Minimum requirements
Last updated September 1st, 2026
You must meet the following requirements to use the Knox Service Plugin on your managed devices.
What you need
-
Samsung devices that support Knox and run Android 12 or later.
-
A Unified Endpoint Management (UEM) solution that supports Android Enterprise deployments and is compatible with Knox Service Plugin.
-
A valid Knox Platform for Enterprise (KPE) license. For more information about Knox licenses, see Knox Platform for Enterprise licenses.
-
You must set up your devices in one of the supported Android Enterprise deployments.
Supported deployments
Before you can use Knox Service Plugin, your devices must be deployed in one of the following Android Enterprise deployment modes.
-
Fully managed — Also known as Company Owned, Business Only (COBO) — lets admins manage company devices that are owned by the enterprise, and are devices intended exclusively for work purposes. IT admins have full control over fully managed devices.
-
Company owned devices with a work profile — Company owned devices with a personal profile and a work profile. Employees can use these devices for personal and work purposes. For more information, see the Android Enterprise documentation.
-
Work Profile — Helps admins manage the BYOD (Bring Your Own Device) use case, where employees bring a personal device and a managed work profile is deployed on to the device. IT admins can only control the work area, and have no visibility or access outside of it.
Refer to your respective EMM configuration guide for information on provisioning dedicated devices (COSU).
Supported features
Your deployment must use policy configurations that Knox Service Plugin supports. Knox Service Plugin inherits its policies from the Knox Platform for Enterprise framework. These policies can be either standard or premium features. Premium features require a free Knox Platform for Enterprise Premium license.
Supported UEMs
You need a UEM that supports Android Enterprise based deployments, device management APIs, and complies with the OEMConfig specification. Check with your UEM vendor to confirm which version of the UEM console you need to use with Knox Service Plugin. Some UEMs offer more than one console, and some consoles may not support Knox Service Plugin.
For information about configuring UEMs, see Set up with a UEM.
All UEM partners continue to support Knox Platform for Enterprise through their console. Customers need to use Knox Service Plugin only if their UEM solution provider doesn’t support a Knox feature they plan to use. For more information, see Which policy should I use if duplicate policies exist?.
On this page
Is this page helpful?