In 2019, Samsung announced its support for Android OEMConfig by launching the Knox Service Plugin. The main purpose of Knox Service Plugin was to offer its customers immediate access to existing and new features of Knox Platform for Enterprise. Today, Knox Service Plugin offers services to all Samsung devices, with plans to extend its services to other Samsung devices, wearables and displays.
Samsung’s Knox Service Plugin (KSP) is a solution that allows UEM customers to access Knox Platform for Enterprise’s (KPE) latest features right after its release, through a preferred UEM solution vendor like Hexnode UEM. KSP’s automatic deployment grants IT admins access to Knox’s latest features on the day of launch, rather than waiting for their UEM to integrate the features. Hexnode UEM offers integration with Knox Service Plugin that allows users to experience over-the-air deployment and updates in Samsung devices.
KSP is Samsung’s OEMConfig app that use managed configurations to configure OEM-specific device features. With OEMConfig, you can create and push configurations to apps through an XML schema file in an app on Google Play, meaning any UEM in compliance with the OEMConfig standard can set up KSP.
Pre-requisites of Knox Service Plugin
Samsung devices that support Knox and run Android 9.0 (Knox 3.2.1) or higher — or Android 8.0 (Knox 3.0) or higher for devices enrolled as Device Owner.
Set up your devices using the following Android Enterprise deployments: Managed Device (Device Owner), Work Profile (Profile Owner), and fully managed with a work profile
KSP works with the following Android Enterprise deployment modes:
Android 8.0: Fully managed device deployments only
Android 9.0, 10.0: Fully managed device i.e., Device Owner, Work Profile, fully managed device with a work profile, and Android dedicated devices (COSU) (Corporate-Owned Single Use) mode.
Android 11 and higher: Fully managed devices – Device Owner (DO), Work Profile on personally owned devices, Work Profile on company-owned devices.
A valid Knox Platform for Enterprise (KPE) license for each of the devices managed with KSP.
If you want to deploy premium policies, Knox’s Premium license provides advanced security features, kiosks, and device customization.
For the KSP implementation of OEMConfig, you must support:
Advanced app restrictions: Includes multi-level nested schema to render managed configuration of KSP.
Feedback channel: KSP uses feedback channel to return feedback to your UEM console. This allows IT admins to monitor the configuration status, like detecting and solving errors.
A Unified Endpoint Management (UEM) solution that supports advanced app restrictions, feedback channel, allows OEMConfig app customization and enables auto update setting.
Featured resource
Hexnode Android Management Solution
Get started with Hexnode’s Android Management solution to improve efficiency, increase productivity, save time and overhead costs of managing your corporate devices.
From your Hexnode UEM console, go to +Add Apps > Managed Google Apps, search for Knox Service Plugin, and select it to add KSP to the Hexnode app repository. Then, from a policy, go to Android > App Management > App Configurations to configure it.
The Hexnode UEM console deploys the applicable Knox features and policies using OEMConfig.
Set up policies in the form of Managed app configurations, which are saved and published to the managed enterprise devices.
The app settings and configurations are summarized into three categories; Device Wide Policies, Work Profile Policies (Profile Owner) and Common Configurations. You can check out Knox’s example schema to know more about the configurations.
When a user’s device is being provisioned, Hexnode UEM invokes the managed Google Play Store, installs KSP and pushes the managed configuration to the device.
After installation, the KSP app runs in the background on the device and applies the Knox policies and returns the result of the configuration process.
Samsung releases KSP updates every month, and gets updated automatically. So, devices with existing versions of KSP would receive the latest features as well, without the need to manually update the app.
How Long Does It Take for KSP Policies to Apply?
One question IT admins ask often: once a policy is pushed, how soon does it actually take effect on the device?
With Knox Service Plugin, propagation isn’t instant. Configuration changes typically apply within 1 to 2 days, depending on server traffic, device connectivity, and Google’s backend processing.
Here’s the flow: your UEM sends the schema data to Google. Google then delivers the managed configuration to the device. Once received, the KSP agent applies the updated policy and reports the result back through the feedback channel.
If there’s no functional change from the previous configuration, the agent skips the update entirely — so you won’t see unnecessary re-application of unchanged policies.
What if changes don’t apply within 2 days?
That’s usually a sign to check device connectivity, confirm the device is enrolled correctly, or reach out to support.
For testing, admins can enable Debug mode within KSP. This surfaces real-time logs on the device UI, confirming whether the managed configuration was received and processed correctly — useful before rolling a policy out fleet-wide.
Building this verification step into your deployment checklist helps avoid support tickets caused by simple propagation delays rather than actual configuration errors.
What are the key features of Knox Service Plugin?
With the Knox Service Plugin, you can configure and manage various Samsung device features:
Security
User authentication methods, multi-factor authentication, certificate management and DualDAR data encryption
Connections
Wi-Fi, Bluetooth, cellular data, tethering, USB, developer mode, NFC, APN, enterprise billing and global proxy
VPN
VPN providers, types and chaining, device scope, bypass, proxy and UID/PID metadata
App Management
Notifications, battery optimization and whitelisted device admins
Customization
Quick panel, battery protection and app suggestions
Firmware Updates
Over-The-Air updates, over Wi-Fi updates and recovery mode
Restrictions
Power and data saver modes, external storage encryption, Dual SIMs, Microphone, Sharing, common criteria and remote control
Samsung Knox Service Plugin provide customers access to Knox’s existing and new features as soon as they are launched commercially. Apart from this, the other benefits include:
Automatic Firmware Over-The-Air updates on enterprise Samsung devices.
Availability of all KPE features, regardless of which UEM you choose.
Knox Service Plugin helps UEM partners:
Remove the need for a separate app or months of development time to integrate new features to the UEM.
With managed configurations, UEM providers can roll out new features as soon as they’re released, with minimal development from their side. This minimizes the development cost, while ensuring that customers receive the latest updates.
When Should You Use KSP Instead of Native UEM Controls?
KSP is powerful, but it isn’t meant to replace your UEM’s built-in Android controls.
As a general rule: use your UEM’s native, standard Android Enterprise policies for common tasks — think basic restrictions, Wi-Fi, or app management. Reserve KSP specifically for Knox-exclusive capabilities unavailable anywhere else, like DualDAR encryption, VPN chaining, or Common Criteria mode.
Why does this distinction matter?
Native UEM policies are typically more stable, better tested across OS versions, and easier to troubleshoot. KSP configurations, since they mirror Samsung’s own schema updates, can shift with each monthly release.
Layering KSP only where it adds genuine value — rather than duplicating settings your UEM already manages — keeps policies cleaner and reduces the chance of conflicting configurations on a device.
A practical example:
If you only need to block the camera or manage Wi-Fi networks, Hexnode’s native Android restrictions already cover that. But if you need Samsung DeX customization, Knox Premium password policies, or advanced VPN behavior, that’s where KSP steps in.
This hybrid approach — using native Android controls for standard settings and KSP for Knox-exclusive capabilities — is a practical way to organize Samsung Knox management, helping IT admins avoid redundant policy layers.
Knox Service Plugin capabilities with Hexnode UEM
Device Restrictions
Enable device restriction controls: Use this control to enable or disable restriction controls for the device.
Allow Microphone: Use this setting to disable the microphone without user interaction.
Allow Wi-Fi: Use this control to allow or restrict the device’s ability to connect to Wi-Fi networks.
Allow Wi-Fi Direct: Use this control to allow or restrict the device’s ability to connect to Wi-Fi Direct networks.
Allow Bluetooth: Use this control to allow or restrict the device’s ability to make Bluetooth connections.
Allow cellular data: Use this control to allow or restrict the device’s ability to use the cellular data connection.
Allow VPN connections: Use this control to enable or disable VPN connections on the device.
Allow power saving mode: Use this control to enable or disable the device from entering the Power Saver mode automatically.
Enforce external storage encryption: Use this control to enable external storage (SD Card) encryption.
Allow user to modify Settings: Use this control to allow or restrict the user from changing the device settings.
Allow developer mode: Use this control to enable or disable the device to enter into a developer mode.
Allow camera: Use this control to enable or disable camera.
Allow USB debugging: Use this control to enable or disable the device to enter into a USB debugging mode.
Firmware update (FOTA) policy
Enable E-FOTA client installation and launch: Use this control to enable or disable installation and launch of E-FOTA client.
Enforce firmware auto-update on Wi-Fi (Premium): Use this control to enable or disable automatic firmware updates when the device is connected to Wi-Fi network.
Allow firmware update in recovery mode: Use this control to enable or disable firmware updates when the device is in recovery mode.
Allow firmware update over-the-air: Use this control to enable or disable firmware updates using Firmware-Over-The-Air (FOTA) technology.
Enable firmware controls: Use this control to enable or disable advanced firmware update options.
Password policy
Enable password policy controls with KSP: Use this control to allow management of password policies on the device.
Biometric authentication: Policies to manage the biometric authentication option without user interaction.
Enable multi factor authentication (Premium): Use this control to enable or disable multifactor authentication (2FA).
Password Change (Premium): A group of policies to manage password change.
Password Change (Premium): A group of policies to manage password change.
Maximum Failed Password Attempt to Wipe Data: Enter the maximum number of failed passwords allowed until the data in the device is wiped.
Define Password Quality: Select level of complexity you would like to define for the device password; From No Password to Complex Password (letter, numeric, alphanumeric); Numeric Complex.
Enable password visibility: Use this policy to control the visibility of Password while typing
Advanced Restriction policies (Premium)
Set USB Device Connection Type: Use this control to select the USB connection type.
Wi-Fi Advanced Detect suspicious network: A group of controls to configure WIPS to prevents unauthorized network access to local area networks and other information assets by wireless devices.
Allow dual SIM operation: Use this control to enable or disable the secondary SIM card slot on a dual SIM device.
Enable Common Criteria mode: Use this control to enable services to bring the device into the Common Criteria-evaluated configuration.
Allow remote control: Use this control to block connections to the device, using third-party remote-control apps.
Allow Bluetooth scanning: Use this control to block the device from scanning for Bluetooth devices in range to improve the accuracy of location detection.
Allow Allow Wi-Fi scanning: Use this control to block the device from scanning for Wi-Fi networks in range to improve the accuracy of location detection.
Enable Advanced Restrictions controls: Use this control to enable advanced controls on the device.
VPN policies (Premium)
Enable VPN chaining: Use this control to enable the use of two VPNs to double encrypt the data-traffic from apps added to the VPN profile.
Manage list of apps that can bypass VPN: Use these controls to add a list of applications at a device-wide or Work profile/Separated Apps specific level that can bypass VPN and connect to the network directly.
Enable on-demand VPN: For fully managed device with or without a Work profile/Separated Apps, enter a comma-separated list of package names to specify apps that can use VPN connections.
Manage list of apps that use VPN: Use these controls to add a list of applications at a device-wide or Work profile/Separated Apps specific level that can use VPN and connect to the network directly.
VPN type: Choose the VPN type applicable to the apps on the device.
Enable VPN controls: Use this control to enable or disable VPN controls for the device.
With Knox Service Plugin, users have immediate access to the latest Knox features, improving workplace efficiency, safety and providing customer satisfaction worldwide.
Hexnode UEM, now a Samsung Knox validated partner, can assist IT admins in ensuring maximum productivity at the workplace.
FAQs
Does Knox Service Plugin work on non-Samsung Android devices?
No, Knox Service Plugin is built exclusively for Samsung devices that support the Knox platform. It relies on Knox Platform for Enterprise (KPE) features embedded in Samsung’s hardware and firmware, which aren’t present on other Android OEM devices. Non-Samsung devices would need their own OEM-specific OEMConfig app instead.
Do I need a separate license to use KSP with Hexnode UEM?
Yes, KSP requires a valid Knox Platform for Enterprise (KPE) license for each managed device. Standard KPE features are covered under this base license, but deploying premium policies like advanced VPN chaining or Common Criteria mode requires the Knox Premium license tier. This licensing is managed through Samsung, separate from your Hexnode subscription.
What happens if a Samsung device isn’t enrolled correctly for KSP?
If enrollment isn’t set up correctly, KSP configurations may fail to apply even after the normal 1-2 day propagation window. Admins should first confirm the device is enrolled under a supported Android Enterprise mode, such as Device Owner or Work Profile. Using Debug mode can also help verify whether the device received the managed configuration at all.
Is Knox Service Plugin required to manage Samsung devices with Hexnode UEM?
No, KSP is not required for basic Samsung device management. Hexnode’s native Android Enterprise controls handle standard tasks like Wi-Fi, app management, and basic restrictions without KSP. KSP is only necessary when you need Knox-exclusive features unavailable through standard Android management.
How often should IT admins check for new Knox Service Plugin updates?
Admins don’t need to manually check, since Samsung releases KSP updates monthly and the app updates automatically. Existing devices with older KSP versions still receive new features without manual intervention. It’s still good practice to periodically review the Hexnode console to confirm new Knox policies are available for configuration.
Setup Samsung Knox device management for your enterprise