Enable Samsung Cloud backups on Android Enterprise Samsung devicesSolved

Participant
Discussion
2 days ago Sep 01, 2026

I’m setting up Android Enterprise enrollment for Samsung devices in Hexnode and noticed that Samsung Cloud backups are disabled by the security policy. Google Drive backup options are available and enabled, but I can’t find a Samsung Cloud-specific setting under the usual Android or Knox restrictions.

Is there a way to allow Samsung Cloud backups for fully managed Samsung devices through Hexnode? Also, if a device is lost or replaced, does restoring a cloud backup enroll the replacement device automatically, or does the device need to be enrolled first?

Replies (6)

Marked SolutionPending Review
Hexnode Expert
2 days ago Sep 01, 2026
Marked SolutionPending Review

Hi @abel-j,

Samsung Cloud backup access on Android Enterprise fully managed Samsung devices is not controlled through the standard Android restriction toggles in Hexnode.

In fully managed/device owner mode, Android Enterprise restricts OEM-specific cloud services by default to reduce the risk of corporate data being synced to unmanaged personal accounts. Google backup works more directly because it is tied to the managed Google account framework.

For Samsung Cloud backup-related controls, use Samsung’s OEMConfig app, Knox Service Plugin.

Recommended configuration:

  1. Add Knox Service Plugin to Hexnode
    • Go to Apps > Add Apps > Managed Google Apps.
    • Search for Knox Service Plugin.
    • Approve and add it to the app repository.
  2. Configure it in a policy
    • Go to Policies and create or edit an Android policy.
    • Under Android, open Knox Configurations > Knox Service Plugin.
    • Click Configure.
  3. Enable the required Samsung account and backup controls
    • Enable Device Account Policy controls.
    • Enable Samsung Account for Business option under Samsung Account configuration.
    • If you plan to use Samsung Smart Switch for backup or restore, also enable Allow Smart Switch.
  4. Deploy the policy
    • Save the Knox Service Plugin configuration.
    • Assign the policy to the required Samsung devices or device groups.

Hexnode will install Knox Service Plugin on the target devices and push the OEMConfig settings silently.

Restoring a backup does not automatically enroll a new device into Hexnode. A replacement device must be enrolled first from the factory setup screen. After enrollment, Hexnode applies the required management profile, policies, apps, and restrictions.

Regards,
Isabel Lora
Hexnode UEM

Marked SolutionPending Review
Participant
2 days ago Sep 01, 2026
Marked SolutionPending Review

That helps, but I’m still a bit confused about the restore flow. I usually enroll devices with the 6-tap QR code method from the Android welcome screen. I don’t remember seeing the usual “Copy apps and data” screen during setup. Am I missing it, or is it skipped because of the QR enrollment?

Marked SolutionPending Review
Hexnode Expert
2 days ago Sep 01, 2026
Marked SolutionPending Review

You are not missing it. With the 6-tap QR code enrollment method, Android starts a corporate provisioning flow that can suppress the standard consumer “Copy apps and data” screen.

For that enrollment method, use this workflow instead:

  1. Factory reset or start with a new Samsung device.
  2. From the welcome screen, tap 6 times and scan the Hexnode enrollment QR code.
  3. Complete enrollment and reach the home screen.
  4. Wait a few minutes for Hexnode to install apps and apply policies, including the Knox Service Plugin configuration.
  5. Open Samsung Smart Switch on the device.
  6. Sign in with the allowed Samsung account and restore the cloud backup, or transfer data from the old device if available.

If Samsung Smart Switch does not open or is missing, check whether it is blocked by an app blacklist, app restriction, or kiosk/app control policy. Smart Switch must be allowed if it is part of your backup and restore workflow.

Regards,
Isabel Lora
Hexnode UEM

Marked SolutionPending Review
Participant
2 days ago Sep 01, 2026
Marked SolutionPending Review

We ran into the same thing. We had blocked Smart Switch because it looked like preinstalled bloatware, and then nobody could restore from Samsung Cloud after enrollment. Allowing Smart Switch and pushing the KSP settings fixed the restore path for our Samsung devices.

Marked SolutionPending Review
Participant
2 days ago Sep 01, 2026
Marked SolutionPending Review

So the safe process is: enroll first, wait for the Knox Service Plugin policy to apply, then restore with Smart Switch. The backup itself won’t bring the device into Hexnode automatically. That clears it up.

Marked SolutionPending Review
Hexnode Expert
2 days ago Sep 01, 2026
Marked SolutionPending Review

Correct. Treat enrollment and backup restoration as separate steps:

  • Enrollment claims and manages the device in Hexnode.
  • The Samsung Cloud or Smart Switch restore brings back user data, supported settings, and app-related content.

For Android Enterprise devices, the device must be enrolled into management first. The backup does not contain the Hexnode enrollment state and cannot automatically enroll a replacement device.

Regards,
Isabel Lora
Hexnode UEM

Save