- *BASICS*
- The Knox Ecosystem
- White Paper
- Samsung Knox Portal
- Knox Cloud Services
- General Knox Support
- Knox Licenses
- *FOR IT ADMINS*
- Knox Admin Portal
- Knox Suite
- Knox Platform for Enterprise
- Introduction
- How-to videos
- Before you begin
- Get started with UEMs
- Introduction
- Blackberry UEM
- Citrix Endpoint Management
- FAMOC
- IBM MaaS360
- Microsoft Intune
- MobileIron Cloud
- MobileIron Core
- Samsung Knox Manage
- SOTI MobiControl
- VMware Workspace ONE UEM
- Knox Service Plugin
- Release notes
- Migrate to Android 11
- FAQs
- Troubleshoot
- KBAs
- Knox Mobile Enrollment
- Introduction
- How-to videos
- Get started
- Features
- Register resellers
- Add an admin
- Create profiles
- Google device owner support
- MDM compatibility matrices
- Device users
- Activity log
- Enroll and unenroll devices
- Configure devices
- Provide KME feedback
- Use the Knox Deployment App (KDA)
- Recover Google FRP locked devices using KME
- Role-based access control (RBAC)
- Release notes
- FAQs
- Troubleshoot
- KBAs
- On-Premise
- Knox Configure
- Mobile
- Wearables
- Shared Device
- KBAs
- Knox Capture
- Introduction
- How it works
- How-to videos
- IT admins: Get started
- Getting started with Knox Capture
- Step 1: Launch Knox Capture
- Step 2: Create a scanning profile
- Step 3: Select apps and activities
- Step 4: Configure the scanner
- Step 5: Set keystroke output rules
- Step 6: Test apps in your configuration
- Step 7: Share your configuration
- Step 8: Deploy Knox Capture in Managed mode
- End users: Get started
- Features
- Release notes
- FAQs
- Troubleshoot
- Knox Asset Intelligence
- Knox Manage
- Introduction
- How-to videos
- Get started
- Video: Getting started with Knox Manage
- Integration with Managed Service Provider
- Access Knox Manage
- Configure basic environments
- Create user accounts
- Create groups
- Create organization
- Set up devices and profiles
- Set up Knox Manage deployment with a Knox Suite license
- Manage Chromebooks
- Manage Android devices with the Android Management API
- Manage Shared iPads
- Configure
- Licenses
- Organization
- Users
- Sync user information
- Groups
- Devices
- Content
- Applications
- View applications
- Add applications
- Introduction
- Add internal Android and iOS applications
- Add internal Windows applications
- Add public applications using Google Play Store
- Add public applications using iOS App Store
- Add public applications using Managed Google Play
- Add public applications using Managed Google Play Private
- Add public applications using Managed Google Play Store Private Web
- Add public applications using Microsoft Store
- Add Chrome OS applications
- Assign applications
- Introduction
- Assign internal Android and iOS apps
- Assign iOS App Store applications
- Assign Google Play applications
- Assign Managed Google Play applications
- Assign Managed Google Play Private applications
- Assign Managed Google Play public web apps
- Assign Windows applications
- Assign Chrome OS applications
- Manage applications
- Volume Purchase Program for iOS
- Profile
- Knox E-FOTA
- Certificates
- Advanced settings
- Monitor
- Kiosk devices
- Knox Remote Support
- Active Directory
- Microsoft Exchange
- Mobile Admin
- Appendix
- Release notes
- Features
- FAQs
- KBAs
- Knox E-FOTA
- Introduction
- How-to videos
- Get started
- Features
- EMM integration
- Appendix
- Release notes
- FAQs
- KBAs
- Troubleshoot
- Knox E-FOTA On-Premises
- Legacy Knox E-FOTA products
- Knox Guard
- Introduction
- How-to video
- Get started
- Using Knox Guard
- Dashboard
- Manage devices
- Introduction
- Accept or reject devices
- Upload devices
- Delete devices
- Complete payment
- Send payment overdue notification
- Enable or disable SIM control
- Download devices as CSV
- View device log
- View device deletion log
- Start and stop blinking reminder
- Lock and unlock devices
- Update lock message
- Send relock timestamp
- Turn on/off relock reminder
- Manage policies
- Manage licenses
- Manage resellers
- Manage admins and roles
- Activity log
- Knox Deployment App
- Release notes
- FAQs
- KBAs
- Support
- Samsung Care+ for Business
- *FOR RESELLERS*
- Knox Deployment Program
- *FOR MANAGED SERVICE PROVIDERS*
- Knox MSP Program
Manage admins and roles
Admins play a central role in approving registration requests as well as approving device reseller registration requests and assigning a reseller type and commercial availability designation to a reseller account.
With Role-Based Access Control (RBAC), admins responsible for account creation (Super Admins) are able to assign refined role permissions to each individual admin.
Each reseller account can be managed by multiple administrators.
Create a role
Roles are assigned to each admin to specify custom permissions and access. When View only permission is selected, no profile configuration, device management, license or reseller administration is permitted. Note that new roles will have the View only permission selected by default.
To create a role to assign to an admin:
- Log in to the Knox Reseller Portal.
- Select Administrators and Roles from the left-hand navigation menu.
- Select the ROLES tab.
- Click the CREATE ROLE button.
- Define the following role details and administrative permissions:
- Role name — Enter unique name for the role to help you identify the newly created role during assignment.
- Description — Enter a description for the role. Max 200 characters permissible.
- Customers — Add Manage customers permissions to add/edit customer configurations or View only permissions.
- Devices — Add the ability to Upload devices, and Delete devices to the role's permissions, or just view customer device configurations.
- Activity log — Select this option to assign the ability view customer activity logs.
- Administrators and Roles — Select Invite and manage administrators to grant this administrator the ability to invite other administrators into the Knox Reseller Portal. Select Manage roles to grant this administrator the ability to assign roles, which includes role permissions the assigning administrator doesn't have.NOTE —The ability to Create and manage roles is a highly critical permission. Admins with this permission can also add and edit roles to include any permissions in the list.
- Knox Cloud APIs — Grant the ability to access the Knox Cloud APIs portal. Note that the Knox Cloud APIs field will only be available if a Samsung Admin enables this feature for the tenant.
- Click Save.
Invite admins
Invite admin
- Log in to the Knox Reseller Portal.
- Click on the Administrators & Roles tab.
- Click INVITE ADMINISTRATOR.
- In the Invite administrator screen, enter the following information:
- First Name — Provide the first name of the administrator resource for this invitation.
- Last Name — Provide the last name of the administrator resource for this invitation.
- Email — If this email is not already associated with a Samsung Account, the user will have to create a Samsung Account before logging in to Knox Configure. The creation of a Samsung account is required before an administrative account can be created.
- Role — Use the drop-down menu to assign this new administrator a role that is appropriate to their intended administrative function. If unsure about the exact permissions of an available role, select View Role Details to review the scope of its available permissions.
- Select INVITE when completed.
The newly added administrator displays by name, with the email address displaying as a link that can be selected to update the administrator name and company management designation. If editing the administrator's profile, select Save to commit the updates.
Resend invitation
- Log in to the Knox Reseller Portal.
- From the left-navigation, click on Administrators & roles.
- Under NAME, select the target customer link with a pending status.
- Click RESEND INVITATION.
- Click CONFIRM.
Revoke invitation
- Log in to the Knox Reseller Portal.
- From the left-navigation, click on Administrators & roles.
- Under NAME, select the target customer link with a pending status.
- Click REVOKE INVITATION.
- Read the notice to verify that you understand that the user will not be notified with this action and when the user clicks the link in the invitation email, they will not be granted access to Knox solutions or data.
- Click REVOKE.
View and edit admins and roles
View admin and role details
In the Administrators & Roles page you'll be able to view the administrator summary by default.
To view the role summary, click on the ROLES tab.
All the Administrators and Roles can be easily shuffled using the arrows beside table heading NAME in ADMINISTRATORS tab and ROLE NAME in ROLES tab. In addition, Administrators can be filtered for a specific role using the drop-down ROLE as shown below.
Edit admin and role details
View details
- Log in to the Knox Reseller Portal.
- From the left-navigation, click on Administrators & roles.
-
Under NAME for Administrator or ROLE NAME for Role, select the target customer or admin link.
In the Edit administrator window, you'll be able to view the administrator's first name, last name, email address, roles and status.
Edit details
- Log in to the Knox Reseller Portal.
- From the left-navigation, click on Administrators & roles.
- Under NAME for Administrator or ROLE NAME for Role, select the target customer or admin link.
- Edit the details as needed.
- When done, click SAVE.
Delete a role
- Log in to the Knox Reseller Portal.
- Select Administrators and Roles from the left-hand navigation menu.
- Select the ROLES tab and click on the role you want to delete.
- In the Edit role window, select DELETE. A Delete role pop-up window prompts to confirm the action while showing any pending, revoked or blocked admins associated with this role. If there is an active admin associated with this role, it needs to be assigned another role to do the deletion. Both these cases are shown in the following screenshot.