How to configure Knox E-FOTA on Microsoft Intune

Last updated August 4th, 2026

Categories:

This content is intended for customers looking to use Knox E-FOTA on Microsoft Intune.

Environment

  • Knox E-FOTA
  • Microsoft Intune

Overview

Knox E-FOTA requires the following components to manage firmware on your Samsung device fleet:

  • The Knox E-FOTA client installed on your devices
  • Devices that are enrolled in Knox E-FOTA on Microsoft Intune
  • A firmware management policy, created and assigned to the device fleet

This guide outlines the steps you must follow to configure Knox E-FOTA on Microsoft Intune.

Prerequisite: Set up Samsung Knox cloud services

Before you can use Knox E-FOTA on Microsoft Intune, ensure that the following prerequisites are met:

  • You have a Samsung Knox account
  • You’ve connected your Microsoft Intune tenant with Samsung Knox E-FOTA

Step 1: Create a device group

Create a group for Samsung devices you want to manage with Knox E-FOTA. If you already have a device group, you can skip to Step 2: Add required Samsung apps with Managed Google Play.

  1. Sign in to the Microsoft Intune admin center.

  2. On the navigation menu, go to Groups and click New group.

    Microsoft Intune Groups overview page with New group button highlighted

  3. Create a Group name and click Create.

Step 2: Deploy required Samsung apps with Managed Google Play

To use Knox E-FOTA, you must install and run the Knox E-FOTA app on your devices. We recommend using Knox Service Plugin to automatically install and run the Knox E-FOTA app.

Add required apps to your device group

To add Knox E-FOTA and Knox Service Plugin to your device group:

  1. Connect your Intune account to your Managed Google Play account.
  2. On the navigation menu, go to Apps > Android.
  3. Click Create.
  4. Under Category, select Store app. Under App type, select Managed Google Play app.
  5. Search for Knox E-FOTA, then click on the app and click Select.
  6. Search for Knox Service Plugin, then click on the app and click Select.
  7. Click X to close Managed Google Play and return to the Android apps list, which should now include Knox E-FOTA and Knox Service Plugin. If these apps don’t appear, click Refresh.
  8. Click Knox E-FOTA on the Android apps list. Under Manage, click Properties.
  9. Next to Assignments, click Edit.
  10. Under Required, click Add group.
  11. Select the group of devices you want to manage with Knox E-FOTA.
  12. Click Review + save, then click Save.
  13. Repeat steps 8 to 12 for Knox Service Plugin.

If you’re enrolling corporate-owned dedicated devices with Managed Home Screen or any kiosk app, add the following Android Enterprise system apps to your device group:

App name Publisher Package name
Knox E-FOTA Plugin Samsung Electronics Co., Ltd. com.samsung.android.knox.efota.plugin
Knox Container Core Samsung Electronics Co., Ltd. com.samsung.android.knox.containercore
Knox E-FOTA Samsung Electronics Co., Ltd. com.samsung.android.knox.efota

Configure Knox Service Plugin

Configure Knox Service Plugin to automatically install and run the Knox E-FOTA app:

  1. On the navigation menu, go to Devices.

  2. On the Devices menu, go to the Manage devices section and click Configuration.

    Microsoft Intune Devices menu showing Configuration section highlighted

  3. Click Create > New Policy.

  4. Under Platform, select Android Enterprise.

  5. Under Profile type, select Templates.

  6. Select OEMConfig.

    Create profile wizard showing Android Enterprise platform and OEMConfig profile type selection

  7. Click Create.

  8. Give your profile a Name.

  9. Click Select an OEMConfig app, and select Knox Service Plugin.

  10. Click Next.

  11. Next to Device-wide policies, click Configure.

    Knox Service Plugin configuration showing Device-wide policies with Configure button highlighted

  12. Set Enable device policy controls to True.

    Enable device policy controls setting set to True

  13. Next to Firmware update (FOTA) policy, click Configure.

  14. Set Enable firmware controls to True.

  15. Set Enable E-FOTA client installation & launch to True.

  16. Click Next.

  17. (Optional) Select scope tags, then click Next.

  18. On the Assignments tab, click Add groups and select the group of devices you want to manage with Knox E-FOTA.

  19. Click Next and review your profile.

  20. Click Create.

    Knox Service Plugin profile review screen showing configuration summary before creating

Step 3: Enroll and add devices

Enroll your devices to Microsoft Intune, and add them to the group of devices you want to manage with Knox E-FOTA. Skip this section if you’ve already enrolled devices to Microsoft Intune and added them to your device group.

  1. Enroll Android devices in Microsoft Intune.
  2. On the navigation menu, go to Groups > All groups.
  3. Click on your device group.
  4. Under Manage, click Members.
  5. Click Add members, and select devices to add to your group.
  6. Click Select.

Step 4: Register devices with Samsung

Register your device group with Samsung Knox E-FOTA so you can begin managing firmware for those devices.

  1. Sign in to the Microsoft Intune admin center.

  2. On the left navigation menu, go to Tenant administration > Connectors and tokens.

    Microsoft Intune Tenant administration page showing Connectors and tokens menu highlighted

  3. On the Connectors and tokens menu, go to Firmware over-the-air update.

    Connectors and tokens page showing Firmware over-the-air update section under Android and ChromeOS category

  4. Select Samsung on the list of OEMs.

  5. Under Register Devices with Samsung, click Add groups.

  6. Select your device group.

  7. Click Select.

  8. Click Register.

Step 5: Create a Knox E-FOTA firmware deployment

Create a firmware deployment to set detailed policies to schedule and throttle firmware downloads, and configure firmware policies for your fleet of devices.

  1. On the navigation menu, go to Devices.

  2. Under Manage updates, click Android FOTA deployments.

  3. Click Create.

  4. Under Manufacturer, select Samsung then click Create.

  5. Give your deployment a Name then click Next.

  6. Configure the following firmware deployment settings:

    • Firmware version — Select the device model, sales code, and CSC you want to target. This defines which devices will receive the firmware update.

      Under Update type, choose one of the following policies:

      • Latest any — Pushes the newest available firmware version to your devices.
      • Latest Up to Max OS Version — The latest firmware, within a select OS version is pushed to the devices.
      • Lock current firmware version — Prevents any firmware changes on your devices, maintaining the current version.
      • Select firmware version — Lets you pick a specific firmware version from the available options for your targeted devices. Only firmware versions compatible with the targeted devices are available.
    • Deployment schedule — Set the date range when devices in the deployment can start to download and install the update. If you want to run the deployment indefinitely, select Set start date only.

      The timezone is set in UTC, and you can’t set a start date and time that’s in the past.

    • Installation schedule — Controls when during the day devices can begin installing firmware, based on the device’s local timezone. For example, you might set this to overnight hours to minimize user disruption.

      • Download period — Control when during the day devices can begin downloading firmware, based on the device’s local timezone. You can set this time window to match the Installation schedule, or set a customer time window for downloads.
      • Allow user to postpone installation — Allow users to postpone the installation up to three times, and configure how often they’re reminded.
    • Device conditions — Specify device conditions that must be met before installation can begin.

      • Minimum battery — Require a minimum battery percentage before installation starts.
      • Charging status — Require devices to be connected to a charging dock during installation.
      • Network type — Allow firmware downloads over any network, or restrict devices to only download firmware when connected to Wi-Fi.
  7. (Optional) Select scope tags, then click Next.

  8. Select the device groups to include or exclude this firmware deployment, then click Next.

  9. Review your firmware deployment settings, and click Create.

Is this page helpful?