Back to top

List of environment settings

Last updated January 22nd, 2024

The environment settings by category are as follows. All options have default values and the values can be modified.



Option Description
Default Country Code Select the country of your tenant. The country code and the corresponding language are used for user agreements, privacy policy, admin and user enrollment, and public application enrollment on user devices.
Time Zone Select the time zone of the Knox Manage server. Based on the time zone, the information on the Knox Manage console is displayed, tasks and events scheduled by admins are performed, and user and device statistics are collected.
Date Format Set the date format to be applied to all screens that show dates, such as the Last Updated field.

For more information about setting the logo, see Setting the logo.

Option Description
Logo Image Click Select Image and upload the image file of your company logo. The image must be a GIF, JPG, PNG, or BMP file. The file can't be larger than 190 x 33 and must be 1 MB or lower. Click Default to use the default image as your company logo.
Header Color Click the color box and set a color for the header.
Header Font Color Click the color box and set a color for the header text.
Preview Preview the company logo.


Configure the settings about the login environment and the admin account.

Option Description
Two-Factor Authentication Enable the use of OTP authentication as well as an account ID and password when admins sign in to the Knox Manage console. For OTP authentication, the admin's mobile phone number or email address is required.
Allow Multi-point Logins Allow concurrent sign-ins on the Knox Manage console.
Action When Admin Login Fails

Select the response of the Knox Manage server when there are successive failed login attempts.

  • Deactivate account until an upper level admin unlocks
  • Disable login for 10 mins
  • No action
Maximum Failed Login Attempts

Enter the maximum number of failed sign-in attempts. When users exceed the maximum, their accounts are locked.

You can enter a value from 3 to 10.

Inactivity Limit on Admin Accounts (days)

Enter an inactivity limit for admin accounts. If sub-admins or read-only admins don't sign in for longer than the limit you set, their accounts are locked. To unlock their accounts, they must ask the super admin.

You can enter a value from 10 to 9999.

Maximum Session Timeout (min)

Enter the maximum session time limit for the Knox Manage console. If the limit is exceeded, you are signed out automatically.

You can enter a value from 1 to 60.



Configure the device management settings.

Update the KM Agent for Android
Specify the method for updating the Knox Manage Agent on Android devices. You can choose from the following options:
  • Manual ---The device user can manually update the Knox Manage Agent on the device.
  • User consent ---The Knox Manage Agent can be automatically updated on the device, but the device user is shown a prompt asking for their permission to update the Knox Manage Agent. The device user can opt out of the update process.
  • Force update ---The Knox Manage Agent is automatically updated once a day using a background process. The device user cannot opt out of the update process.


Even if this option is set to Manual or User consent, if the Auto Update Apps on Android Enterprise setting is set to Always auto update, then the Knox Manage agent is automatically updated.

Based on Last Seen (time)
Enter the standard time gap for connection of the device and server. This standard is used for displaying information in the Last Seen column of the device list in the Device menu.
  • If the gap between the current time and the last connected time of a device does not exceed the standard, the Last Seen information of the device is displayed in green.
  • If the gap between the current time and the last connected time of a device exceeds the standard, the Last Seen information of the device is displayed in red.
The value is entered in hours.
Limited Enrollment
Enable enrollment of mobile devices using their IMEI or serial numbers.
Limited Enrollment for KME Devices
Enable enrollment of KME devices using their IMEI or serial numbers. Only devices registered through Knox Mobile Enrollment can be enrolled in Knox Manage. Devices cannot be enrolled in Knox Manage through manual registration or the Zero Touch method.
Device Location View Period (days)
Enter the period for saving device location data. You can view the location of devices saved during that time period.
Maximum Number of Active Devices per Use
Select the number of devices that can be enrolled per user.
APNs Topic for iOS
When you register an APNs certificate in the Admin Portal, this value is automatically entered.
If the value is different from the value in the Current Subject Name field in Setting > iOS > APNs Setting , complete the following steps:
  1. Start the command prompt on your PC.
  1. Enter C:/> keytool -v -list -storetype pkcs12 -keystore {APNS certificate filename}.p12 | find "UID".
  2. Change the APNs Topic value to the value appearing afte UID= .
Daily retries for device commands in queue
Select how many notifications you will receive per day to send device commands which are sent but not applied successfully.
  • 0 : You receive no notification.
  • 1 : You receive a notification at 11 PM local time per tenant.
  • 2 : You receive a notification at 10 AM and 10 PM local time per tenant.
Unapplied device commands are listed in History > Device Command in Reques t .
Camera Option from Lock Screen for iOS
Enable the camera feature on iOS devices when the device screen is locked.
User Enrollment for iOS Enable enrollment of personally-owned Apple devices. For more details about this type of enrollment, see Apple User Enrollment quickstart .
Delete App upon Unenrollment
Enable the applications installed on a device to be deleted when the device is unenrolled. The deletion targets are internal applications for Android devices and all applications installed through Knox Manage for iOS devices.
Delete Content upon Unassignment

For target devices that content sensitive or confidential date that is compromised if the device is unenrolled or unassigned, IT admins can use this option to automatically delete content upon unassignment. Content can be unassigned from a device in the following ways:

  • The device is unenrolled from Knox Manage.
  • The content is unassigned to the device's group or organization.
  • The content is deleted on the Knox Manage console.
Notification that policy is not applied
Enable sending a notification to the device when no profile is applied to a group or organization. When the user turns off the alarm in the device's setting menu, notifications on whether the profile is applied do not show.
Direct boot command polling interval for Android (min)
Set the polling cycle to send the Knox Manage command for Android devices.
If the polling interval is 0, polling will not be performed. However, polling is executed once after the Knox Manage Agent is started.

Inventory Schedule

Configure the interval to collect the device inventory by mobile OS.

Option Description
Inventory Collection Interval for Android (hr)

Enter the interval for collecting the inventory information for Android devices.

You can enter a value from 4 to 24 or 0 (the device inventory is not collected).


To set an interval for collecting the location data of Android devices, navigate to Profile. Click a profile name and click Modify Policy > Android Enterprise or Android (Legacy) > Location > Report device location Interval. For more information, see Location (Android Enterprise) or Location (Android Legacy).

Inventory Collection Interval for iOS (hr)

Enter the interval for collecting the inventory information for iOS devices.

You can enter a value from 4 to 24 or 0 (the device inventory is not collected).

Inventory Collection Interval for Windows (hr)

Enter the interval for collecting the inventory information for Windows devices.

You can enter a value from 4 to 24 or 0 (the device inventory is not collected).

App & Service Desk


Configure the application deletion setting.

Option Description
Manage Deletion

Select the area to delete applications from.

  • Console ---Deletes applications only from the application list in the Admin Portal.
  • Console + Device ---Deletes applications from the application list and also from the devices in the assigned groups/organizations.

Knox Manage App Store

Configure the activation of the review feature in the Knox Manage App Store.

Option Description
Knox Manage App Store Review Enable users to evaluate and write a review about applications in the Knox Manage App Store.

Service Desk

Enter the service desk information displayed on user devices.

Option Description
Service Desk Email Enter the service desk email address.
Service Desk Phone Enter the service desk phone number.

Is this page helpful?