Samsung KME and Android Zero Touch

Introduction

Samsung Knox is a security platform for Samsung devices that allows organizations to securely manage their mobile devices. Android Zero Touch is a feature that allows you to automatically configure and provision your devices without the need for manual interaction with the device. Together, Samsung Knox and Android Zero Touch provide a comprehensive solution for secure and efficient enterprise mobile device management.

Automatic enrollment with Android Enterprise

For Android Enterprise, two different types are available for automatic enrollment:

  1. Samsung Knox Mobile Enrollment (KME) for Samsung devices
  2. Android Zero Touch for all other manufacturers with Android operating system

Samsung Knox Mobile Enrollment (KME)

With Samsung Knox Mobile Enrollment, Samsung devices can be quickly and easily prepared for management in a Mobile Device Management (MDM) system. The enrollment of company-, administration- or school-owned devices can be done faster without the need to manually enroll each device individually. This results in enormous time savings, especially when dealing with a large number of devices. The setup of the devices is started automatically as soon as they are put into operation and an Internet connection is established. Even if devices registered in the KME program are reset, they automatically re-enroll in the MDM system used. The KME program thus offers similar functions to Apple’s Device Enrollment Program (DEP).

Requirements

Samsung devices can be enrolled in the KME program by authorized dealers using the serial number. If the devices were not obtained from an authorized dealer, Samsung offers the possibility to add devices manually afterwards in the KME program. To do this, either a special QR code must be scanned during the device setup or the Knox Mobile Deployment app has be used on an additional Samsung device to set up a new device.

Combination of Samsung KME and Android Enterprise

Samsung Knox Mobile Enrollment can be combined with Android Enterprise enrollment types “Managed Device” (Managed Device) and Managed Device with Personal Profile (Company Owned, Personally Enabled - COPE).

KME enrollment

Prepare enrollment in Relution

  • Go to Devices > Enrollments and then click Add
  • Select Android Enterprise as the platform and either Set up managed device or Set up managed device with personal profile as the type, depending on your use case

Create an enrollment

  • Enable the Multiple enrollment option and select a validity date that will not expire soon
  • Save the enrollment
  • In the created enrollment, a KME Custom JSON is provided under Enrollment Information and the Use DPC Identifier tab. Copy this code to the clipboard

Enrollment information

Create KME profile

  • Log in to the Samsung Knox Portal →
  • Click on Profiles in the left side menu. Here you will find all the KME profiles that have already been created. The table also shows the number of linked devices

Overview KME profiles

  • Click on CREATE PROFILE in the upper right corner
  • Select Android Enterprise

Android Enterprise

  • Name the profile and select Other in the Pick your MDM field
  • In the MDM Agent APK field, add this address: https://play.google.com/managed/downloadManagingApp?identifier=setup
  • Click on Continue
  • In the upper left corner of the Custom JSON Data field, paste the JSON from your clipboard that you copied in the previous step
  • Click on Create

Optional

  • You can optionally create a QR code. This can be used to enroll or to add devices to the KME
  • To do this, click on ADD A QR CODE

KME QR Code

  • To add new devices to KME, the checkbox Also allow QR Code enrollment for devices not uploaded by a reseller must be enabled. Otherwise the code will only work with devices already stored in KME
  • Additionally you can store a Wi-Fi configuration. This can make the enrollment of a large number of devices much easier, as the Wi-Fi connection no longer needs to be set up manually
  • Finish your entries by clicking on ADD

Linking devices and profiles

  • If no QR code is used, devices that have already been registered have to be linked to the KME profile that has been created

  • To do this, switch to Devices in the side menu and select the desired devices

  • Then select the menu Actions > Configure Devices in the upper right corner

    KME QR Code

  • Then start up the devices as usual

Android Zero Touch

The functionality of Android Zero Touch is similar to that of Samsung Knox Mobile Enrollment (KME). A profile must be created in the Zero Touch Portal →, which is then linked to the desired devices from the device list.

Preparation for enrollment in Relution

  • Go to Devices > Enrollments and then click Add
  • Select Android Enterprise as the platform and either Set up managed device or Set up managed device with personal profile as the type, depending on your use case

Create an enrollment

  • Enable the Multiple enrollment option and select a validity date that will not expire soon
  • Save the enrollment
  • In the enrollment created, an Android Enterprise Zero Touch custom JSON is provided under Enrollment Information and the Use DPC Identifier tab. Copy this code to the clipboard

Enrollment information

Create Zero Touch Profile

  • Log in to the Zero Touch Portal →
  • Go to Configurations in the left menu
  • Click on the plus (+) icon in the gray bar
  • Name your configuration
  • Under EMM DPC select the option Android Device Policy. It is possible that there are several entries with this name. Use any one you like
  • Under DPC extras paste the JSON copied from your clipboard in the previous step
  • Fill in the remaining fields and click on ADD

Linking devices and profiles

  • Switch to the Devices section via the side menu
  • Select the appropriate configuration for each device
  • Then put the devices into operation as usual