Samsung devices do not support Android Enterprise Zero Touch, but many want the same feature to automatic enroll Samsung devices into Intune with out touching the devices. This is possible for Samsung devices if you are using Samsung KNOX enrollment, that is a free service from Samsung, you just need to set it up and configure automatic enrollment into Intune. Samsung devices do not support Android Enterprise Zero Touch and in a Enterprise that is not always a good thing, but with Samsung KNOX Mobile Enrollment (KME) we can  create a similarly experience for the IT admin and the end user. In this blog post I show how the IT admin can get a existent device into KME – I will highly recommend to let your device reseller to the the heavy work on getting the devices in to KME.
In this blog post I will cover how to get Samsung KNOX and configure automatic enrollment into Intune and Android Enterprise. You can also use KNOX enrollment with Device Admin – i will not cover that in this blogpost.


 

Start by going to Samsung KNOX portal – if you are not signed up then create a Samsung account, like any other service in your IT infrastructure create a service account and do not use a personal account so the the service belongs to the company and not a named user that can leave the company at some point in time.

  1. Enter Email
  2. Enter Password
  3. Click Sign in

AE ZeroTouch with KNOX - 01

Fill out any required information in the register for Samsung Knox web portal

AE ZeroTouch with KNOX - 02

There is a lot of solutions in the Samsung KNOX universe, but we only need the Knox Mobile Enrollment (KME) to get the devices silent into Intune.

  1. Click Apply now

AE ZeroTouch with KNOX - 03

  1. Click “I have read and agree to the …”
  2. Click Summit application

AE ZeroTouch with KNOX - 04

Now you just have to wait until you application has been approved, in my case I got a call from Samsung after 2 days where they was asking what I needed the KME for and who my reseller was. When that was sorted out I had access to KME the next day.

  1. Click Launch console

AE ZeroTouch with KNOX - 05

The firm time accessing KME you need to do some setup, it takes about 5 minutes and then you are ready to go.

  1. Click Start

AE ZeroTouch with KNOX - 06

The integration with Intune do require a MDM server URI.

  1. Click Server URI not required for my MDM
  2. Click continue

AE ZeroTouch with KNOX - 07

Now you need to create your first MDM profile – this profile allows you to configure how your devices is getting into Intune

  1. Enter name : Intune Enrollment
  2. Click add support contact

AE ZeroTouch with KNOX - 08

When you are filling out the support contact details you can see it as preview on the right side

  1. Enter Company Name
  2. Enter Company Address
  3. Enter Support Phone Number
  4. Enter support Email Address
  5. Click Save

AE ZeroTouch with KNOX - 09

  1. Click Add MDM application

AE ZeroTouch with KNOX - 10

Here you have to choose between Android Enterprise or Android (Device Admin)

Android Enterprise :  https://aka.ms/intune_kme_deviceowner
Android : https://aka.ms/intune_kme

  1. Enter https://aka.ms/intune_kme_deviceowner
  2. Click Save

AE ZeroTouch with KNOX - 11

When you have entered the MDM agent APK you get more options:

  1. MDM APK
  2. Click Enable this app as a Google Device Owner
  3. Select Microsoft Intune as supported MDM

AE ZeroTouch with KNOX - 16

After you have saved the profile you get the option to enter your reseller so the reseller can automatic upload new devices that you a purchasing and assign a default profile.
To enter the reseller is optional but I will highly recommend it so you can automated the hole process and allowing you to send the devices directly to the end user.

  1. Click Skip

AE ZeroTouch with KNOX - 14

Then you are all set and ready to get your Samsung devices into the KME service

  1. Click Next

AE ZeroTouch with KNOX - 15

And you are ready with your Samsung KNOX setup.


You have to possibility to add your own devices to Samsung KNOX for existent devices.

Prerequisite for IT Admins:

  • You need to have applied for and set up a username and password for Knox Mobile Enrollment or Knox Configure before they can use the Knox Deployment App.
  • Your devices must support NFC or Bluetooth. Please check your device specification.
  • You must have at least one profile configured in the Knox Mobile Enrollment or Knox Configure portal.

You need to download the Knox Deployment Application from Google Play

AE ZeroTouch with KNOX - 20

Start KNOX Deployment Application

  1. Enter Email address
  2. Enter Password
  3. Click Sign In

Screenshot_20190610-211712_Knox Deployment

Then you can move forward to and get your devices in Samsung KNOX

  1. Select a profile you have created in Samsung KNOX
  2. Select deployment mode – in my example I use NFC (You can also be Bluetooth)

Screenshot_20190610-225559_Knox Deployment

After the profile deployment to the device you can see the device in your Samsung KNOX portal.

AE ZeroTouch with KNOX - 21.png

Happy deployment 🙂


Read more:

Automatically enroll Android devices by using Samsung’s Knox Mobile Enrollment

Meet Samsung Knox