Academy
Technical · Course T2

Lesson 5 of 5

Knox Mobile Enrollment

8 min read
In this lesson you'll learn to
  • Create a Knox MDM profile that points Samsung devices at WeGuard
  • Register devices via reseller upload or CSV
  • Wire the WeGuard Enterprise ID into the Knox profile
  • Position KME vs Zero Touch for Samsung fleets

Samsung fleets get their own zero-touch program: Knox Mobile Enrollment. Same promise as Google's — power on, walk away — with two practical differences partners should know cold: it reaches older Samsung hardware (most devices after 2016, below Android 8.0 included), and the customer can register devices themselves instead of depending entirely on the reseller.

Grab the Enterprise ID first

The Knox profile needs the tenant's Enterprise ID. In WeGuard, it's at Settings → Android, top of the page, with a copy button. No ID = Android Enterprise binding incomplete — back to lesson 1.

Create the MDM profile in Knox

Sign in at the Samsung Knox portal (create the customer's Knox enterprise account if they don't have one), then under Knox Mobile Enrollment → MDM Profiles:

FieldValue
Profile name"WeGuard MDM" or similar
MDM agentThe WeGuard Android agent package
MDM server URLThe WeGuard enrollment server URL from your account team
Custom JSON{"enterpriseId": "<the ID you copied>"}

Under device settings, the recommended posture for corporate fleets:

  • Skip initial setup wizard: on — that's the zero-touch feel
  • Allow user to skip MDM setup: off — otherwise users can bypass enrollment
  • Force device encryption: per the customer's security bar

Register the devices

Two paths, and this is where KME is friendlier than ZTE:

  • Reseller upload (recommended at scale) — the customer hands their Knox account details to a Knox-certified reseller, who pushes IMEIs/serials straight into the account.
  • Self-serve — in KME → Devices, add IMEIs or serial numbers manually or upload a CSV. Useful for devices bought outside the reseller channel.

Then select the devices and assign the WeGuard profile to them.

WeGuard-side prep and first boot

Make sure the right Android policy exists in WeGuard (Work Managed for corporate, Kiosk for dedicated; defaults under Settings → Device Provisioning). Then the device-side story matches ZTE: unbox or factory reset, power on, connect — the setup wizard is skipped, the agent installs, the policy applies, the device shows Active in WeGuard.

Positioning: KME vs ZTE

Zero TouchKME
VendorsAny Android Enterprise OEMSamsung only
Minimum OSAndroid 8.0Most Samsung models after 2016
Device registrationAuthorized reseller onlyReseller or self-serve CSV
ExtrasKnox-specific controls

They're not rivals — a mixed fleet runs both programs in one tenant. The sales answer to "we're a Samsung shop with older devices" is KME; to "we buy whatever's cheapest this quarter" it's ZTE; to "both" it's both.

Knowledge check
1. Which piece of WeGuard data goes into the Knox MDM profile?
2. Unlike Google Zero Touch, KME device registration can be done by…
3. When is KME the right call over Google Zero Touch?