# Configure and deploy Knox Service Plugin app for Samsung devices

The [Knox Service Plugin (KSP)](https://docs.samsungknox.com/admin/knox-service-plugin/welcome.htm) is Samsung’s OEMConfig application that allows enterprises to access and use all the Knox management features on their UEM consoles as soon as they are released in the market. KPE provides defense-grade security to a wide range of Samsung devices and equips them with best-in-class hardware security, policy management, and compliance capabilities, in addition to the extensive security features offered by UEM solutions. As a result, IT admins need not wait for their UEM solutions to integrate the latest Knox features to be able to deploy them to their corporate devices, hence providing IT admins better control over the distribution and configuration of KPE features. The KSP application must be added and approved in the Hexnode UEM portal before you can deploy the app to your target devices.

 Notes:- Your organization should be [enrolled in the Android Enterprise program](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-organization-in-android-enterprise-using-hexnode-mdm/).
- The Knox Service Plugin application is supported on Knox-supported Samsung devices running on Android 9.0 (Knox 3.2.1) and above. However, in the case of Knox-supported Samsung devices enrolled as Device Owner, the KSP application is supported from Android 8.0 (Knox 3.0).

 

Adding the Knox Service Plugin application from Policies 
---------------------------------------------------------

The Knox Service Plugin application must be added to the app inventory before you can configure it and associate it with your target devices. To add the KSP application,

1. Login to your Hexnode UEM portal.
2. Navigate to **Policies > New Policy > New Blank Policy**.
3. Enter suitable details for Policy Name and Description. Click on **Android** and select **Knox Service Plugin** under **Restrictions**.
4. Click on **Configure**.
5. Click on **Add and Approve**. Select the Knox Service Plugin application from the list of applications and click on **Select**.

Configuring the Knox Service Plugin application 
------------------------------------------------

Once the Knox Service Plugin application has been added to the Hexnode UEM portal, you can configure the app settings and preferences via policies by following the steps given below:

1. Login to your Hexnode UEM portal.
2. Navigate to **Policies > New Policy > New Blank Policy.**
3. Enter suitable details for Policy Name and Description. Click on **Android** and select **Knox Service Plugin** under **Restrictions**.
4. Click on **Configure**. If the Knox Service Plugin application has already been added, click on the **Configure** button.
5. Configure the available settings and click on **Done**.
6. In the **Configure Applications** window, you can edit the permissions, preferences and configurations of the KSP application. Once completed, click on **Done**.

Check out [Knox’s example schema](https://docs.samsungknox.com/admin/knox-service-plugin/policies.html) to get a detailed description of all the available configurations. You can configure device restrictions, policies, network settings, certificates, privacy preferences and much more using the Knox Service Plugin application.

Associating Policy Targets
--------------------------

If you haven’t saved the policy yet,

1. Go to the **Policy Targets** tab within the Policy.
2. Click on **+ Add Devices**.
3. Search and select the devices with which the Policy needs to be associated with and click on **OK**. You can also associate policies to **Device Groups, Users, User Groups** or **Domains** from the left pane underneath the **Policy Targets** tab.
4. Save the policy to associate the policy to the device.

If you have saved the policy,

1. From your **Policies** tab, check the policy.
2. Select **Associate Targets** from **Manage**.
3. Select the devices and click on **Associate** to get the policy associated with these devices.

 Note:- Once the Knox Service Plugin app is installed and the configurations are deployed to the device, the app can be removed only if: 
    - The device is factory reset, or
    - The work profile is deleted.