Knox Guard 26.10 release notes
Last updated October 8th, 2026
This document is new for the Knox cloud services 26.10 UAT.
On this tab
- New
- Analytics data feed for Knox Guard Edition customers
- Automatic firmware installation for Knox Guard Edition devices
- Control outgoing calls at the device level
- Updates
- Malware scanning for apps uploaded to Application installation policy
- Support for app allowlisting
- Certain special characters no longer supported in message fields
New
Analytics data feed for Knox Guard Edition customers
Starting with Knox Guard 26.10, Knox Guard Edition customers can use the new Analytics data feed policy to retrieve information about all their devices without having to call the Knox Guard server using the REST API.
To get analytics data, first configure your data feed settings in the Knox Guard console, then retrieve the data reports using an SFTP call. This feature enables you to consistently receive large amounts of data, without having to worry about timeouts or system stability.
To learn more about:
- The Analytics data feed policy and the types of data you can retrieve, see Analytics data feed.
- How to retrieve your data reports, see the Knox Guard developer guide.
- Knox Guard Edition licenses and features, see Manage licenses.
Automatic firmware installation for Knox Guard Edition devices
To help keep your device fleet up-to-date with the latest security patches, the new Auto firmware installation policy allows Knox Guard Edition customers to install the most recent firmware updates on their devices.
Once enabled, as soon as the latest security patch is downloaded to a Knox Guard Edition device, it automatically installs. Device users won’t be able to delay or cancel the installation, even if the device is actively in use.
Control outgoing calls at the device level
With Knox Guard 26.10, if you have a Knox Guard Advanced license, you can now restrict a device’s ability to make outgoing calls. This allows you to apply phone restrictions that aren’t tied to the device’s SIM, while also letting device users contact up to ten allowlisted numbers needed for day-to-day use. Emergency calls are exempt from this restriction.
Outgoing call controls are applied per device through device actions, and functions independently of the SIM control policy. As such, you can use this feature to encourage specific users to fulfill any outstanding payments, without having to apply more rigorous restrictions.
For more information, see Outgoing call control.
Updates
Malware scanning for apps uploaded to Application installation policy
With this release, all apps uploaded to the Application installation policy are now automatically scanned for malware. If malware is detected, the app is removed from the Knox Guard console and can’t be installed on devices. This prevents malicious apps from being installed, protecting both service providers and device users from security threats.
Support for app allowlisting
Previously, if you had a Knox Guard Advanced license, you could only use the App blocklist policy to prevent device users from accessing apps. With Knox Guard 26.10, this feature is expanded to allow you to both block and allow specific apps from your devices.
Renamed to App access control, you can use this policy to apply the following restrictions to your devices:
- Blocklist – If enabled, device users can’t access any apps on this list.
- Allowlist – If enabled, device users can only access apps on this list. Not applicable to pre-loaded system apps*. If you want to block access to a system app, add it to the blocklist.
You can simultaneously block up to 50 apps and allow up to 10 apps at once. As such, this policy restricts device users access to only apps you approve, while also blocking access to system apps.
*Pre-loaded system apps are identified by Android’s ApplicationInfo.FLAG_SYSTEM attribute. Apps without this flag are disabled by the allowlist unless added explicitly. Before applying an allowlist, verify that any app you want to permit either has the FLAG_SYSTEM attribute or is added to the allowlist.
Certain special characters no longer supported in message fields
As part of our ongoing commitment to strengthening product security, starting with Knox Guard 26.10, certain special characters are no longer supported in messages and can’t be entered.
Blocked characters include: < > | ~ ` ^ \ =
This restriction impacts all actions and policies with a Message input field, such as:
- Complete device management
- Lock and unlock device
- Update lock message
- Blinking reminders
- Send notifications
- Offline device lock
- Enrollment notices
- Relock reminders
- Pay-as-you-go lock screen
Configurations set prior to the 26.10 release will continue to function without issue. However, creating, updating, or re-applying any policy with blocked characters returns an error.
In addition, blocked characters may be removed or modified from CSV file exports. As such, you may notice that the values in the exported file differ from the original input in the Knox Guard console. This applies even to legacy activity log entries created before this restriction was introduced. The original values stored in your policies aren’t modified.
Is this page helpful?
Thank you for your feedback!