 2. Click **Bulk Enrollment**. A window opens. Click **Browse** to upload the created CSV file and **Import** it. Enrollment email is sent to all users listed in the CSV file. ### Enrollment Process on Knox devices Users who receive enrollment requests can enroll their devices as follows: Users need to copy the Server Name, Port Number, and OTP provided in the email. A ManageEngine MDM Self Service app exclusively designed for SAFE and Knox devices is downloaded to the user's device. The ManageEngine MDM Self Service app for SAFE and Knox devices has advanced management capabilities unlike normal Android devices. 1. Users receive an enrollment email and click the link in the email to start the enrollment process. 2. Mobile Device Manager Plus recognizes the device as a normal Android device, SAFE device, or Knox device, including the Android version. The user is automatically directed to the app's Play Store page, where the appropriate Knox app, ManageEngine MDM Self Service app for Android 4.2 and above, can be downloaded. If Mobile Device Manager Plus cannot identify the device, the user is provided with a link explaining the list of SAFE and Knox devices. The user can refer to the link and choose to download the appropriate app. The ManageEngine MDM Self Service app for Android 4.2 and above is designed to manage Knox devices. On choosing to download the appropriate app, the user is directed to the app's Play Store page. 3. Users must enter the certificate name as **ManageEngine MDM** and click OK. 4. The app can be downloaded by clicking **Download**. 5. Once the download is successful, users click the downloaded ManageEngine MDM Self Service app to install it. 6. After installation completes, users should open the app. 7. Users must provide the One Time Password (OTP) or Active Directory/Azure credentials after opening the app. This depends on the authentication type. If two-factor authentication is enabled, users must provide both the OTP and the AD/Azure credentials. 8. Users should accept the **Terms and Conditions** by clicking **Continue**. 9. Users should enable **Device Administrator** on their mobile device and click **Activate**. 10. Users can now see that their devices have been enrolled successfully. When a device is enrolled, the user receives an App Catalog from which apps distributed through Mobile Device Manager Plus can be installed. Administrators are also notified that a new user has enrolled the device. If specific profiles or apps were distributed to the group in which the device is enrolled, the newly added device automatically receives all applied profiles and distributed apps. The ManageEngine MDM Self Service app icon is listed on all enrolled mobile devices. By clicking the MDM app icon, the MDM app opens and the end user can see distributed apps and associated profiles. Profiles associated with devices are listed under Policies and Restrictions. Device Details provides complete information about the device. An exclusive Knox container is also created within the mobile device. By clicking the Knox container icon, the user can access the Policies and Restrictions page in the container. On clicking **Create Knox Container**, the user is prompted to accept the Terms and Conditions in the License Agreement. For Knox v1.0 devices, the Knox Container download process is initiated. This can take a while, after which the user is directed to set a password for the container. For other Knox devices, the user is automatically directed to the password setting page. This password is used to unlock and access the Knox Container and view corporate resources. Apps distributed by Mobile Device Manager Plus for the Knox container can be accessed by clicking the "Apps" icon within the container. By clicking the "Personal home" icon, the user can exit the Knox container and view personal data and apps on the device. [![Samsung Knox enrollment tutorial video thumbnail](https://www.manageengine.com/mobile-device-management/help/images/Samsung_knox_enrollment_video_thumbnail.png)](https://www.manageengine.com/mobile-device-management/demo/samsung-knox-enrollment-with-mdm-video.html) **We have made your job simpler!** Learn how to perform out-of-the-box Samsung Knox Mobile Enrollment using MDM, **in under 5 minutes**, through [this demo video](https://www.manageengine.com/mobile-device-management/demo/samsung-knox-enrollment-with-mdm-video.html). ### FAQs 1. What is Samsung Knox? Samsung Knox is a suite of enhancements designed to address security problems in the current open-source Android platform. Samsung Knox offers enhanced security compared with SAFE devices and is ideal for enterprises that require high-level security. It secures and segregates users' personal and corporate data by creating an exclusive container for corporate data. It also provides application security by allowing the segregation of apps for personal and corporate use. 2. What are all the Knox supported devices? Operating systems that support Knox include: - 4.2.2+ Jelly Bean - 4.3 Jelly Bean - 4.4.X Kit Kat - 5.0.X Lollipop - 6.0.X Marshmallow - 7.0.X Nougat - 8.0.X Oreo - 9.0.X Pie In devices running Android 10.0 or later, a Knox container cannot be created because a Harmonized Container is created that combines the Knox container and Android work profile. The smartphones and tablets that support Knox are: - Galaxy S5 series - Galaxy S4 series - Galaxy S3 - Galaxy Note 3 series - Galaxy Note 2 - Galaxy Grand 2 - Galaxy Tab series For more details on Knox-supported devices, refer to [this resource](https://www.samsungknox.com/en/knox-platform/supported-devices). - **Do we need a special agent or should we install plugin to avail this feature?** Knox devices can be managed by installing the ManageEngine MDM Self Service app designed for Android 4.2 and above. - **Can we install Enterprise Apps inside container?** Yes, only Enterprise Apps can be distributed and applied inside the Knox Container. - **What will happen to Apps inside container when the container gets removed?** When the Knox Container is removed, all apps present in the container are also removed. ## Frequently Asked Questions - **What are the prerequisites for enrolling Samsung Knox devices in ManageEngine MDM?** Prerequisites for Knox enrollment include a Samsung Knox-enabled device, a valid Knox license, network connectivity to the MDM server, and the ManageEngine MDM Self Service app installed on the device. - **Which Samsung device models support Knox management in ManageEngine MDM?** ManageEngine MDM supports Knox management on Samsung Galaxy devices that come preloaded with the Samsung Knox platform. Devices must run Android 5.0 or later with a compatible Knox version. - **Can Knox enrollment be done remotely without user interaction?** Yes. Admin enrollment for Knox devices can be initiated remotely from the ManageEngine MDM console without requiring manual input from the end user, provided the device is powered on and connected to the network.