Android Enterprise Smart Switch blocked by security policy with Knox Service PluginSolved

Participant
Discussion
3 days ago Sep 24, 2026

I’m enrolling corporate Samsung devices into Android Enterprise using QR code enrollment and applying a Hexnode policy during onboarding. The goal is to make device replacement easier by using Samsung Smart Switch or Samsung Cloud Backup.

I configured Knox Service Plugin to allow Smart Switch and enabled Samsung Account for Business. The devices also have a Knox Platform for Enterprise Premium license assigned. However, when Smart Switch or Samsung Cloud Backup is opened on an enrolled device, it shows “Blocked by your Security Policy.”

While checking the device logs, I keep seeing doRestrictionSmartSwitch=true even when Smart Switch is toggled on in the KSP policy. Is this a KSP misconfiguration, or is Android Enterprise blocking it somewhere else?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
3 days ago Sep 24, 2026
Marked SolutionPending Review

Hi @hugo_l ,

There are two separate behaviors to consider here:

1. Samsung Cloud Backup / Samsung Backup and Restore

Samsung Backup and Restore features are not available on devices enrolled using Android Enterprise activation modes such as Fully Managed / Device Owner enrollment. This restriction is enforced by the Android Enterprise framework, so it cannot be overridden through Hexnode or Knox Service Plugin. Enabling Samsung Account for Business does not bypass this Android Enterprise limitation.

The doRestrictionSmartSwitch=true entry can still appear because the OS-level restriction remains active for backup and restore functions.

2. Allowing the Samsung Smart Switch app itself

Samsung provides a workaround to allow the Smart Switch app on managed Samsung devices. In Hexnode, make sure the app and KSP configuration are both applied correctly:

  1. Go to Apps > Add apps > Managed Google apps.
  2. Search for and add Samsung Smart Switch.
  3. Go to the Android policy applied to the device.
  4. Add Samsung Smart Switch under App configurations.
  5. Set the managed app configuration to allow Smart Switch on the device.

If you are using Knox Service Plugin along with the native Hexnode policy, confirm that these KSP options are enabled:

  • Enable device policy control
  • Enable device customization
  • Enable device restriction controls
  • Allow Smart Switch

After applying the updated policy, sync the device. If this is being tested during enrollment, re-enrolling the test device with the corrected KSP configuration can help confirm whether the restriction is cleared from the start.

Regards,
Isabel Lora
Hexnode UEM

Marked SolutionPending Review
Participant
3 days ago Sep 24, 2026
Marked SolutionPending Review

This helped. I had enabled the Smart Switch option inside KSP, but I had not enabled all the parent KSP controls like device policy control, device customization, and restriction controls. After updating those and re-enrolling the test device, Smart Switch no longer shows the blocked by security policy message.

Does that mean Samsung Cloud Backup should work now too, or is that still separate?

Marked SolutionPending Review
Hexnode Expert
3 days ago Sep 24, 2026
Marked SolutionPending Review

The Smart Switch app being allowed and Samsung Cloud Backup working are separate outcomes.

Enabling the KSP parent controls and the Allow Smart Switch option can remove the policy block for launching or using the Smart Switch app where Samsung supports that workaround.

However, Samsung Cloud Backup / Samsung Backup and Restore remains unavailable for Android Enterprise Fully Managed / Device Owner devices. That part is not controlled by the Hexnode policy toggle. It is a platform restriction enforced during Android Enterprise enrollment.

For device replacement workflows, the recommended approach is usually to rely on managed app redeployment, account-based app sync, and app-specific backup or cloud sync options rather than Samsung Cloud Backup on Fully Managed devices.

Regards,
Isabel Lora
Hexnode UEM

Save