Samsung Knox

Relution supports Samsung Knox to provide advanced security and management features for Samsung devices.
Knox policies can be applied system-wide or within the work profile, depending on the device mode (Device Owner or Work Profile).
The Samsung Knox Service Plugin is automatically deployed on devices where the Knox policy is applied.
Configuration is done through this plugin and offers the following features:


Overview of Knox Features

The plugin provides the following functional areas:

Profile Settings

  • Profile name and version
  • Knox license key (e.g., Knox Suite, DualDAR)
  • Enable/Disable Debug Mode

App and Policy Management

  • Separate app policies (Work Profile vs. Device Owner)
  • Device settings (e.g., Camera, Quick Panel, Firmware Updates)
  • Work profile policies (Profile Owner)
  • App assignments for accessing Knox SDK

Network & Security

  • Advanced Wi-Fi configurations (Premium)
  • APN profiles
  • VPN profiles (Premium)
  • Firewall profiles
  • Proxy profiles (manual or PAC)

Certificates & Keys

  • Certificate management (Premium)
  • Deployment of certificates
  • Approved apps for accessing private keys (Premium)
  • UCM plugin configurations (Premium)

Device Configuration & Customization

  • Device accounts and policies
  • Device and settings customization (Premium)
  • Key mapping for launching apps
  • DeX customizations (Premium)
  • Peripheral configurations
  • USB device whitelisting

Advanced Profiles

  • NPA Data Points (Premium)
  • RCP Data Sync (Premium)
  • Permission controls for apps

Behavior in Relution

  • Configuration is done in the managed app configuration editor of the Knox Service Plugin.
  • A Knox configuration takes precedence over a Knox Service Plugin configuration in the Manage Apps configuration and overwrites it.
  • If the Manage Apps configuration of the same policy version already contains a Knox Service Plugin configuration, it is adopted when the Knox configuration is created. The form displays a notice to this effect.
  • Placeholders for user, device and certificates are supported.
  • If the plugin reports errors, the Knox configuration is shown in the device details with the yellow status Notice rather than as a violation (Violated). Without errors, the status is Resolved. The plugin’s feedback can be viewed there.
  • If the Knox configuration is removed from the policy, the Knox Service Plugin remains force-installed on devices where it is already installed and receives an empty configuration. This also applies if the plugin is blocked in Manage Apps.

Notes

  • Many features are only available on Knox-enabled Samsung devices. A list of supported devices is available on the Samsung Knox support page →.
  • Some advanced options require a valid Knox Premium License.
  • Before rollout, it is recommended to test with pilot devices, as Knox and Android Enterprise policies may overlap.
Top