Technical · Course T2Lesson 5 of 5
Knox Mobile Enrollment
8 min read- Create a Knox MDM profile that points Samsung devices at WeGuard
- Register devices via reseller upload or CSV
- Wire the WeGuard Enterprise ID into the Knox profile
- Position KME vs Zero Touch for Samsung fleets
Samsung fleets get their own zero-touch program: Knox Mobile Enrollment. Same promise as Google's — power on, walk away — with two practical differences partners should know cold: it reaches older Samsung hardware (most devices after 2016, below Android 8.0 included), and the customer can register devices themselves instead of depending entirely on the reseller.
Grab the Enterprise ID first
The Knox profile needs the tenant's Enterprise ID. In WeGuard, it's at Settings → Android, top of the page, with a copy button. No ID = Android Enterprise binding incomplete — back to lesson 1.
Create the MDM profile in Knox
Sign in at the Samsung Knox portal (create the customer's Knox enterprise account if they don't have one), then under Knox Mobile Enrollment → MDM Profiles:
| Field | Value |
|---|---|
| Profile name | "WeGuard MDM" or similar |
| MDM agent | The WeGuard Android agent package |
| MDM server URL | The WeGuard enrollment server URL from your account team |
| Custom JSON | {"enterpriseId": "<the ID you copied>"} |
Under device settings, the recommended posture for corporate fleets:
- Skip initial setup wizard: on — that's the zero-touch feel
- Allow user to skip MDM setup: off — otherwise users can bypass enrollment
- Force device encryption: per the customer's security bar
Register the devices
Two paths, and this is where KME is friendlier than ZTE:
- Reseller upload (recommended at scale) — the customer hands their Knox account details to a Knox-certified reseller, who pushes IMEIs/serials straight into the account.
- Self-serve — in KME → Devices, add IMEIs or serial numbers manually or upload a CSV. Useful for devices bought outside the reseller channel.
Then select the devices and assign the WeGuard profile to them.
WeGuard-side prep and first boot
Make sure the right Android policy exists in WeGuard (Work Managed for corporate, Kiosk for dedicated; defaults under Settings → Device Provisioning). Then the device-side story matches ZTE: unbox or factory reset, power on, connect — the setup wizard is skipped, the agent installs, the policy applies, the device shows Active in WeGuard.
Positioning: KME vs ZTE
| Zero Touch | KME | |
|---|---|---|
| Vendors | Any Android Enterprise OEM | Samsung only |
| Minimum OS | Android 8.0 | Most Samsung models after 2016 |
| Device registration | Authorized reseller only | Reseller or self-serve CSV |
| Extras | — | Knox-specific controls |
They're not rivals — a mixed fleet runs both programs in one tenant. The sales answer to "we're a Samsung shop with older devices" is KME; to "we buy whatever's cheapest this quarter" it's ZTE; to "both" it's both.