Category filter

How to Configure Username Passthrough for Samsung Knox Mobile Enrollment

Samsung Knox Mobile Enrollment (KME) allows for the bulk enrollment of corporate-owned devices. To streamline this process further, Hexnode UEM supports Username Passthrough. This feature automatically pre-fills the user’s email address (User ID) during the enrollment authentication step, requiring the user to only enter their password.

This ensures that specific devices are enrolled only by the intended users, preventing unauthorized enrollment attempts.

Prerequisites & Important Notes

  • Supported Profiles: Username Passthrough is an optional feature available only for Knox devices enrolled via an Android Enterprise profile.
  • Data Requirement: You must pre-configure the User ID in the Samsung Knox Admin Portal before enrollment.
  • Matching Credentials: The User ID entered in the Knox portal must exactly match the user’s email address configured in the Hexnode portal.

Step 1: Configure User IDs in Knox Admin Portal

You can assign User IDs individually or in bulk within the Samsung Knox console.

Method A: Configure for a Single User

  1. Sign in to your Knox Admin Portal.
  2. Navigate to Devices in the left-hand menu.
  3. Select the specific device you wish to configure.
  4. In the User ID field, enter the user’s email address (ensure it matches their Hexnode email).
  5. Click Save.

Configuring Knox Username Passthrough on the device details page in Knox Admin Portal.

Method B: Configure for Bulk Users

  1. Sign in to your Knox Admin Portal..
  2. Navigate to Devices.
  3. Click on Actions > Bulk Actions > Assign User Credentials and Profile.
  4. Uploading user credentials for a bulk set of users to configure Knox Username Passthrough in Knox Admin Portal.

  5. Upload your .csv file containing the device details and corresponding User IDs.
  6. Click Submit.

 Uploading user credentials in bulk to configure Knox Username Passthrough in Knox Admin Portal.

Step 2: Send Enrollment Requests from Hexnode

Once the Knox side is configured, initiate the enrollment from Hexnode.

  1. Log in to the Hexnode UEM portal.
  2. Navigate to Enroll > All Enrollments > Invite > Email.
  3. Set the Domain to Local.
  4. Select your target:
    1. Single User: Select the user from the dropdown list.
    2. Bulk Users: Upload a .csv file containing the user details.
  5. Send the invitation.

What Happens on the Device?

When the user powers on the device and begins the enrollment process:

  1. The User ID configured in the Knox Portal is automatically passed to the Hexnode UEM app.
  2. The Username field on the authentication screen will be pre-populated and locked (grayed out).
  3. The user cannot change the username; they simply enter the password (provided in the enrollment email or their directory password) to complete setup.

Frequently Asked Questions (FAQs)

Q1: What is Samsung Knox?

Samsung Knox is a defense-grade security platform built into Samsung mobile devices from the chip up. It provides real-time protection against malicious attacks and creates a secure container to separate work data from personal data. For IT admins, it also offers a suite of cloud solutions (like Knox Mobile Enrollment) to deploy, manage, and secure devices at scale.

Q2: Is this feature mandatory for KME?

No, it is optional. If you leave the User ID field blank in the Knox Portal, the user will be required to manually type their username and password during enrollment.

Enrolling Devices